Vulnerabilities under control
Only with an SBOM including unique identifiers (purl, CPE) can you automatically check whether known vulnerabilities such as Log4Shell are present in your product, throughout the entire support period.
A Software Bill of Materials is only worth as much as the information it contains. Whether your SBOM meets the requirements depends on the market: in the EU the Cyber Resilience Act sets the framework and BSI TR-03183-2 the benchmark, while in the US it is the NTIA Minimum Elements. This page explains which standard counts for which use case.
Go straight to the free SBOM checkModern software consists predominantly of third-party and open-source components. Without a complete inventory, you can assess neither whether a new vulnerability affects your product nor which license obligations apply.
Only with an SBOM including unique identifiers (purl, CPE) can you automatically check whether known vulnerabilities such as Log4Shell are present in your product, throughout the entire support period.
The Cyber Resilience Act makes the SBOM mandatory from 11 December 2027 for products with digital elements on the EU market. In the US, Executive Order 14028 and the FDA already require SBOMs today.
Customers, auditors and authorities increasingly require reliable SBOMs as an entry requirement. Anyone who can deliver a standard-conformant SBOM significantly shortens procurement processes and security reviews.
The BSI Technical Guideline TR-03183-2 specifies which information an SBOM must contain at document and component level. It is the reference benchmark for the European market.
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to create and maintain a machine-readable SBOM (Annex I, Part II No. 1). BSI TR-03183-2 specifies what such an SBOM should look like formally and in content, making it the key reference for implementation in the EU.
Anyone who has to demonstrate the state of the art for SBOMs to market surveillance, notified bodies or auditors is on safe ground with the BSI Technical Guideline. It defines clear mandatory and additional fields per component and makes the quality of an SBOM objectively verifiable.
Manufacturers pass CRA requirements down their supply chain by contract. Anyone delivering software components, libraries or embedded stacks to European product manufacturers is increasingly asked for an SBOM per BSI TR-03183-2, including hashes, license information and resolved dependencies.
In public sector tenders and among operators of critical infrastructure in Germany, TR-03183-2 is frequently referenced as the benchmark. An SBOM conforming to it eases procurement, vulnerability management and cooperation with the BSI.
| Version | Status | When it makes sense |
|---|---|---|
| v2.1.0 | Current version | For all new SBOM processes and CRA preparation. Requires CycloneDX from 1.6 (SPDX 2.x is no longer permitted), SHA-512 hashes, BSI component properties and an explicitly indicated completeness of the dependency graph. |
| v2.0.0 | September 2024 | When contracts or customer requirements explicitly reference v2.0.0. Still accepts SPDX 2.2/2.3 alongside CycloneDX from 1.5, but already requires SHA-512 hashes and the extended component fields. |
| v1.1 | Older version | Only for legacy contracts pinned to v1.1. More lenient on hashes (SHA-256 is sufficient) and component fields. No longer recommended for new projects. |
The NTIA document "The Minimum Elements For a Software Bill of Materials" (July 2021) defines the internationally widespread baseline: basic data fields, automation support and processes.
The NTIA Minimum Elements originated in 2021 on behalf of the US government (Executive Order 14028) and are the starting point for all SBOM requirements in US federal procurement. Anyone supplying software to US agencies or their suppliers should meet at least these baseline fields.
The FDA requires an SBOM for connected medical devices (cyber devices under Section 524B FD&C Act) as part of the clearance process and aligns with the NTIA Minimum Elements. For MedTech manufacturers with US business, NTIA conformity is therefore effectively mandatory.
Many corporations and platform operators worldwide require their software suppliers to provide an "NTIA-conformant SBOM" as the lowest common denominator. The Minimum Elements are deliberately lean and quickly achievable with common tooling.
Anyone just starting out with SBOMs sensibly begins with the NTIA Minimum Elements: few mandatory fields, a clear structure, quick wins. Moving up to the stricter BSI requirements (hashes, license validation, full dependency graph) is much easier afterwards.
The NTIA Minimum Elements define the foundation; BSI TR-03183-2 builds on it and goes considerably further in field depth and verifiability.
| Criterion | NTIA Minimum Elements | BSI TR-03183-2 (v2.1.0) |
|---|---|---|
| Origin and context | US Department of Commerce (NTIA), Executive Order 14028; basis for US procurement and the FDA | BSI; specifies the SBOM requirement of the EU Cyber Resilience Act |
| Formats | SPDX or CycloneDX, machine-readable (JSON, XML, Tag-Value) | CycloneDX from 1.6 or SPDX from 3.0.1 (older versions: SPDX 2.2/2.3 too) |
| Mandatory fields per component | Supplier, name, version, unique identifiers (where available), dependencies | Additionally creator with contact, filename, SHA-512 hash, validated license information, properties (executable, archive, structured) |
| Dependencies | At least top-level dependencies or an explicit completeness statement | Recursively resolved, complete graph with indicated completeness |
| Typical use | Entry point, US market, international minimum requirement | EU market, CRA evidence, authorities and critical infrastructure |
Rule of thumb: whoever meets BSI TR-03183-2 meets the NTIA Minimum Elements along with it. The reverse is not true. For manufacturers with EU business, the Technical Guideline is therefore the sensible target level, with NTIA as the minimum level for a quick start.
Check your SBOM for free against BSI TR-03183-2 (v2.1.0, v2.0.0, v1.1) or the NTIA Minimum Elements. The check runs entirely in your browser, including an assessment report as PDF.
Go to the SBOM Compliance CheckQuestions about implementation? Reach out at info@actsecure.eu.
The Technical Guideline itself is not a legal norm. What is binding is the Cyber Resilience Act, which requires an SBOM without specifying its content in detail. However, TR-03183-2 describes the state of the art from the BSI's perspective and is regularly used as the benchmark in contracts, tenders and assessments. Meeting it puts you in a strong position for CRA evidence.
As a starting point yes, as a target no. The NTIA Minimum Elements cover the baseline fields (supplier, name, version, dependencies, author, timestamp), but require neither hashes nor validated license information nor the field depth demanded by TR-03183-2. For the European market the SBOM should be aligned with the BSI benchmark over time.
Both are established, machine-readable standards. For new projects with a BSI focus, CycloneDX from version 1.6 is recommended, since the current TR-03183-2 v2.1.0 only accepts SPDX again from version 3.0.1 and the BSI-specific component fields map cleanly to CycloneDX properties. In the US context, both formats are equally widespread.
No. An SBOM that meets BSI TR-03183-2 practically covers the NTIA Minimum Elements in full. The sensible approach is therefore: NTIA as the entry and minimum level, BSI TR-03183-2 as the target level for the EU market. With our SBOM check you can validate both benchmarks against the same file.
Note: This overview is intended for initial orientation and does not replace legal advice. The authoritative sources are Regulation (EU) 2024/2847, BSI TR-03183-2 in its respective valid version and the relevant US requirements.