SBOM
A Software Bill of Materials (SBOM) is the structured inventory of every software component, library, and dependency that makes up a software product or a product containing embedded software. The SBOM lists component names, versions, licenses, and supply-chain origins in a machine-readable format (SPDX, CycloneDX). SBOM requirements have become regulatory in the US (Executive Order 14028, FDA guidance for medical devices) and are entering the EU Digital Product Passport framework as electronic products proliferate.
In context
A medical device manufacturer producing an implantable pump submits an SBOM to the FDA listing every open-source library, third-party component, and version hash in the device firmware — enabling the regulator to verify no known-vulnerable software is present. When Log4Shell was discovered in 2021, manufacturers with complete SBOMs in their PLM could assess exposure across their entire product fleet within hours; those without SBOMs spent weeks doing manual inventory.
Why it matters
Modern engineered products contain as much software as hardware — an automotive ECU, a medical infusion pump, an industrial controller all ship with embedded code stacks that are themselves supply chains. Without an SBOM, manufacturers cannot assess vulnerability exposure (Log4Shell, SolarWinds) or comply with emerging cyber-resilience regulation. PLM's role here is expanding: managing the SBOM alongside the hardware BOM, linking software versions to product configurations, and feeding SBOM data into lifecycle traceability.
Related concepts
External References
This term appears in
Cite this definition
Finocchiaro, Michael. “SBOM.” DemystifyingPLM PLM Glossary, 2026, https://www.demystifyingplm.com/glossary/sbom