Cybersecurity Glossary

Software Bill of Materials

A list of the components inside a piece of software, so you can tell whether a new flaw affects you.

What Software Bill of Materials means

Modern applications are assembled from hundreds of open source and commercial parts. When a serious flaw appears in one of them, the first question is whether you are running it. Without a component list that question takes days of guessing. With one it takes minutes.

Why Software Bill of Materials matters for small businesses and nonprofits

Small organisations rarely build software, but they buy it, and they can ask for the list. It turns a vendor's reassurance into something you can check, and it makes the next widely reported flaw a short conversation rather than a scramble.

What to do about Software Bill of Materials

Three steps to deal with Software Bill of Materials

  • Ask for a component list from suppliers of anything that touches customer or financial data
  • Keep the lists somewhere searchable, so a new flaw can be checked against them quickly
  • Agree with the supplier how fast they will tell you when one of their components is affected

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.

A list of the components inside a piece of software, so you can tell whether a new flaw affects you.