SBOM Adoption: Where the Industry Stands 18 Months After EO 14028

Eighteen months after Executive Order 14028 mandated Software Bill of Materials practices for federal software vendors, the SBOM ecosystem has made remarkable progress — and also revealed significant gaps. SBOM publication has grown from near-zero to hundreds of new documents per day. Tooling has matured dramatically. Yet most organizations outside the federal supply chain have not yet built the SBOM programs they need.

The Growth in SBOM Publication

Data from CISA's SBOM tracking shows that SBOM publication grew from approximately 68 new SBOMs per day in March 2022 to over 150 per day by year-end — more than doubling in nine months. The majority of this growth came from federal contractors complying with EO 14028 requirements, but commercial adoption outside the federal market has also accelerated as enterprise customers began requiring SBOMs from their software vendors.

Where Adoption Lags

Despite the growth, gaps remain significant. A 2022 survey by the NTIA found that only 62% of software organizations had adopted any form of SBOM monitoring or generation. Among those that had, a significant portion were generating SBOMs manually or only for a subset of their products. True automation — SBOM generation integrated into CI/CD for every product and every release — remained the exception rather than the rule.

The Tooling Ecosystem Has Matured

The availability and quality of SBOM tooling improved dramatically in 2022. Syft reached production stability. CycloneDX 1.4 was released with improved security features. Major commercial platforms including Black Duck, Snyk, and FOSSA invested heavily in SBOM generation and management capabilities. The emergence of specialized platforms focused specifically on SBOM compliance — rather than treating it as a secondary feature — has given organizations more options for building compliant programs.

The Federal Market as a Leading Indicator

The federal government's requirements are functioning as a leading indicator for commercial adoption. Vendors that built SBOM programs to meet federal requirements are finding that the same practices are increasingly demanded by enterprise commercial customers — particularly in finance, healthcare, and critical infrastructure. Organizations that dismissed SBOM as a "government thing" in 2021 are now receiving SBOM requests from their largest commercial accounts.

What 2023 Will Bring

The FDA's March 2023 deadline for SBOM in medical device submissions will be the next major compliance event. EU Cyber Resilience Act discussions are advancing, putting SBOM on the radar for European technology companies. And CISA's continuous publication of SBOM guidance is filling in the implementation details that early adopters have been waiting for. The trajectory points clearly toward SBOM becoming a universal software industry practice within the next two to three years.

// Recommended Tool

Get Ahead of the SBOM Curve with Fossity

Fossity — Organizations that build SBOM programs now — before regulatory pressure reaches their industry — are in the strongest security and compliance posture. Fossity gives you the tools to get there quickly: automated SBOM generation, continuous monitoring, and compliance reporting for every regulatory framework.

Visit Fossity.com →
// Author: Esteban C.