SBOM Compliance in Financial Services: Banks, Insurers, and the DORA / PCI DSS Double Mandate

Financial institutions occupy a unique position in the SBOM compliance landscape: they are simultaneously subject to PCI DSS 4.0's software component inventory requirement (Requirement 6.3.2), DORA's ICT asset register and third-party risk management obligations, and potentially EO 14028 requirements if they operate in the U.S. federal market. Building separate compliance programs for each framework is both inefficient and unnecessary — the underlying capability they all require is the same.

The Overlapping Requirements

PCI DSS 4.0 Requirement 6.3.2 requires a component inventory for custom software that is used to identify and remediate security vulnerabilities. DORA Article 8 requires an ICT asset register that documents software components, their versions, and interdependencies. Both requirements are satisfied by the same artifact: a machine-readable SBOM for each application in scope, maintained continuously through automated CI/CD integration.

The DORA ICT Register as SBOM Extension

DORA's ICT register has a broader scope than PCI DSS's component inventory requirement — it includes hardware assets, third-party service dependencies, and system interconnections alongside software components. Organizations should view the SBOM as providing the software layer of the DORA ICT register, with the register built by combining SBOM data with hardware inventory and service dependency mapping from existing CMDB (Configuration Management Database) systems.

Third-Party Risk: Where DORA Goes Further

DORA places significant emphasis on ICT third-party risk that PCI DSS addresses less directly. Financial institutions must assess concentration risk from critical ICT providers, require contractual cybersecurity provisions from vendors, and conduct ongoing monitoring of critical technology providers' security posture. Requesting SBOMs from critical technology vendors and monitoring those SBOMs for newly disclosed vulnerabilities is a concrete implementation of DORA's third-party monitoring requirements.

Building the Unified Program

The recommended approach is to build a single SBOM program that generates evidence for both frameworks: automated SBOM generation for all custom and critical commercial applications; continuous vulnerability monitoring with documented remediation workflows; vendor SBOM collection for critical third-party providers; and centralized SBOM management with audit trails that can be produced for QSA review (PCI) and regulatory examination (DORA supervisors). One SBOM platform, two compliance frameworks addressed.

// Recommended Tool

Unified SBOM Compliance for Financial Services with Fossity

Fossity — Fossity helps financial institutions satisfy DORA ICT asset management and PCI DSS 4.0 Requirement 6.3.2 from a single SBOM platform — reducing the compliance complexity of multiple overlapping frameworks with one unified program.

Visit Fossity.com →
// Author: Esteban C.