→ Back to Home
Cybersecurity

SBOMs in 2026: Everyone's Generating Them, No One's Using Them

A recent ENISA report, titled "SBOM Adoption State of Play 2026," has brought to light a critical disparity within the realm of software supply chain security. The report indicates that despite widespread adoption in generating Software Bills of Materials (SBOMs), organizations are largely failing to leverage these crucial documents for proactive security measures. The survey, which gathered insights from 334 organizations—predominantly from the EU and subject to the Cyber Resilience Act (CRA)—found that 39% of companies generate SBOMs at build time, and 74% have at least partially automated their per-release generation processes. However, the effective consumption of these SBOMs for security intelligence is lagging significantly. Approximately 44% of respondents acknowledged a moderate gap between their SBOM generation efforts and actual utilization, with a further 23% reporting a substantial gap. A mere 7% of organizations have managed to close this gap entirely, and a concerning 20% remain unaware of how SBOMs are consumed within their own structures. ENISA's findings suggest that the primary driver for SBOM generation is often compliance, rather than a strategic approach to enhancing security posture. Several factors contribute to this operational shortfall. Despite over 90% of organizations expressing concern regarding supply chain security, only 34% allocate significant resources to address these concerns. The problem is exacerbated by a skills shortage, with 57% of respondents identifying a lack of expertise or trained staff as a major impediment to effective SBOM utilization. Furthermore, 62% of organizations find it challenging to achieve a high degree of completeness in their SBOM data. The article stresses that while SBOMs provide transparency into software components, a holistic security strategy must also encompass the protection of build and development environments, especially as supply chain attacks increasingly target CI/CD pipelines and developer workstations, addressing blind spots that SBOMs alone cannot cover.
#sbom#software supply chain#supply chain security#enisa#cra compliance#vulnerability management
Read original source