Taming the SBOM chaos – A legal compass for the CRA and open source compliance
About this talk
This talk, presented by Hendrik Schöttle of Osborne Clarke, focuses on the intersection of Software Bill of Materials (SBOMs) with legal obligations, licensing, and regulatory compliance, particularly in the context of the Cyber Resilience Act (CRA). The session highlights the importance of SBOMs as machine-readable inventories of software components, emphasizing that while they are essential for visibility in the software supply chain, they cannot solely ensure compliance. It explores three key legal dimensions: license compliance, which stipulates that organizations must provide full license texts and meet attribution requirements; pre-contractual disclosure obligations to avoid legal defects; and regulatory compliance under the CRA that mandates SBOMs for products with digital elements. The speaker clarifies that while these domains operate independently, they often overlap, and ensuring compliance requires not just technical accuracy but also timely legal disclosures.