Spectra Assure Free Trial
Get your 14-day free trial of Spectra Assure for Software Supply Chain Security
Get Free TrialMore about Spectra Assure Free Trial[SBOMs] had already been well established in places like the aerospace industry, where they have very low tolerance for any problems and a very high expectation of sound engineering practices.
More than a decade ago, large financial institutions began to speak publicly about their use of SBOMs to ensure that the components used in the third-party products they were relying on to conduct business were transparent, Woods noted.
While SBOM adoption was slowly taking shape in those critical sectors in the 2010s, the rhetoric on Capitol Hill was divisive. Woods said that pushback for SBOM adoption was rooted in the notion that “you couldn’t possibly track all of the software that was used in producing a product.” Nonetheless, with time, SBOM adoption slowly increased – not as a result of government policy but because of market forces, he said:
Just by the fact of asking for an SBOM, you can cause that market to change.
SBOM adoption is far higher now than in 2013, but Woods said there are still laggards who have yet to jump in. He said he likes to remind leaders of what a BOM offers in the context of manufacturing: improved quality, reduced cost, fewer safety issues, and less liability post-procurement. And, he said, BOMs' value in their most basic form can be transferable to the digital landscape.
With a few “engineering tweaks,” the standard BOM can be made applicable to software, Woods said, and those who have been slow to adopt SBOMs will see that a software package isn’t very different from a vehicle that needs to pass its safety tests. And organizations will have to adapt sooner rather than later if they want to survive in a demanding market, in the face of cyberthreats, he said.
The value of an SBOM is essential for cybersecurity, Woods said:
If you want to optimize your security and [minimize] risk, you kind of need that transparency; you need some kind of SBOM.
While the SBOM brings a great amount of value to the market, it alone can't manage software risk. However, Woods is hopeful that as adoption increases and more use cases come to light, the value that SBOMs bring will only increase. The SBOM is continuing to evolve to bring this value to organizations. For example, OWASP recently introduced CycloneDX 1.6 with the hope of future-proofing SBOMs.
To help organizations better understand SBOMs and their place in software supply chain security, several leading experts joined in a recent webinar, "SBOMs Are Having a Moment. How to Make Them Actionable," providing an overview of why SBOMs are in the spotlight and how organizations can best operationalize them for greater software supply chain security.
To learn more about the history of the SBOM, where it stands today — and what Woods believes is the future for the SBOM, watch the full ConversingLabs episode “The Past, Present & Future of SBOMs,” or listen to it wherever you get your podcasts.


The TeamPCP actors, alleged to be behind one of the most active supply chain threats, were arrested — but this is not the end of Shai-Hulud.

UAT-10147 leveraged agentic AI to go beyond scripting to deliver a backdoor. The method highlights the need for agentic SOCs.

The annual cybersecurity conference focused on frontier AI agents — and what they mean for cyber. Here are three key takeaways.