sbomcompliancessdfeu-cratrends

Anchore — SBOMs in 2025: Trends & Predictions

Outlines the regulatory drivers for SBOM adoption and identifies build-native metadata propagation as the future of supply chain transparency.

Summary

By 2025, Software Bills of Materials (SBOMs) have transitioned from a suggested best practice to a mandatory requirement for securing the software supply chain, driven by global regulatory shifts like the EU Cyber Resilience Act (CRA) and the US Executive Order 14028. Research shows that 70-90% of modern applications are composed of OSS dependencies, making SBOMs the focal point for scaling vulnerability management and ensuring transparency across complex digital infrastructure. Two major trends are emerging: steady regulatory pressure forcing all federal agencies to comply with the NIST Secure Software Development Framework (SSDF), and foundational ecosystems beginning to implement build-native SBOM support. The Yocto Project's OpenEmbedded build system already includes native SBOM generation, establishing a blueprint for automating transparency directly within the developer toolchain to prevent hidden supply chain complexity from being exploited.

Gaps Analysis

Evidence

Foundational software ecosystems begin to implement build-native SBOM support... producers will generate SBOMs as part of standard build pipelines.

Blind Spot

Risk Guard analyzes existing manifest files but doesn't integrate with 'Build-Native' metadata generators to verify the provenance of an artifact.

Actionable Capability

Risk Guard would be better if it could ingest and verify 'Build-Time Attestations' (SLSA) alongside standard SBOM manifests.

← Previous Next →