Thomas Graf, Siemens AG

Thomas Graf, Siemens

This is an overview of Siemens SBOM activities. Siemens started about 10 years ago to work on ways to automatically determine all third-party dependencies of products, including all the meta data we needed.

For about 5 years now, we have the Siemens Standard BOM, a central group of people working on SBOM standards and tools. We started from the license compliance point of view but now we are focusing a lot on CRA. We have developed several SBOM libraries, SBOM scanners and databases to manage all this information.

This session is part of SBOM Focus

Focus on SBOM


Open Source Security Foundation
OWASP Foundation
Open regulatory compliance working group (ORCWG.ORG)