Viktor Petersson

Viktor Petersson

SBOMs are quickly moving from best practice to baseline requirement, driven by regulations like the EU Cyber Resilience Act, U.S. Executive Order 14028, PCI DSS 4.0, and updates to the NIST Cybersecurity Framework. Yet most organizations still struggle with inconsistent tooling, shallow metadata, and a lack of validation standards.

This talk introduces a practical, six-phase framework for generating SBOMs that are accurate, enriched, and verifiable. It’s built on real-world implementation experience and informed by research currently under review by CISA. The framework is tool-agnostic and designed to scale, from single applications to large CI/CD environments.

We’ll walk through:

  • Key regulatory drivers and where SBOM fits in
  • The six phases: generation, augmentation, enrichment, verification, signing, and linking
  • Demo of a CI/CD-integrated SBOM pipeline
  • Lessons learned from production deployments

Attendees will leave with clear guidance on building sustainable SBOM workflows that improve compliance

Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)