Generate a complete software inventory
Build a complete software inventory (SBOM) with dependency trust scores and quality assessment.

Auditors and regulators will ask for this. Have it ready.
The EU Cyber Resilience Act requires software vendors to maintain and share SBOMs by December 2027. NIS2 and SOC 2 Type II supply chain evidence all point the same direction. Beyond compliance, an SBOM is how you answer "are we affected?" in minutes instead of days the next time a package makes headlines - and how license conflicts get caught before legal or an auditor finds them.
- Audit-ready evidence for CRA, NIS2 and SOC 2 Type II, generated automatically
- Surface license conflicts or restrictive licenses for early review
- Track your exposure to newly disclosed vulnerabilities across your dependencies
A complete SBOM, graded before sharing.
On every scan, generates a complete software inventory: every direct and transitive package. Assesses its quality, track dependencies and licenses, assign a trust score to each dependency, measure completeness and accuracy
- Generate a complete software inventory, including direct and transitive dependencies
- Track dependencies and licenses, with a trust score for every dependency
- Assess inventory quality through completeness and accuracy metrics
Export in the required format.
Every SBOM is generated in both CycloneDX and SPDX - the two formats legal teams, auditors, and regulators expect. Export it straight from your dashboard the moment it's requested, with no extra tooling and no reformatting.
- Generate SBOMs and export directly from your dashboard when needed
- Share standardized outputs without reformatting or extra tooling
Identify license risks early.
Review license information for every dependency from a single software inventory. Identify dependencies that may require additional review for compliance or distribution.
- Centralize dependency and license info in one inventory for faster reviews
- Identify dependencies needing further review for compliance or distribution
FAQ about SBOM
What is an SBOM?
A software bill of materials (SBOM) is a complete inventory of every package your software depends on, direct and transitive, along with its version and license. Lumstep generates one automatically on every scan.
Why does an SBOM matter beyond compliance?
The EU Cyber Resilience Act requires vendors to maintain and share SBOMs by December 2027, and NIS2 and SOC 2 Type II both expect supply-chain evidence. Beyond audits, it's how you answer "are we affected?" in minutes the next time a package makes headlines.
Isn't a package.json or requirements.txt already an SBOM?
No. Those files list only the dependencies you declared directly. Lumstep's SBOM also resolves every transitive dependency pulled in behind them, tracks each one's license, and scores the inventory for completeness and accuracy.
What formats does Lumstep export SBOMs in?
Every SBOM is generated in both CycloneDX and SPDX, the two formats legal teams, auditors, and regulators expect.
How is an SBOM's quality measured?
Each SBOM gets a quality score based on completeness and accuracy, ensuring compliance before you share it.
How do I get my SBOM to an auditor or customer who's asking for one?
Export it directly from your dashboard the moment it's requested, in CycloneDX or SPDX, with no extra tooling or reformatting.
My SBOM lists 1,400 packages. Should I be worried?
Not by the number itself - a modern application pulling in a thousand-plus packages is normal, and most arrived transitively rather than by choice. What matters is how many you can't account for: the unmaintained ones, the ones with unclear licenses, the ones nobody on your team picked. That's what the quality score and per-dependency trust scores are for.
Generate your first SBOM in minutes.
Free early access. Your SBOM is ready on the first scan, with no extra configuration.