SBOM compliance: the regulations and frameworks that require SBOMs
SBOM expectations now come from national guidelines, sector regulators, product-safety law and industry standards. This overview shows who requires what, and how binding each source is.
- In India, CERT-In's Version 2.0 guidelines set the technical baseline and SEBI's CSCRF makes SBOMs a requirement for regulated entities' core and critical software.
- The EU Cyber Resilience Act requires manufacturers to draw up an SBOM covering at least top-level dependencies.
- U.S. federal policy has shifted from central mandates to agency-led, risk-based decisions on SBOMs.
- Some frameworks, such as PCI DSS, require a component inventory without naming an SBOM format.
- One well-governed SBOM programme can provide evidence against several of these at once.
How to read SBOM requirements
SBOM obligations vary in three ways: who must produce or obtain an SBOM (manufacturer, supplier, consumer), how binding the source is (law, regulator directive, guideline, contract), and what content is expected (field list, depth, format). The summaries below reflect public documents as of September 2026.
India
| Source | Status | SBOM expectation |
|---|---|---|
| CERT-In Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, v2.0 (9 July 2025) | Technical guidance, aimed at government, public sector, essential services and software exporters | 21 baseline fields; SPDX or CycloneDX; VEX and CSAF; SBOMs in procurement and a complete SBOM with software supplied to government [1] |
| CERT-In Comprehensive Cyber Security Audit Policy Guidelines (25 July 2025) | Audit guidance | Lists SBOM, QBOM and AIBOM auditing within the scope of engagements [2] |
| SEBI CSCRF (20 August 2024) and FAQs (June 2025) | Regulatory circular for SEBI regulated entities | SBOMs for all software required for core and critical business operations, in-house or third-party, including SaaS; board-approved exceptions where unobtainable [3][4] |
| RBI IT Governance, Risk, Controls and Assurance Practices Directions, 2023 | Directions for regulated entities | Does not use the term SBOM, but requires source code or escrow for critical applications and vendor confirmation that applications are free of known vulnerabilities [5] |
Law-firm commentary describes CERT-In's guidelines as non-mandatory but strongly recommended [6]. Sector regulators can make them binding in practice, which SEBI has done for SBOMs. See CERT-In SBOM requirements and SBOM for banks.
European Union
The Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to identify and document components, "including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies" [7]. The SBOM belongs in the technical documentation and must be provided to market surveillance authorities on request; it need not be made public [8]. Reporting obligations for actively exploited vulnerabilities apply from 11 September 2026 [9], with the main obligations applying from 11 December 2027 [7].
Germany's BSI publishes TR-03183-2, a technical guideline on SBOMs linked to CRA requirements; version 2.1.0 is dated 3 September 2025 [10]. It requires CycloneDX 1.6 or later, or SPDX 3.0.1 or later, SHA-512 hashes, and excludes vulnerability data from the SBOM itself [11].
United States
Executive Order 14028 (May 2021) directed the publication of minimum SBOM elements and named providing SBOMs to purchasers as a secure-development practice [12]. OMB memorandum M-22-18 then allowed agencies to require SBOMs in solicitations [13]. In February 2026, OMB memorandum M-26-05 rescinded M-22-18 and its update, leaving agencies to decide whether to require SBOMs based on risk [14]. The technical baseline remains the 2026 Minimum Elements for an SBOM, published by CISA with the NSA and partners on 30 July 2026 [15].
For medical devices, section 524B of the FD&C Act requires cyber-device manufacturers to provide the FDA "a software bill of materials, including commercial, open-source, and off-the-shelf software components" [16].
Industry standards
PCI DSS v4.0 requirement 6.3.2, mandatory from 31 March 2025, requires an inventory of bespoke and custom software and the third-party components incorporated into it. It does not prescribe an SBOM format, but an SBOM is a practical way to meet it [17]. NIST's SSDF practice PS.3.2 calls for collecting and sharing provenance data for each release's components, with an SBOM as the example [18].
Common threads
- Formats: CycloneDX and SPDX appear in CERT-In, CISA and BSI guidance.
- Depth: ranges from top-level dependencies (CRA) to full transitive coverage (CISA 2026).
- Currency: SEBI and CERT-In expect SBOMs to be updated when software changes.
- Vulnerability status: CERT-In includes vulnerabilities in the SBOM and recommends VEX, while BSI keeps them out of the SBOM.
Mapping these differences is easier with a single inventory validated against several field policies; see SBOM validation.
How IntelliXBOM helps
IntelliXBOM validates SBOMs against required-field policies such as CERT-In's, maps the inventory to framework controls and produces timestamped evidence. It helps organisations address several of these requirements from one governed inventory; it does not certify compliance.
This article summarises public guidance for information only and is not legal advice; refer to the current official documents before acting.
Frequently asked questions
Is an SBOM mandatory in India?
CERT-In's guidelines are framed as technical guidance, but they state that software supplied to government, public-sector and essential-services organisations must be accompanied by a complete SBOM. SEBI's CSCRF requires SBOMs for regulated entities' core and critical software.
Does the EU Cyber Resilience Act require an SBOM?
Yes. Manufacturers must draw up a machine-readable SBOM covering at least top-level dependencies, keep it in the technical documentation and provide it to market surveillance authorities on request.
Do U.S. federal agencies still require SBOMs?
OMB memorandum M-26-05 of February 2026 rescinded the earlier central guidance and lets each agency decide, based on risk, whether to require SBOMs. CISA's 2026 Minimum Elements remain the reference for content.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- Comprehensive Cyber Security Audit Policy Guidelines, Version 1.0 (25 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/Comprehensive_Cyber_Security_Audit_Policy_Guidelines.pdf
- Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
- Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (June 2025)SEBIwww.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
- Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023Reserve Bank of Indiawww.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12562
- CERT-In's Technical Guidelines on SBOM, QBOM and CBOM, AIBOM and HBOMAZB & Partnerswww.azbpartners.com/bank/cert-ins-technical-guidelines-on-sbom-qbom-and-cbom-aibom-and-hbom/
- Regulation (EU) 2024/2847, Cyber Resilience ActEUR-Lexeur-lex.europa.eu/eli/reg/2024/2847/oj
- SBOM Requirements in the EU's CRA (Cyber Resilience Act)FOSSAfossa.com/blog/sbom-requirements-cra-cyber-resilience-act/
- Cyber Resilience Act, Reporting obligationsEuropean Commissiondigital-strategy.ec.europa.eu/en/policies/cra-reporting
- BSI TR-03183-2: Cyber Resilience Requirements for Manufacturers and Products, Part 2: Software Bill of Materials (SBOM), Version 2.1.0BSI (German Federal Office for Information Security)www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI-TR-03183-2_v2_1_0.pdf
- BSI TR-03183-2: SBOM Requirements (v2.1.0)sbomifysbomify.com/compliance/bsi-tr-03183/
- Executive Order 14028, Improving the Nation's Cybersecurity (May 2021)Federal Registerwww.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity
- M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices (14 September 2022)Office of Management and Budgetbidenwhitehouse.archives.gov/wp-content/uploads/2022/09/M-22-18.pdf
- OMB Rescinds Biden-Era Software Security Requirements, Directs Agency-Led and Risk-Based Approach (February 2026)Davis Wright Tremainewww.dwt.com/blogs/privacy--security-law-blog/2026/02/omb-changes-course-on-software-security
- CISA Releases the 2026 SBOM Minimum ElementsFOSSAfossa.com/blog/cisa-releases-2026-minimum-sbom-elements/
- 21 U.S. Code § 360n-2, Ensuring cybersecurity of devices (FD&C Act section 524B)Legal Information Institute, Cornell Law Schoolwww.law.cornell.edu/uscode/text/21/360n-2
- Understanding SBOM Requirements in PCI DSSFOSSAfossa.com/blog/understanding-sbom-requirements-pci-dss/
- SP 800-218, Secure Software Development Framework (SSDF) Version 1.1NISTcsrc.nist.gov/pubs/sp/800/218/final
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.