2025 in Review: SBOM Compliance Becomes a Global Standard

In January 2025, Software Bill of Materials was still considered by many organizations outside the U.S. federal market as a compliance concern they could monitor from a distance. By December 2025, that position is no longer tenable. PCI DSS 4.0 full compliance took effect in March. DORA became applicable in January. The EU CRA entered into force in December 2024 with a compliance clock running. SBOM is now a global standard for responsible software production.

The Regulatory Milestones of 2025

March 31, 2025 marked the end of the PCI DSS 3.2.1 grace period. From that date, all organizations subject to PCI DSS must comply with version 4.0, including Requirement 6.3.2's software component inventory mandate. This brought SBOM requirements into the payment card processing ecosystem globally — affecting tens of thousands of merchants, payment processors, and financial institutions that had previously been outside the SBOM conversation.

The NTIA published updated SBOM Minimum Elements in mid-2025, refining the 2021 guidance with lessons from four years of practical implementation. The new guidance strengthened requirements for PURL accuracy, introduced recommendations for SBOM quality tiers, and for the first time provided specific guidance on SBOM freshness — how current an SBOM must be to be considered valid for compliance purposes.

Security Events That Reinforced SBOM's Value

2025 saw continued elevated rates of software supply chain attacks. The response time differential between organizations with mature SBOM programs and those without remained stark — with SBOM-equipped organizations consistently resolving major vulnerability exposure in hours rather than days. This empirical evidence has strengthened the business case for SBOM investment with executive and board audiences in ways that compliance arguments alone could not.

The AI Supply Chain Dimension

2025 brought increasing attention to the security of AI models embedded in software products. As organizations incorporated pre-trained models from open source repositories like Hugging Face, questions arose about the "ingredients" of those models — training data provenance, model architecture details, and security validation. The AI Bill of Materials (AIBOM) concept, extending SBOM principles to ML models, moved from research concept to practical initiative with early tooling available from several vendors.

Looking Ahead to 2026

The EU CRA's September 2026 vulnerability reporting deadline creates the next major compliance event. Organizations that have not yet built vulnerability disclosure processes and connected them to their SBOM monitoring infrastructure must do so in the first half of 2026. The approaching deadline is already driving investment, particularly among European software companies and U.S./Asian companies with material EU revenue. 2026 will also likely see the first major enforcement actions under the CRA, establishing precedents that will shape industry behavior for years.

// Recommended Tool

Enter 2026 Compliant and Confident with Fossity

Fossity — As SBOM compliance becomes a global baseline in 2026, Fossity gives your organization the tooling to meet every major regulatory framework — EO 14028, FDA, EU CRA, PCI DSS 4.0, and DORA — from a single unified platform. Start 2026 ahead of the curve.

Visit Fossity.com →
// Author: Esteban C.