CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation
UD2.208 (Decroly) | Day 2 | 11:30 - 12:00 | Speakers: Viktor Petersson
Abstract
As one of the co-leaders of the CISA working group on SBOM Generation and a contributor to its accompanying whitepaper, I’ve spent the last few years deep in the trenches of SBOM creation. With the EU’s Cyber Resilience Act (CRA) raising the bar for software transparency and lifecycle security, the need for reliable, high-quality SBOMs has never been more urgent.
In this talk, I’ll present a practical blueprint for SBOM generation that goes beyond minimal compliance and helps projects prepare for the expectations emerging from the CRA and similar regulatory frameworks. The model breaks SBOM creation into four clear phases:
- Authoring – producing the initial SBOM from a lockfile
- Augmenting – resolving gaps and adding metadata to meet increasingly strict transparency requirements that SBOM generation tools can't do
- Enriching – improve the quality of the SBOM using open data sets
- Signing – provide attestation to ensure the SBOM can be trusted
I’ll discuss the technical considerations behind each phase, common pitfalls, and how these practices help projects avoid the compliance gaps many teams are now discovering as the CRA timeline approaches.
To ground everything in reality, I’ll demo a fully open-source workflow built with the sbomify action, a tool from sbomify that runs in GitHub Actions or any CI environment, enabling CRA-ready SBOM pipelines without proprietary tooling.
Speakers
Viktor is a serial entrepreneur and cybersecurity innovator, currently focused on shaping the future of software security and compliance. As the founder of sbomify, he simplifies Software Bill of Materials (SBOM) management, helping organizations navigate emerging cybersecurity regulations such as the Cyber Resilience Act (CRA). Viktor is also the cofounder of Screenly, a leading secure digital signage platform that powers over 10,000 screens globally, trusted by security-conscious organizations like NASA, Lowe's, and Capital One.
An advocate for secure and efficient technology practices, Viktor is passionate about helping companies adapt to the rapidly evolving cybersecurity landscape. He shares insights and industry trends through his podcast, Nerding Out With Viktor, engaging with thought leaders and technologists to explore what's next in tech security, innovation, and compliance.
Links
External Links
Notice: The placeholder video image is licensed under CC BY-SA 4.0. The original image can be found hereChanges made to the image are: Cropped the image to a new ratio, part of the image was cut off.
