Keysight has recently unveiled a new software tool aimed at assisting manufacturers in complying with the growing transparency demands for software as cybersecurity regulations tighten worldwide. The SBOM Manager platform is specifically designed to facilitate the creation and upkeep of software bills of materials (SBOMs), which are increasingly mandated under regulations like the EU Cyber Resilience Act (CRA).
For readers of eeNews Europe, this development signifies a broader trend towards traceability and responsibility in the realm of digital product design, particularly as European regulations start to necessitate structured vulnerability reporting and enhanced supply chain visibility.
The EU Cyber Resilience Act, set to come into force in 2026, is anticipated to mandate that manufacturers of connected products establish cybersecurity risk management processes, maintain SBOMs, and promptly report actively exploited vulnerabilities within a 24-hour window. Similar expectations are already emerging in the US and certain parts of Asia, indicating a global convergence towards software transparency.
In this context, SBOMs are increasingly viewed as a prerequisite for market entry rather than merely a recommended best practice. They offer a systematic inventory of software components, encompassing open-source and third-party elements, which can be linked to known vulnerabilities.
Keysight’s SBOM Manager is crafted to tackle the intricacies of constructing and managing these inventories across contemporary software stacks. The platform scrutinizes binaries, firmware, and containerized applications, encompassing embedded and closed-source components, to provide a more comprehensive perspective of system dependencies.
Beyond SBOM generation, the tool cross-references component data with various vulnerability databases and employs filtering mechanisms, including support for Vulnerability Exploitability eXchange (VEX), to minimize false positives. This methodology aims to assist engineering teams in prioritizing actionable risks over large volumes of unfiltered vulnerability information.
The platform also facilitates controlled sharing of SBOM data through role-based access and version tracking, which could be pertinent for organizations seeking to demonstrate compliance to regulators or clients.
Naoki Shimazaki, Fourth Design Department, Director, Software-Defined Solutions Division, Connective Engineering Division, Hitachi Industry & Control Solutions, Ltd., remarked: “The utilization of SBOMs is evolving into a crucial component in monitoring system security risks, encompassing software composition management and supply chain risk management. We are of the opinion that solutions like these, which enable visibility into system components and support vulnerability impact analysis, hold significant potential in fortifying organizations’ cybersecurity endeavors.”
Dmitry Raidman, Co-founder and Chief Technology Officer, CyBeats, emphasized: “While companies are innovating at the pace of AI, they must also implement stricter governance and more robust controls, particularly as modern products increasingly rely on open source, third-party components, and AI-assisted development. Supply chain transparency and accountability are now paramount. To meet the escalating global regulations, organizations require the capability to consistently generate reliable SBOMs, correlate them with actionable vulnerability intelligence, apply VEX to minimize noise, and automate response workflows at scale. As transparency expectations expand across software, AI, cryptography, and hardware, visibility into the complete digital product stack is becoming indispensable for secure-by-design development, regulatory readiness, and customer trust.”
Ram Periakaruppan, Vice President and General Manager, Network Test & Security Solutions at Keysight, stated: “As cybersecurity regulations mature, SBOMs are evolving into a prerequisite for conducting business on a global scale. Keysight SBOM Manager empowers organizations to meet these demands confidently by delivering accuracy, consistency, and scalability to SBOM generation and management.”