Generic SBOM scanners produce incomplete or inaccurate results, especially in complex builds, firmware and legacy software.
Software development with end-to-end competence
Software Bill of Materials – a burden or a benefit? You decide.
Wapice helps organisations create accurate SBOMs even in challenging software environments, integrate component information into existing development workflows and use it for practical vulnerability analysis.
Generic SBOM scanners produce incomplete or inaccurate results, especially in complex builds, firmware and legacy software.
Vulnerability scanners produce findings, but teams still need effective ways to understand and prioritise them.
Cybersecurity regulation is ambiguous. It is hard to judge what SBOM and vulnerability management capabilities are sufficient.
How to distribute SBOM and vulnerability information in closed-source supply chains?
Modern software typically consists of numerous third-party components, with dependency trees extending far beyond what development teams directly see.
Third-party code, containers and trusted components can all introduce vulnerabilities into the software supply chain.
When these risks accumulate unnoticed, they can affect software quality, create costly security incidents and make regulatory compliance increasingly difficult.
Effective software supply chain security requires accurate visibility into your software components, well-defined processes and tools that support the engineering team.
The first step in knowing what software contains is a Software Bill of Materials, more commonly known as an SBOM.
An SBOM represents the dependency tree in a standardized inventory that can be read and understood by vulnerability analyzers and other systems. SBOMs can, however, vary significantly in quality.
The simplest SBOM may contain only package names and versions, whereas a more accurate version can include identifiers such as PURL, CPE and hashes, license information and build information.
Creating a high-quality SBOM can be challenging without previous experience.
Ensuring that the SBOM is as accurate as possible reduces false positives and misconceptions while providing a realistic view of software dependencies.

The EU Cyber Resilience Act (CRA) requires manufacturers to identify and document software components in a commonly used, machine-readable format. In practice, this means maintaining an accurate Software Bill of Materials (SBOM) for products with digital elements.
The CRA also requires manufacturers to address known exploitable vulnerabilities and to perform vulnerability analysis and management throughout the product lifecycle. This makes SBOM not only a documentation requirement, but also an important foundation for continuous vulnerability management and software supply chain security.
The main CRA obligations become applicable on 11 December 2027.
One of the most important benefits of an SBOM is that it enables vulnerability tracking against public vulnerability databases such as CVEs.
This provides visibility into vulnerabilities affecting third-party software components. However, analyzing an SBOM once is only the beginning of a well-defined software supply chain security process.
Feeding an SBOM into a vulnerability analyzer does not automatically guarantee accurate or actionable results. The quality of the SBOM determines which vulnerabilities can be identified in the first place.
OWASP Dependency-Track is a free and open-source platform for organization-wide third-party software vulnerability management.
Want to have less false positives? Wapice has successfully extended the platform with AI based context-aware relevance analysis!
Contact us to discuss how it would fit to your needs!

We help companies build software supply chain security practices that fit their products, development environments and regulatory requirements.
SBOM creates value when it becomes part of continuous software security work — not when it remains an unused build artifact.
Whether you are preparing for CRA requirements, struggling with SBOM accuracy or looking for a more effective way to manage third-party vulnerabilities, we can help you define the right approach and put it into practice.