Software Bill of Materials requirements
Software Bill of Materials requirements are arriving in Financial & Capital Markets through multiple regulatory vectors simultaneously. The U.S. Securities and Exchange Commission's cybersecurity disclosure rules, finalized in 2023, create direct pressure on publicly traded financial institutions to document and disclose material software supply chain risks, and the European Banking Authority has signaled SBOM-adjacent expectations through its ICT risk management guidelines under DORA. Compliance teams are not waiting: they are mapping third-party software inventories against vendor contracts now, before examiners start asking.
Watch
- SEC cybersecurity disclosure rules: what counts as a 'material' SBOM gap
- DORA ICT third-party risk provisions taking effect January 2025 for EU-regulated entities
- CISA cross-sector SBOM guidance and whether financial regulators adopt it by reference
- OCC and Federal Reserve exam posture on software supply chain documentation in IT audits
Recent material activity in Financial & Capital Markets
Active monitoring in place across Financial & Capital Markets. Material developments related to software bill of materials requirements will appear here as they are published.