Knowledge · Supply chain
Checking supplier SBOMs: completeness and vulnerabilities
Ben Plannet, co-founder and CTO of LegacyMind GmbH · As of 5 October 2026
The short answer
You check a supplier's SBOM for three things: whether it is technically valid, whether the fields you need for your own documentation are filled, and which known vulnerabilities its components have. Whether the SBOM matches the shipped image only shows once you compare it with what is actually in the image.
Why you check your supplier's SBOM
Annex I Part II of the Cyber Resilience Act requires manufacturers to identify and document the components of their product, at least the top-level dependencies, in a commonly used machine-readable format. If you buy in controllers, modules or firmware, that part comes from your suppliers. Their SBOM becomes part of your own documentation.
An SBOM is a statement by the supplier about its product. Whether it is right does not show in the file itself.
Doing it by hand
- Check the format: validate the file against the CycloneDX or SPDX schema. Both projects publish their schemas.
- Check the required fields: for every component its creator, name, version, file name, dependencies, licence and SHA-512 hash. Missing versions are the most common gap; without a version no CVE match is possible.
- Check the identifiers: does every component have a purl or CPE? Without one you map names by hand.
- Match vulnerabilities: check the components against the NVD, vendor advisories (CSAF) and the CISA KEV catalogue.
- Compare with the image: build an inventory of the shipped image and put it next to the SBOM. What is in the image but missing from the SBOM is the real gap.
The per-component fields BSI TR-03183-2 names
Technical Guideline TR-03183-2 of Germany's BSI (version 2.1.0, 20 August 2025) describes what an SBOM contains at a minimum. The list works as a requirement for suppliers. For the SBOM itself it names the creator and a timestamp, and as formats CycloneDX 1.6 or later and SPDX 3.0.1 or later. Vulnerabilities, it says, belong in a separate document, not in the SBOM.
| Data field | Content |
|---|---|
| Component creator | Email or URL of the component's creator |
| Component name | Name the creator assigns |
| Component version | The creator's version, otherwise the file's modification date |
| Filename | Actual file name of the component |
| Dependencies | Direct dependencies, stating whether the list is complete |
| Distribution licences | Licence as an SPDX identifier |
| Hash | SHA-512 of the deployable component |
| Executable, archive, structured | Whether executable, an archive, with metadata kept |
What LegacyMind does automatically
Your suppliers' SBOMs in CycloneDX (JSON, XML) or SPDX (JSON, tag-value, SPDX 3.0 JSON-LD), up to 64 MB. The format is detected from the document, not the file name. Every component is matched against the vulnerability sources.
The match uses 12 sources, among them the distribution trackers, the NVD and the CSAF advisories of BSI, Siemens, CERT@VDE and CISA, enriched with CISA KEV and EUVD. Your suppliers' component names go to no public query API.
Today you get two results side by side: the measured inventory of the image and the CVE matching of the supplier SBOM. Both sit on the same device, so you can read them next to each other. The automatic check of which declared component is actually in the image is in progress.
You make the conformity statement. This page and our reports provide technical findings as its basis.
Questions
- Which formats should a supplier SBOM have?
- CycloneDX and SPDX are common, as JSON or XML or tag-value. BSI TR-03183-2 names CycloneDX 1.6 or later and SPDX 3.0.1 or later for newly generated SBOMs.
- Is an SBOM without versions enough?
- No. Without a version you cannot say whether a known vulnerability affects the delivered component. Ask for the versions.
- Do vulnerabilities belong in the SBOM?
- Not under TR-03183-2. The SBOM describes the components; vulnerabilities change daily and belong in a separate document, for example CSAF with VEX.
- How do I know the SBOM matches the image?
- By building an inventory of the image itself and comparing the two lists. A binary analysis of the image provides that inventory without source code.
Sources
Read on
Check your own image
The app and the reports are in German. Questions in English are welcome.