Software Bill of Materials

Generate a complete software inventory

Build a complete software inventory (SBOM) with dependency trust scores and quality assessment.

Lumstep software inventory dashboard listing tracked packages, versions, and licenses

Why SBOM matters

Auditors and regulators will ask for this. Have it ready.

The EU Cyber Resilience Act requires software vendors to maintain and share SBOMs by December 2027. NIS2 and SOC 2 Type II supply chain evidence all point the same direction. Beyond compliance, an SBOM is how you answer "are we affected?" in minutes instead of days the next time a package makes headlines - and how license conflicts get caught before legal or an auditor finds them.

  • Audit-ready evidence for CRA, NIS2 and SOC 2 Type II, generated automatically
  • Surface license conflicts or restrictive licenses for early review
  • Track your exposure to newly disclosed vulnerabilities across your dependencies
compliance coverage3 of 3 frameworks →
EU Cyber Resilience ActSBOM required by Dec 2027Covered
NIS2Supply-chain evidence requiredCovered
SOC 2 Type IISupply-chain evidence requiredCovered
gpl-licensed-lib 2.1.0GPL-3.0 conflict detectedFlagged
Generate & score

A complete SBOM, graded before sharing.

On every scan, generates a complete software inventory: every direct and transitive package. Assesses its quality, track dependencies and licenses, assign a trust score to each dependency, measure completeness and accuracy

  • Generate a complete software inventory, including direct and transitive dependencies
  • Track dependencies and licenses, with a trust score for every dependency
  • Assess inventory quality through completeness and accuracy metrics
acme/payments-api312 components resolved →
A−SBOM quality scoreCompleteness & accuracy assessed8.5 / 10
express4.19.2 · MITClean
lodash.template4.5.0 · unknown licenseReview
gpl-licensed-lib2.1.0 · GPL-3.0GPL conflict
Export & share

Export in the required format.

Every SBOM is generated in both CycloneDX and SPDX - the two formats legal teams, auditors, and regulators expect. Export it straight from your dashboard the moment it's requested, with no extra tooling and no reformatting.

  • Generate SBOMs and export directly from your dashboard when needed
  • Share standardized outputs without reformatting or extra tooling
export formatsready on every scan →
CycloneDX
JSON · OWASP standard
SPDX
ISO/IEC 5962 standard
RecipientsLegal · auditors · procurement
License insight

Identify license risks early.

Review license information for every dependency from a single software inventory. Identify dependencies that may require additional review for compliance or distribution.

  • Centralize dependency and license info in one inventory for faster reviews
  • Identify dependencies needing further review for compliance or distribution
license breakdown · 244 packages4 flagged →
MIT184Clean
Apache-2.056Clean
GPL-3.01Conflict
Unknown3Review
FAQ

FAQ about SBOM

What is an SBOM?

A software bill of materials (SBOM) is a complete inventory of every package your software depends on, direct and transitive, along with its version and license. Lumstep generates one automatically on every scan.

Why does an SBOM matter beyond compliance?

The EU Cyber Resilience Act requires vendors to maintain and share SBOMs by December 2027, and NIS2 and SOC 2 Type II both expect supply-chain evidence. Beyond audits, it's how you answer "are we affected?" in minutes the next time a package makes headlines.

Isn't a package.json or requirements.txt already an SBOM?

No. Those files list only the dependencies you declared directly. Lumstep's SBOM also resolves every transitive dependency pulled in behind them, tracks each one's license, and scores the inventory for completeness and accuracy.

What formats does Lumstep export SBOMs in?

Every SBOM is generated in both CycloneDX and SPDX, the two formats legal teams, auditors, and regulators expect.

How is an SBOM's quality measured?

Each SBOM gets a quality score based on completeness and accuracy, ensuring compliance before you share it.

How do I get my SBOM to an auditor or customer who's asking for one?

Export it directly from your dashboard the moment it's requested, in CycloneDX or SPDX, with no extra tooling or reformatting.

My SBOM lists 1,400 packages. Should I be worried?

Not by the number itself - a modern application pulling in a thousand-plus packages is normal, and most arrived transitively rather than by choice. What matters is how many you can't account for: the unmaintained ones, the ones with unclear licenses, the ones nobody on your team picked. That's what the quality score and per-dependency trust scores are for.

Generate your first SBOM in minutes.

Free early access. Your SBOM is ready on the first scan, with no extra configuration.

Get early access