Divulgare la privacy e la cybersecurity nelle aziende
con spiegazioni semplici e operative, AI assisted
Osservatorio a cura del dott. V. Spataro 



   demo 2026-06-13 ·  NEW:   Appunta · Stampa · Cita: 'Doc 101437' · pdf

SBOM Adoption State of Play  PDF

abstract:



Documento annotato il 13.06.2026 Fonte: europa.eu
Link: https://www.enisa.europa.eu/sites/default/files/20




analisi:

L'analisi è riservata agli iscritti. Segui la newsletter dell'Osservatorio oppure il Podcast iscrizione gratuita 30 giorni

-




index:




testo:

Eestimated reading time: 35 min .... ........ State of Play – 2026 Survey Results and Analysis ...

 


Testo riservato. Per iscriversi:
all'Osservatorio - al Podcast (30 gg gratuito)

br /> State of Play –
2026
Survey Results and Analysis
JUNE 2026
TLP - CLEAR

SBOM Adoption State of Play – 2026
1

About ENISA
The European Union Agency for Cybersecurity, ENISA, is the Union’ s agency dedicated to achieving a
high common level of cybersecurity across Europe. Established in 2004 and strengthened by the EU
Cybersecurity Act, the European Union Agency for Cybersecurity contributes to EU cyber policy,
enhances the trustworthiness of ICT products, services and processes with cybersecurity certification
schemes, cooperates with Member States and EU bodies, and helps Europe prepare for the cyber
challenges of tomorrow. Through knowledge sharing, capacity building and awareness raising, the
Agency works together with its key stakeholders to strengthen trust in the connected economy, to
boost resilience of the Union’ s infrastructure, and, ultimately, to keep Europe’ s society and citizens
digitally secure. More information about ENISA and its work can be found here: www.enisa.europa.eu
.

CONTACT
For contacting the authors, please use product_security@enisa.europa.eu
For media enquiries about this paper, please use press@enisa.europa.eu .
AUTHORS
European Union Agency for Cybersecurity (ENISA)
LEGAL NOTICE
This publication represents the views and interpretations of ENISA, unless stated otherwise. It does
not endorse a regulatory obligation of ENISA or of ENISA bodies pursuant to the Regulation (EU)
No 2019/881.
ENISA has the right to alter, update or remove the publication or any of its contents. It is intended for
informat ion purposes only and it must be accessible free of charge. All references to it or its use as a
whole or partially must contain ENISA as its source.
Third -party sources are quoted as appropriate. ENISA is not responsible or liable for the content of the
external sources including external websites referenced in this publication. Neither ENISA nor any
person acting on its behalf is responsible for the use that might be made of the information contained
in this publication. ENISA maintains its intellectual property rights in relation to this publication.
Luxembourg: Publications Office of the European Union, 2026

COPYRIGHT NOTICE
© European Union Agency for Cybersecurity (ENISA), 2026
This publication is licenced under CC -BY 4.0 ‘Unless otherwise noted, the reuse of this document is
authorised under the Creative Commons Attribution 4.0 International (CC BY 4.0) licence
( https://creativecommons.org/licenses/by/4.0/
). This means that reuse is allowed, provided that
appropriate credit is given and any changes are indicated.
Copyright for the image on the cover and on pages 1:63 © Adobe Stock
For any use or reproduction of photos or other material that is not under the ENISA copyright,
permission must be sought directly from the copyright holders.
ISBN 978-92-9204- 791-7 , DOI 10.2824/0741767

SBOM Adoption State of Play – 2026
2

Table of Contents
About ENISA 1
Executive Summary 3
1. Introduction 6
1.1 The Background 6
1.2 The Concept of .... .
1.3 The Survey 7
2. Analysis of the .... ..... .. ... ... ...... .
2.1 Survey Cohort 8
2.2 CRA Applicability, Awareness, Exposure and Investments 9
2.3 Supply Chain Security 12
2.4 SBOM Specifics 14
2.4.1 Adoption Readiness 14
2.4.2 Formats, Tools and Lifecycle Integration 17
2.4.3 Usage Patterns and Gaps 20
2.4.4 Barriers, Needs and External Supports 23
2.4.5 Vulnerability Management 25
2.4.6 Interoperability Requirements 26
2.4.7 Supplier Requirements (for .... .........) ..
2.4.1 Guidance 29
3. Conclusions 30

SBOM Adoption State of Play – 2026
3

Executive Summary
The EU ..... .......... ... (...) ........ ..... .......... .. ........ ...., .......... ...
supply chain security landscape by making security- by-design and security- by-default, a legal
obligation for all digital products entering the EU m arket. Software supply chain transparency thus
becomes a required cybersecurity capability, positioning the Software Bill of Materials (SBOM) as
an enabler and key mechanism for operational efficiency, vulnerability management, third -party risk
management, and regulatory compliance.
SBOM is defined as a formal record containing details and supply chain relationships of components
included in the software elements of a product with digital elements. It provides visibility of the
components, libraries, dependencies and licencing requirements in a software product.
The European Union Agency for Cybersecurity launched a survey at the end of 2025 to gain
factual data on how organisations across industries and of varying sizes are approaching ....
adoption in response to the CRA. This report analyses the results of the .... . .... .. ... ...
survey , by discussing:
... ........., ......... ............. ... .............. .......
→ supply chain security concerns and investment plans for the identified risks ;
.... ........... ... ........ ...... .
.... ......., ....... ........., ........... ........, ..... ... ...... ...... .
.... .............. ........, ..... ... ........ ....... .
.... ................ ............ .
→ the guidance required to support .... ........ .. ......
The analysis confirms that the ... .... .. .. ........... ... .... ........ .. .............
broadly invest in .... .......... ... .......... .. ......... .... .. ... ........ ...........
Lifecycle (SDLC) , while expediting their implementation timeline to meet expected maturity levels.
Based on the respondents’ estimations, 79% of the organisations will reach the necessary ....
maturity level by the time that the ... .... .. ..... ...........
Organi sations acknowledged the value of continuously generating and consuming .... .. ....
reduction and cost avoidance (37 % ), in operational efficiency (29 %) and in meeting contractual
requirements and gaining a competitive edge in bids (26 % ).
78 % of the respondents reported that their organisations have already initiated their ....
adoption journey , with 44 % currently being in the pilot or limited adoption phase. 9 % have already
reached a mature level of implementation , fully supported by automation , while 25 % have stated
that SBOMs are broadly adopted in their products .
The selected .... ...... . ...... .. ..... .... ... ... ........... ......... ..... . ...... .... ..
commonly used and machine- readable: 44 % of the respondents reported using CycloneDX and 29 %
Software Package Data Exchange (SPDX). However , 11 % of the respondents indicated that they do
not use a standard format and the remaining 17 % still use a proprietary format.

SBOM Adoption State of Play – 2026
4

The survey indicates that .... .... .. .... ... ... .............. ... ........ .. ...............
by 29 % of the organisations, for ensuring open -source licen ces (OSS) are correctly used/declared
by 22 %, for meeting regulatory requirements by 19 %, for e valuating third -party software risks
by 14 % and for maintaining an up -to -date inventory of all components by 13 % of the
organisations.
The main barriers that prevent organisations from adopt ing SBOMs at scale , as identified by the
respondents in different parts of the survey, are:
→ the technical challenge of achieving a high degree of .... ............ (.. %).
→ the lack of internal skills or dedicated staff (28 %);
.... .... ....... (.. %). ...
→ vulnerability matching (35 % quite a lot and 23 % extremely challenging).
The means that are going to facilitate this process have also been assessed by the respondents in
different parts of the survey. It is clearly stated that external support is needed. The main needs can be
summari sed:
→ a reference implementation providing the pipelines in a public repository ;
→ a guide navigating the process of tool selection based on evaluations and benchmarking;
→ conformance tests with check point and validators ;
→ industry consensus on best practices to integrate producing/consuming SBOMs :
o into software development practices , deemed the most critical (23 %),
o into risk and compliance processes (19 %),
o how to produce/consume SBOMs and how these methods will evolve/improve over
time (19 %);
→ development of a profile defining what constitutes a ‘good enough ’ .... .
→ call for the standardisation of .... ....... ... ..... ........ ...... .
→ development of a risk .......... ......... .... ......... .... .....
Overall, the survey findings indicate that .... ........ ...... ............. .. ........... ... ..
strongly influenced by the regulatory requirements introduced by the CRA. However, they also
demonstrate that .... ........ .......... ... ....... ........ .... ...... .. ... ........... ..
shared i mplementation practices , improvements in supplier transparency , continued
investment in workforce capabilities, and definition of the role of SBOMs within operational risk
management frameworks.

SBOM Adoption State of Play – 2026
5

SBOM Adoption State of Play – 2026
6

1. Introduction
1.1 The Background
The EU ..... .......... ... (...) ( .) , ........... ... ............. ....... ... .............
challenges faced by the European Union, aims to enhance cybersecurity culture and strengthen cyber
resilience across the EU m arket. These goals are fulfilled via a legal framework which lays out the
essential requirements for the development of secure products with digital elements , ensuring security
and transparency in the digital supply chain. It is a methodological and structured approach to target
the low levels of built -in cybersecurity in many products, address the insufficient provision of security
updates and help end users assess cybersecurity in the products that they consume.
Along with other horizontal rules which address different aspects of cybersecurity, t he ... ..........
for the first time the legal requirement for manufactures to create, maintain and, where necessary ,
share with market surveillance authorities Software Bill of Materials (SBOM) for all products with digital
elements . This change transforms SBOMs from a best practice and optional implementation for supply
chain security in to a mandatory security measure upholding security, transparency and conformity with
the regulation. SBOMs now play a multifaceted role in building market trust by facilitating informed,
risk -based decision- making, providing traceability of products and components, supporting compliance
and securing the supply chain.
1.2 The Concept of ....
Under the CRA, the .... .. ....... .. . ...... ...... .......... ....... ... ...... .....
relationships of components included in the software elements of a product with digital elements. The
SBOM obligations for manufacturers , outlined in the CRA, can be summari sed as follows.
• Manufacturers must generate .... ... ..... ....... .... ....... ........ .... ..... .. ...
EU market.
• The .... .... .. .. . ........ .... ... ....... -........ .......
• The .... .... ..... .. ..... ... ...- ..... ............ .. ... ........
• The .... .... .. .... .. .. .... .......... ... ....... ’. .... ......
• The .... .... .. ........ .. ... ....... ’. ......... ............. ... ........ .. ......
surveillance authorities upon request. There is no obligation to make it public.
• The .... .... .. ........ .. ... ............. ........ ....... ... .. ..... .. ...
manufacturer and support the identification and recording of vulnerabilities and components
contained in products with digital elements.
(1) Regulation (EU) 2024/2847 of the European Parliament and of the Council of 23 October 2024 on horizontal cybersecurity
requirements for products with digital elements and amending Regulations (EU) No 1 68/2013 and (EU) 2019/1020 and
Directive (EU) 2020/1828 (Cyber Resilience Act) .

SBOM Adoption State of Play – 2026
7

1.3 The Survey
Given the significant role of .... .. ........ ...... ..... ............ ... ........ , ..... .... ...
now mandatory nature as defined by the CRA, the European Union Agency for Cybersecurity (ENISA),
with this survey , sought to examine .... ......... ... ... ....... ..... .. .... ........ ......
various organisations and industries. The results provided meaningful insights on:
• the level of .... ........ ... ........ .
• the most common formats, tooling and usage scenarios ;
• perceived value, challenges, and the gap between .... .......... ... ............
The survey was divided into seven sections to gain targeted understanding on each subject area, from
demographics to ... ........., .... ........... ......, ........ ... ......... .... .........
were presented in multiple -choice format to facilitate pattern identification and the analys is of the
results , while a few open- ended questions were included to gather specific insights. All responses
were confidential and used only in aggregate.

Figure 1: Survey infographic
The survey received 3 34 responses from organisations across the EU and, in some cases , beyond;
almost 65 % of the respondents are EU -based organi sations and more than 80 % are companies that
are directly impacted by the CRA.
This report presents the analys is of the .... ..... .. ... ... ...... ....... ......... .. ... ... ..
2025 and has the follow ing structure:
• Executive Summary
• Section 1 . Introduction
• Section 2 . Analysis of the .... ..... .. ... ... ......
• Section 3 . Conclusions

SBOM Adoption State of Play – 2026
8

2. Analysis of the .... ..... .. ...
Art Survey
2.1 Survey Cohort
The survey received mainly responses from private- sector companies (87.72 %). This was expected
due to the ... ’. ..... .. ............. ... ......... .. ........ .... ....... ......... ......
authorities, trade associations and non-governmental organisations account collectively for
approximately 8 % of the responses received.
Organi sations with over 2 50 employees are
heavily represented in the survey with more
than 65 % of the responses. Medium- sized
enterprises represent 18 % while
micro enterprises and small enterprises
collectively represent 16 % of the
respondents. This distribution potentially
reflects the capacity and tendency of big
organisations to be proactive and explore
compliance elements of E U policy and law
ahead of time. This approach can also be
explained by their involvement in both the legislative consultation process and the ... . ..... .....
established by the European Commission.
Regarding geographical representation, 6 5 % of the respondents operate mainly within the EU , while
17 % are global operators , 13 % are North American and only 4 % are from Asia and the Middle East .
Figure 2: Geographical spread and organi sation size
Large enterprises: 65 % of respondents

Large enterprises have
the means and capacity
to be proactive and
prioritise innovation,
automation and
regulatory compliance.

SBOM Adoption State of Play – 2026
9

Regarding sector representation, the IT and manufacturing sector represents 54 % of the responses,
while more specific sectors ( automotive, healthcare, financial, energy and telecommunications )
represent lower percentages that do not exceed 35 % collectively.
Figure 3: Type of organi sation
2.2 ... ............., ........., ........ ... ...........
To establish a bas eline understanding of how the ... .......... ............. ...... ... ..
ecosystem, we asked the respondents if and how the regulation is impacting their organi sations. This
question serves as an indicator of awareness and perceived applicability which can determine future
activities to support the organisations based on their needs. By grouping the responses based on
organisation size, we can identify the scope and target audience of the ... ..... .... ......... ..
initial indication of anticipated maturity levels.
An interesting finding is that 80 % of small enterprises were directly impacted by the ... ......
because they place products on the EU m arket or beca use they supply components to manufacturers.
However , the focus mainly shift s towards the readiness journey of microenterprises , as 23 % of the
respondents were either unsure if the ... ....... ..... ............ .. ... ......... ..........
Figure 4: Envisioned ... ...... ..... .. ...... ...... ....

SBOM Adoption State of Play – 2026
10

In assessing organisations’ awareness of the ... ........... ....... .. ...., .. % .. ... .....
enterprises provided a positive answer, while 13 % remain unaware. Nearly all m edium-sized
enterprises confirmed their awareness , whereas for 26 % of small enterprises still unclear.
Even though the results indicate a high level of awareness, it is important to acknowledge that there is
still room for improvement for organisations of all sizes.

Figure 5: Awareness o f ... ........... ....... .. .....
To better understand the relationship between organisational awareness and regulatory exposure, the
survey examined how the respondents ’ familiarity with SBOMs correlates with their perception of the
CRA’s applicability to their organisation. This comparison provides insight into whether organisations
that fall within the ... ’. ........... ..... ... .... .......... ... ............ ......... ...... ..
operationalise these practices. The following results illustrate how .... ........... ...... .........
on perceived ... ............., ............ ......... ......... .... ...... ... ..........
While there is a broad familiarity with the concept of SBOM, varying from somewhat
familiar to very familiar, most organisations which are unsure or currently assessing the
impact of the ... .... ..... ..... ..... .... .......
Noticeably, 33 % of those who answered that they have never heard about .... ...... ....
responded that their organi sation is directly impacted by the ... ....... .. ..... . ........ ....
digital elements on the EU market. This finding aligns with the high percentage ( 80 % ) of organisations
that report only recently hearing about .... ... .... .... .... ... ........ .. ........ ........
organisations because they sell products with digital elements to end users.
Another finding is that among organisations which are still unsure or actively assessing if they are
impac ted by the CRA, a vast majority ( 67 %) reported never having heard about .... ......, .....
13 % had only recently become aware of it .

SBOM Adoption State of Play – 2026
11


Figure 6: .... ........... ..... .. .......... ... ......
In another effort to fully understand the impact of the ... .. ............. .... .... ..... ... ....., ..
is important to assess the financial impact and investment trends related to the implementation of its
requirements. Using the .... ........... .. . ..... ..... , .. ..... ... ........... .. ........ ..
their organi sation’ s decision to invest in .... ....... ... .......... ... .......... .. ... ....
Almost half of the respondents (43 %) indicated that the ... ... ‘.............
accelerated’ their investment in .... ....... ... .........., ..... .. ..........
29 % indicated a ‘moderate influence’.
While , as depicted in Figure 7 , almost 20 % indicated that the ... ...... ... ... .... . .... .. ...
investment, it is worth highlighting the impact that the r egulation has had on software development
security.

Figure 7: ... ......... .. .... ....... ... .......... ...........
This increase in investment seems to also have an impact on the expected timeline to meet the target
SBOM maturity level required by the CRA, as reported by the respondents. As illustrated in Figure 8,
33 % of the respondents estimate they will reach the envisioned maturity level within 12 months (end
of 2026) , while 24 % anticipate requir ing an additional six months. Meanwhile, 30 % indicate d that they
will require two years or more to reach th is level, and 12 % were unable to provide an estimat e.

SBOM Adoption State of Play – 2026
12


Figure 8: Estimated t ime required to meet the target .... ........ ..... ........ .. ... ...
Investment decisions cannot only be supported by regulatory requirements if the end goal is to
increase maturity and strengthen cyber resilience across the EU market. Implementors need to
identify the value of these requirements. SBOMs could provide significant value in various use cases,
security -related processes and business activities , b ut where do organisations obtain the greatest
measurable value using SBOM?
Almost 37 % of the respondents acknowledge d quite a lot of added value in risk reduction and cost
avoidance, 29 % believed that .... .... ..... . ... .. ..... .. ........... .......... , .. %
believed that .... .... ........ ... ..... .. ....... ........... ............ ... ....... .
competitive edge in bids, while almost 26 % believed that .... .... ... ..... . ... .. ..... .. ......
compliance and audit process es easier.

Figure 9: Envisioned value of using SBOMs
2.3 Supply Chain Security
Exploring the key concerns about supply chain security and its impact on the financial decision- making
of the organisations , the survey included questions on how concerned the organisations are about
supply chain security and how they allocate resources (budget, staff or tooling) to manage the security
of the software that they use.

SBOM Adoption State of Play – 2026
13

While there is broad acknowledgement that supply chain security matters, there is a gap in
how this risk is addressed in terms of allocated budget . Noticeably, respondents with
minimal to no concern dominate the limited investment space.
More than 90 % of respondents indicated they are concerned about the security of their supply chain;
a lmost 60 % of them were very or extremely concerned. However , only 34 % of the respondents
allocate d significant or extensive resources to manage the security of the software they use.

Figure 10: Cybersecurity resources allocated to address concern s about supply chain security
To establish a better understanding of how organisations address supply chain security, we asked
respondents to prioriti se the most important activities for their organisations. The following heat map
shows that the 1st priority with the most votes is secure development practic es, with vulnerability
reporting coming second and .... ..... . ... .............. .. ... .......... ..... .. .....
importance can be easily interpreted based on the current practices of the industry and the regulatory
requirements that have accelerated the standardisation of such activities.
It is important to highlight that 53 % of the respondents placed .... .. ..... ... ..... ....
important activities . .... .. ........ ......... ... . .... .. ... ..... ... .......... .. .. .......
visibility of the software components, libraries and dependencies as well as monitoring license
compliance, thus promoting secure software development practices while also providing targeted input
for vulner ability reporting. This constitutes a major enabler for the broad adoption of .... ..........
and consumption.

SBOM Adoption State of Play – 2026
14


Figure 11: Elements envisioned to improve supply chain security
2.4 .... .........
2.4.1 Adoption Readiness
This section discusses organisational readiness in relation to the level of .... ........,
engagement and perception. The aim of this subject area is to understand the .... ........
journey of different types of organisations and how this is influenced by their size. The preliminary
findings show how .... . ... ........., ............ ... .... ........ ... ... ........
external support required to proceed with their implementation.
In Figure 12 , based on the overall rating, we can identify that 78 % of the respondents
reported that their organisations have already initiated their .... ........ ....... ,
with 44 % currently being in the pilot or limited adoption phase. Only 9 % have reached a
mature level of implementation, supported fully by automation , while 25 % stated
that SBOMs are broadly adopted in their products.

An interesting finding has emerged at this point : micro enterprises and small enterprises –
representing 23 % and 25 %, respectively – have already reached a mature level of adoption.
This contrast s sharply with medium- sized and large enterprises , which follow at much low er rates
of 4 % and 6 %, respectively .
Assessing th e overall outcome, medium- sized enterprises appear to lead the way, as the value
for ‘Not yet started’ is 0 %.

SBOM Adoption State of Play – 2026
15


Figure 12: Level of .... ........ ..... .. ...... ...... ....
To understand better how the .... ....... ......... . .... ........... .........., ...
respondents were asked to indicate how their organis ations engage with SBOMs. Across all
organisation size s, the most popular answer was producing SBOMs for their own software .
For small, medium- sized and large organi sations , the second most popular manner of
engagement was consuming SBOMs from their vendors or partners , whereas for
micro enterprises it was provi ding .... ....., ......... .../.. ........... ........ .

Figure 13: Engagement with SBOMs based on organi sation size
Regarding the respondents ’ perception of SBOMs, the replies vary slightly depending on the size
of the organi sation . Overall, 28 % of respondents perceived SBOMs as a mandatory burden ,
which reveals a rather compliance- oriented approach, especially in large organis ations where the
percentage goes up to 36 %.
Regardless of the size of the organisation, SBOMs are prominently considered. Overall,
by 42 % of respondents as a ‘defensive necessity’ (i.e., a vulnerability management
approach), by 20 % as a ‘neutral inventory instrument’ and by 10 % as a ‘competitive
asset’.

SBOM Adoption State of Play – 2026
16

This dual perception highlights an important transition phase within the ecosystem; while
organisations recognise the technical value of SBOMs, many still associate their implementation
with compliance pressure.

Figure 14: Perception of SBOMs based on organi sation size
To have a more holistic perception of the status of .... ........, .. .. ....... .. .......... ...
impediments that the organisations fac e throughout this process. The respondents were asked to
assess the impact s of a variety of factors . T he most commonly fac ed obstacle affecting them
extreme ly is the lack of supplier/third -party .... ............ .../.. ....... . .........
closely is vulnerability matching ( CPE/PURL alignment, false positives) , with almost two
thirds of the organisations being affected extremely or quite a lot , and data qualit y (incomplete
components, identifiers, licen ces) .

Figure 15: Main barriers to adopting SBOMs
To overcome these barriers and accelerate .... ........, ... ........... .... ......... ...
type of external support they wish to receive.

SBOM Adoption State of Play – 2026
17

26 % of the organisations suggested that a reference implementation providing the
pipelines in a public repository would be beneficial. 22 % would find it helpful to have a
guide navigating the process of tool selection based on evaluations and benchmarking,
while 18 % would prefer a suite providing conformance tests with check points and
validators.

All three activities indicated a need for technical guidance and support.
Figure 16 presents the respondents’ preferences regarding all the activities defined as external
support.

Figure 16: External support elements envisioned to accelerate .... ........
2.4.2 Formats, Tools and Lifecycle Integration
CycloneDX is indicated as the predominant .... ......, .... .. %, ..... ........
Package Data Exchange follows with 29 %. Interestingly, 11 % of the respondents
indicated that they do not use a standard format and the remaining 17 % still use a
proprietary format.
This result comes even though the ... .......... ... ... .. ‘. ........ .... ... .......-
readable format ’ under A nnex I, Part II (‘Vulnerability handling requirements ’) and the Technical
g uideline BSI TR -03183-2 (
2) indicates that ‘newly generated or updated .... .... .. .. .... -
or XML -format and a valid .... ......... .. ........., ....... ... .. ...... [.. ] . .....
Package Data Exchange (SPDX), version 3.0.1 or higher’.
I t is worth highlighting that 28 % of the respondents represent a possible interoperability
barrier at the EU market.
(2) Technical guideline BSI TR- 03183: Cyber resilienc e requirements for m anufacturers and p roducts – Part 2: Software b ill of
m aterials (SBOM), available at
https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI -TR -03183-2_v2_1_0.pdf?__blob=publicationFile&v=5 .

SBOM Adoption State of Play – 2026
18


Figure 17: Type s of .... ...... ......... .. ...
Despite 33 % of overall .... .......... ....... .. .... -...... ..... , ..... ... ......
organi sations rely a lot on commercial and proprietary tools as well . Interestingly though,
reliance on manual processes across all company sizes sits at around 1 1 % overall, however in
micro enterprises it go es up to 16 % , introducing an additional hurdle since the C R A aims to
provide security throughout the lifetime of product s. 10 % of the respondents do not generate
SBOM s at all.

Figure 18: .... .......... ....... ..... .. ...... ...... ....
Knowing when organisations are producing SBOMs in the Software Development Lifecycle
provides valuable insights on th e accuracy, trustworthiness and usefulness of .... .... ...
vulnerability management, incident response and regulatory assurance. 39 % of the organi sations
reported that they produce SBOMs during software builds, 16 % during software delivery to an
artifac t registry or repository and 14 % during software deployment .
As the majority of organi sations opt for build -time .... .......... , .. .. .... .. ...... ....
they use them as an operational benefit , which also supports software supply chain trust.

SBOM Adoption State of Play – 2026
19


Figure 19: .... .......... .. ........ ........... .... ..... (....)
Following the same notion, the timing of .... ........... ......... .. .... ... .... ...........
to prevent risks or reactively to detect and manage them after integration or deployment. 16 %
reported that they consume SBOMs during software builds , 15 % during software integration
and 14 % during the decision -making process determining if an external sof tware is going to be
used. Noticeably, the majority of the respondents don’ t know if or how the SBOMs are consumed
in their organisation.

Figure 20: .... ........... ...... ........ ........... .... ..... (....)
Currently, .... .......... ... ........... ..... ... ...... .. .............. .......... .....
automated implementation across each phase of the .... .... ..... .. ... ... .... ...
achiev ing maturity and reliability.
During this period of transition, 74 % of respon dents reported that they have partially or fully
automated .... .......... ... .... ......./..... , .. % .... ......... .. ..... ......... ...
SBOM min imum content (only top- level dependencies) in machine-readable format (SPDX/
CycloneDX), 51 % have partial ly or fully automated the vulnerability handling workflow tied
to .... , .. % .... ......... .. ..... ......... .... ....... ... ... ....... ....... ......
and 39 % have partially or fully automated the inclusion of .... .. ..... .........
documentation.

SBOM Adoption State of Play – 2026
20


Figure 21: .... .......... ..... ...... ......... ......
Regarding commercial off-the- self software (COTS) products purchased by organisations, we
asked the respondents to indicate how often they receive SBOMs from the manufacturers that
they collaborate with .
Overall, t he vast majority of the responses were ‘R arely ’ and ‘N ever’. 39 % of all organisations
responded ‘ Never’, 39 % ‘ Rarely ’, whereas only 2 % answered ‘Always’, implying that they have
standardised this practi ce as an official process.

Figure 22: COTS and .... ..... .. ...... ...... ....
2.4.3 Usage Patterns and Gaps
SBOM depth is crucial to determine if an organisation is effectively identifying risks in transitive
dependencies, build components and runtime environments. Figure 23 presents the level of
SBOM depth that organisations need versus what they receive.
A big gap between the need and actual result has been identified:
36 % of respondents stated that their organisations need all primary components and
direct dependencies with declared known unknowns but only 29 % actually receive
them, 24 % of the organisations need SBOMs with full depth analysis but only 14 %
receive them, while 27 % require SBOMs with depth analysis including declared
known unknows and only 12 % receive them.

SBOM Adoption State of Play – 2026
21

Besides the gap between the organisational needs and how they are addressed, it is important to
highlight the percentage of respondents who stated that they do not know what .... ..... .....
organisation needs versus what they receive.

Figure 23: Level of .... ..... ...... ... ........
The information provided by the SBOMs based on their depth wa s primarily used for the
identification and patching of vulnerabilities by 29 % of the organisations, for ensuring open -
source licen ces (OSS) are correctly used/declared by 22 %, for meeting regulatory
requirements by 19 %, for evaluating third -party software risks by 14 % and for maintaining an
up -to -date inventory of all components by 13 %.
As depicted in the following figure, t he respondents indicated that the primary stakeholders of
SBOM consumption we re the security and application security teams (3 4 % ) and the
development and engineering teams ( 34 %). T he legal/compliance teams and procurement
teams made limited use of .... ..........., .... .... .. % ... . % .. ... ............. ,
respectively , stat ing that th ese teams consume SBOM.

Figure 24: Primary use of SBOMs generated or received

As shown in Figure 25, 44 % of respondents report ed a ‘moderate gap ’ between generating
SBOMs and utili sing them while 23 % report ed a ‘significant gap ’. Only 7 % have closed the gap

SBOM Adoption State of Play – 2026
22

entirely, which indicates that SBOMs are not actively used to their full extent for security but
instead mainly for compliance purposes.

Figure 25: Gap in generating and consuming SBOMs
In an effort to close this gap, organisations are strategically investing i n .... ....... ...
automation. T he survey results show that 34 % of the organisations have invested in tools
dedicated to vulnerability handling via .... , .. % .. .......... ... ......... .. .... ..
the product’ s technical documentation for market surveillance authorities, 19 % in tooling
generating .... ... ... ....... .......... .... ... .......... ............ ... ..... ........
(achieving full completeness) in a machine- readable format and another 19 % in automating the
con tinuous update of SBOMs throughout the product ’s support period.

Figure 26: .... ....... ... .......... ..........
Based on the identified gaps and investment strategies among the organisations, the envisioned
approach to .... ........ .. ........ .. ...... ... .. % .. ... ............. ........ .... ....
aim to fully automate .... .......... . .. .... ......./..... . . ... .. % .. ...........
believed that their organisations will fully automate .... ....... ...... ... .......
support period and almost 23 % believe d that their organisations will partially automate this
proces s. A concerning result is that almost 32 % believe d that their organisations will automate
the .... ... .... ....... .. .......- ........ ...... ..... ...... .. % ........ .... .....
organisations will partially automate this process . This raises concerns about t he quality, ........
and usefulness of SBOMs. W hat comes as a surprise, though, is that most organisations are

SBOM Adoption State of Play – 2026
23

planning to partially automate vulnerability handling workflows tied to SBOM, raising concerns
about the ability to efficiently identify hidden r isks in the software components.

Figure 27: Envisioned approach to .... ........
To interpret the envisioned approach to .... ........, .. .... .. .......... ... .......
challenges that organisations are facing.
Figure 28 presents the challenges in leveraging SBOMs today.

Figure 28: Current challenges in leveraging SBOMs
When asked about the technical challenge of achieving a high degree of .... ............,
62 % of the respondents answered with quit e a lot or extremely difficult. At the same time, when
asked about the lack of quality and co mplete vendor -supplied SBOMs , 30 % of respondents
answered with quite a lot and 27 % with extremely . When asked about the lack of internal skills
or dedicated staff, r espondents answered with moderate (29 % ) or quite a lot (28 % ).
2.4.4 Barriers, Needs and External Supports
Div ing deeper in to the main barriers that prevent organisations from adopt ing SBOMs at scale, the
respondents were asked to rate the challenges presented in

SBOM Adoption State of Play – 2026
24

Figure 29. As show n in the heat map, data quality (37 %), supplier/third- party ....
availability/quality (31 % quite a lot and 30 % extremely), vulnerability matching (35 % quite a
lot and 23 % extremely) and process ownership/governance (33 % moderate) were rated as
the main barriers that could jeopardis e the broad adoption of .... ...... ..............

Figure 29: .... ........ ........
Solely identifying the main barriers is not enough, so the respondents needed to provide their
opinion on what would be useful to their organisations to improve their ability to produce and/or
consume SBOMs.

Industry consensus on best practices to integrate producing/consuming SBOMs into
software development practices was deemed the most critical (23 %), followed by industry
consensus on best practices to integrate producing/consuming SBOMs into risk and
compliance processes (19 %) and industry consensus on how to produce/consume
SBOMs and how these methods will evolve /improve over time (19 %).

SBOM Adoption State of Play – 2026
25

Figure 30: Elements improving the ability to produce or consume SBOMs
2.4.5 Vulnerability Management
Receiving vulnerability status or exploitability claims from suppliers wa s rated ‘critical’ by 39 %
and ‘important ’ by 37 % of respondents, as shown in Figure 31. Together, this accounts for 76 %
of respondents , underscor ing the significance of the coordinated vulnerability disclosure approach
outlined in the CRA.
As depicted in Figure 32, their preferred options for receiving such claims were automatically
(44 %) or via a standardised application programming interface (API ) (40 %).
Figure 31: Importance of receiving vulnerability status from suppliers

SBOM Adoption State of Play – 2026
26

Figure 32: Preferred metho ds for receiving vulnerability claims from suppliers
2.4.6 Interoperability Requirements
SBOM interoperability wa s rated ‘ critical’ by 30 % and ‘important ’ by 39 % of the respondents .
As shown in
Figure 34 , their preferred options to ensure delivery and interoperability were through
machine interfaces (32 %) and by supporting the conversion and compatibility
between formats (30 %).

Figure 33: .... ................ ..........

SBOM Adoption State of Play – 2026
27

Figure 34: Preferred .... ........ .. ................ .......
2.4.7 Supplier Requirements (for .... .........)
Only 10 % of respondents reported that their organis ation had established mandatory ....
requirements within supplier contracts . Assessing the overall responses, company size does
not appear to significantly influence the adoption of this practice, as the reported percentages
remain broadly consistent acros s organisation sizes, with the exception of medium -sized
enterprises .
It is essential though to highlight that 55 % of the respondents we re in the process of including
SBOM requirements in their supplier contracts in a systematic and consistent manner. 37 %
indicated that they already includ e them in an ad hoc manner, while 27 % we re planning to
include them.
Figure 35: .... ............ .. .........
Incorporating .... ............ .... ........... ........... ... ............. ... ... ... ....
of suppliers that align with the expectations of organisations . 45 % of organisations report ed
that only 0 % to 25 % of their suppliers meet their requirements, while just 2 % indicated that
75 % to 100 % of their suppliers meet these expectat ions. This highlights a substantial gap in
supplier readiness that contractual .... ............ ..... .... ........

SBOM Adoption State of Play – 2026
28


Figure 36: Suppliers providing adequate SBOMs
As depicted in Figure 37, supplier readiness gaps are primarily identified in three areas.
Specifically, 27 % of respondents report ed that supplier -provided SBOMs do not meet
completeness requirements , 17 % indicate d that .... ......... ........... ....
sufficient ........ ... .. % ......... .. ...... ....... .. ... ....... .. ........ ..
vulnerability references. These findings point out the quality challenges in supplier -generated
SBOM s.

Figure 37: Main gaps in supplier ’s SBOMs

SBOM Adoption State of Play – 2026
29

2.4.1 Guidance
Targeted external guidance is expected to support organisations across the EU market in
overcoming barriers, responding to organisational needs and accelerat ing the .... ........
progress.


Figure 38: Areas t hat would benefit from guidance or templates
In particular, 31 % of respondents considered the development of a profile defining
what constitutes a ‘good enough’ .... .. .. .........., .. % ...... ... ...
standardisation of .... ....... ... ..... ........ ......, ... .. % ... ..... .. ...
development of a risk .......... ......... .... ......... .... .....

SBOM Adoption State of Play – 2026
30

3. Conclusions



The .... ... ...... ........ ....... .... .. ... ............. ...... .......... ... ..
varying sizes are approaching .... ........ .. ........ .. ... .... ......., ... .......
demonstrate that the ... .. ....... ...... .. . .......... ....... ... ....
implementation, while also revealing some maturity gaps, operational challenges, and
areas where further ecosystem alignment is required to enable sustainable adoption at
scale.
A central conclusion from the survey is that the CRA , while still in transitional period is
already shaping organisational investment priorities and capability development.
Respondents indicated that the regulation is acting as an accelerator for .... .........
This demonstrates that the regulation is functioning as an early market signal influencing
security engineering practices, supply -chain transparency, and compliance strategies.
Respondents reported that their organisations are progressing in their .... ........
journey, with expectations to reach a level of maturity aligned with ... ............
within planned timeframes . Technical external support is needed to accelerate ....
adoption at scale across all organisations, with the need for a n .... .........
Implementation ranking #1 .
The value of SBOM s is identified in risk reduction , cost avoidance and operational
efficiency . .... . ... ......... ...... .. . ......... ............. ......... ,
particularly supporting vulnerability management, licence compliance and regulatory
compliance activities. These use cases align closely with the expectations established under
the ... ... .... ... ...... -.. -...... ...........
There is a strong alignment across respondents regarding format -related requirements.
Respondents broadly recognised that SBOMs must be provided in commonly used and
machine- readable formats to support supply chain transparency at scale. This alignment is
consistent with the expectations articulated in the ... ... ........ ... .... ....
interoperability is not just a technical preference but a requirement for operationalising SBOM.

SBOM Adoption State of Play – 2026
31




Despite progress, respondents identified several challenges affecting implementation
quality and scalability. Among the most frequently cited were .... ............, ....
quality limitations, and shortages of internal skills and specialised staff. These challenges
reflect that .... ........ .. ... .... . ....... . ...., ... .... .. .............. ..........
issue requiring process adaptation and workforce development.
While many respondents reported producing SBOMs with full dependency depth , others
indicated that their current practices remain limited to primary components and direct
dependencies. D eeper dependency visibility is essential for effective vulnerability
management and supply -chain risk management, enabled by comprehensive ....
c overage with full transparency across transitive dependencies .
Respondents indicated that SBOMs are incr easingly generated and consumed during
build-stage activities , suggesting a direct integration into software development
pipelines rather than a post -release documentation activity. Such integration represents an
important step towards achieving continuous transparency across the software life cycle,
supporting timely vulnerability analysis and facilitating more effective risk management.
Respondents expressed concern about t he absence of widely accepted industry best
practices for integrating .... .......... ... ........... .... .... ........
development workflows and organisational risk management processes. The lack of
consensus in this area is one of the most significant challenges identified . These findings
indicate that organisations are not only seeking technical specifications or standards but
also operational guidance .
Respondents highlighted various priority areas where further support would accelerate
adoption. These include the development of a profile defining what constitutes a ‘good
enough’ .... ... ......... ..., ... ............... .. .... ....... ... ........
data fields and the establishment of a risk .......... ......... ....... ..
leveraging .... ............

enisa.europa.eu
TP
-01
-26
-008
-EN
-N
ABOUT ENISA
The European Union Agency for Cybersecurity, ENISA, is the Union ’s agency
dedicated to achieving a high common level of cybersecurity across Europe.
Established in 2004 and strengthened by the EU Cybersecurity Act, the European
Union Agency for Cybersecurity contributes to EU cyber policy, enhances the
trustworthiness of ICT products, services and processes with cybersecuri ty
certification schemes, cooperates with Member States and EU bodies, and helps
Europe prepare for the cyber challenges of tomorrow. Through knowledge sharing,
capacity building and awareness raising, the Agency works together with its key
stakeholders to strengthen trust in the connected economy, to boost resilience of
the Union ’s infrastructure, and, ultimately, to keep Europe’ s society and citizens
digitally secure. More information about ENISA and its work can be found here:
www.enisa.europa.eu .
ENISA
European Union Agency for Cybersecurity
Athens Office
Agamemnonos 14
Chalandri 15231, Attiki, Greece
Brussels Office
Rue de la Loi 107
1049 Brussels, Belgium


Link: https://www.enisa.europa.eu/sites/default/files/20

Testo del 2026-06-13 Fonte: europa.eu




Commenta



i commenti sono anonimi e inviati via mail e cancellati dopo aver migliorato la voce alla quale si riferiscono: non sono archiviati; comunque non lasciare dati particolari. Si applica la privacy policy.


Ricevi gli aggiornamenti su SBOM Adoption State of Play  PDF e gli altri post del sito:

Email: (gratis Info privacy)






Nota: il dizionario è aggiornato frequentemente con correzioni e giurisprudenza










Forum Banca 2026