Skip to content
KOLOSALTech

SBOM and supply chain cyber: why your SME must adopt it in 2026

·7 min read

SBOM (Software Bill of Materials), European CRA, supply chain vulnerabilities: what becomes mandatory in 2026 and how to prepare pragmatically.

Supply chain cyber attacks (SolarWinds, Kaseya, MOVEit, XZ Utils) have proven that software is only as secure as its weakest link. In 2026, SBOM (Software Bill of Materials) becomes an essential topic for SMEs too.

1. What is an SBOM?

An SBOM is a detailed inventory of all software components (libraries, dependencies, open source modules) that make up an application. It's the equivalent of an ingredient list for a food product, but for code.

Standard formats: SPDX (Linux Foundation), CycloneDX (OWASP), SWID (ISO).

2. Why it became critical

  • Log4Shell vulnerability (Dec 2021): 1 line of Java logging code paralyzed thousands of companies worldwide. Without SBOM, impossible to know who was impacted.
  • XZ Utils backdoor (Mar 2024): a malicious maintainer inserted a backdoor in a library used by OpenSSH. Detected by chance 4 days before widespread rollout.
  • European Cyber Resilience Act (CRA, applicable 2027): all publishers selling in the EU must provide machine-readable SBOM + manage vulnerabilities over 5 years.

3. How to generate an SBOM on the publisher side

  • Syft (Anchore): open source, scans Docker images / repos, generates CycloneDX/SPDX SBOM
  • cdxgen (CycloneDX): universal, supports 30+ languages
  • npm sbom (built-in npm 11+): for Node.js projects
  • GitHub Dependency Graph + Dependabot: auto SBOM on all GitHub repos
  • Trivy (Aqua): vulnerability scan + SBOM as bonus

4. What an SME user should ask its suppliers

Without being a publisher, your SME can require:

  • Any critical software supplier: CycloneDX SBOM available on request
  • Update frequency: with every major release + as soon as a critical CVE is discovered in a dependency
  • Vulnerability disclosure policy (security.txt + patch timeline)
  • CRA European compliance (from 2027 onwards)
  • For SaaS: SBOM attestation or equivalent SOC 2 Type II report

5. 90-day action plan for SMEs

Month 1 — Inventory

  • List all critical software (ERP, CRM, business apps, antivirus, backup)
  • Request SBOM or compliance attestation from each publisher
  • Assess publisher maturity (refusal = warning sign)

Month 2 — Monitoring

  • Set up CVE watch on identified components (Snyk, GitHub Advisory, ANSSI CERT-FR)
  • Email notifications for critical CVEs affecting your stack
  • Impact assessment procedure + patch within 7 days

Month 3 — Procurement integration

  • Systematic SBOM clause in all new supplier contracts
  • Decision criterion in RFPs
  • Documentation: SBOM registry + vulnerability policy

6. Link with NIS2

NIS2 art. 21 imposes "supply chain security." In practical terms: audit critical suppliers, require contractual guarantees, action plan in case of supplier incident. SBOM = one of the tools to materialize this governance.

Conclusion

SBOM is no longer a niche technical requirement: it becomes the common language of cyber supply chain. SMEs that adopt it in 2026 gain a competitive edge and prepare for CRA 2027 without pain. KOLOSALTech supports supplier audits + SBOM governance setup + CVE monitoring.

#SBOM#Supply chain#CRA#NIS2
Free guide · 30 pages

SME Cybersecurity 2026 — essential guide

NIS2, 3-2-1 backup, MFA, EDR, 90-day action plan.

Get the guide

An IT/ICT or export project to discuss?

Let's talk about your concrete needs. Reply within 24/48 business hours.

Request a quote