The Growth in SBOM Publication
Data from CISA's SBOM tracking shows that SBOM publication grew from approximately 68 new SBOMs per day in March 2022 to over 150 per day by year-end — more than doubling in nine months. The majority of this growth came from federal contractors complying with EO 14028 requirements, but commercial adoption outside the federal market has also accelerated as enterprise customers began requiring SBOMs from their software vendors.
Where Adoption Lags
Despite the growth, gaps remain significant. A 2022 survey by the NTIA found that only 62% of software organizations had adopted any form of SBOM monitoring or generation. Among those that had, a significant portion were generating SBOMs manually or only for a subset of their products. True automation — SBOM generation integrated into CI/CD for every product and every release — remained the exception rather than the rule.
The Tooling Ecosystem Has Matured
The availability and quality of SBOM tooling improved dramatically in 2022. Syft reached production stability. CycloneDX 1.4 was released with improved security features. Major commercial platforms including Black Duck, Snyk, and FOSSA invested heavily in SBOM generation and management capabilities. The emergence of specialized platforms focused specifically on SBOM compliance — rather than treating it as a secondary feature — has given organizations more options for building compliant programs.
The Federal Market as a Leading Indicator
The federal government's requirements are functioning as a leading indicator for commercial adoption. Vendors that built SBOM programs to meet federal requirements are finding that the same practices are increasingly demanded by enterprise commercial customers — particularly in finance, healthcare, and critical infrastructure. Organizations that dismissed SBOM as a "government thing" in 2021 are now receiving SBOM requests from their largest commercial accounts.
What 2023 Will Bring
The FDA's March 2023 deadline for SBOM in medical device submissions will be the next major compliance event. EU Cyber Resilience Act discussions are advancing, putting SBOM on the radar for European technology companies. And CISA's continuous publication of SBOM guidance is filling in the implementation details that early adopters have been waiting for. The trajectory points clearly toward SBOM becoming a universal software industry practice within the next two to three years.
Get Ahead of the SBOM Curve with Fossity
Fossity — Organizations that build SBOM programs now — before regulatory pressure reaches their industry — are in the strongest security and compliance posture. Fossity gives you the tools to get there quickly: automated SBOM generation, continuous monitoring, and compliance reporting for every regulatory framework.
Visit Fossity.com →