What Has Matured
SBOM generation tooling is now genuinely mature. Open source tools like Syft and Trivy produce high-quality SBOMs across most ecosystems. Commercial platforms offer enterprise-grade generation with policy enforcement. The formats (SPDX 3.0, CycloneDX 1.6) have stabilized and are well-supported. Most major CI/CD platforms have native or first-party integrations for SBOM generation. The days of "how do I even generate an SBOM?" as the primary question are largely behind us.
Vulnerability matching quality has improved significantly. The proliferation of vulnerability databases (NVD, OSV, GHSA, ecosystem-specific databases) alongside better PURL standardization has reduced false positive rates substantially. Reachability analysis, pioneered by Snyk and now available in several platforms, further reduces alert fatigue by distinguishing exploitable from theoretical vulnerabilities.
What Still Falls Short
SBOM consumption tooling remains underdeveloped. While generation tools are mature, the tooling for consuming, validating, and acting on SBOMs received from third parties is still limited. Organizations that need to ingest SBOMs from their software vendors — a requirement in federal procurement and EU CRA supply chain provisions — often still process those SBOMs manually.
SBOM quality assurance is inconsistent. Without widespread adoption of SBOM quality benchmarks, the SBOMs organizations receive from vendors vary enormously in completeness and accuracy. A SBOM that meets the NTIA seven fields in theory may still be practically useless if PURLs are incorrect, versions are imprecise, or the dependency graph is shallow.
What 2026 Will Bring
The EU CRA's September 2026 vulnerability reporting deadline will drive another wave of SBOM tooling investment, particularly in Europe. The CISA 2025 Minimum Elements update will push vendors to improve SBOM quality and completeness. AI-assisted SBOM analysis — using ML to identify anomalous components or unexpected dependency changes — is emerging as the next frontier. And the AI Bill of Materials (AIBOM) concept will mature as organizations grapple with managing the security of the ML models embedded in their software.
Fossity: Built for the Matured SBOM Ecosystem
Fossity — Fossity has grown alongside the SBOM ecosystem — continuously improving generation accuracy, expanding ecosystem coverage, and building the compliance reporting capabilities demanded by EO 14028, FDA, EU CRA, and PCI DSS 4.0. See how Fossity's 2025 platform compares to where tools were when you last evaluated.
Visit Fossity.com →