Strengthening Industrial Cyber Security with SBOMs

Modern automation systems rely on complex software stacks that include third-party and open-source components. Ensuring the security and compliance of such systems requires transparency.

A Software Bill of Materials (SBOM) provides exactly that: a complete, machine-readable inventory of all software components used in a product. Think of a parts list in mechanical engineering or an ingredients list on food packaging it contains:

  • Component names and version information
  • Vendor identifiers
  • Licensing details
  • Metadata

Why SBOMs Matter for Industrial Automation

The EU Cyber Resilience Act (CRA) introduces mandatory Cyber Security requirements for products with digital elements. For machine builders and integrators, SBOMs help meeting regulatory requirements, assessing security risks, and maintaining compliance throughout the lifecycle of their machines and systems.

How B&R Handles SBOMs

B&R focuses on compliance with legal requirements and lists the third-party components and (open-source) licenses used for this purpose. We monitor and analyze the various recommendations issued by global authorities and organizations such as ENISA, CISA, and the BSI. B&R evaluates the wide range of recommendations to establish a consolidated foundation for SBOMs without introducing excessive complexity.

B&R already creates SBOMs as part of our certified secure product development lifecycle according to IEC 62443-4-1. This means we were prepared for SBOM requirements long before the CRA made them mandatory.

Our approach

Industry-standard formats

We use the standardized CycloneDX standard, ensuring interoperability with common vulnerability analysis platforms.

First-level dependencies

B&R SBOMs cover the direct dependencies of our products the components we integrate and are responsible for.

Continuous vulnerability monitoring

SBOMs enable us to systematically monitor for third-party component vulnerabilities and report them.

License transparency

Our SBOMs provide full visibility into open-source licenses used within B&R products.

Creating SBOMs for Your Machine Application

As a machine builder, you need to document the software components in your application. The tooling depends on your technology stack and the industrial automation world brings unique challenges compared to typical IT environments.

Community solutions available today

Community-driven tools already cover different stages of the machine lifecycle. Together, these tools cover both the engineering phase and the as-built state of deployed systems a critical distinction for lifecycle compliance.

SBOM from Automation Studio 6 projects (design time)

The Python-based SBOM Generator for Automation Studio 6 Projects scans your AS6 project structure and produces CycloneDX JSON SBOMs per configuration. It reads project information from Logical, Physical, and APJ data, referencing all used B&R components.

SBOM from SDM system dumps (runtime / field)

A toolkit that processes SDM system dumps from live systems and generates CycloneDX SBOMs along with system evidence bundles. It extracts hardware information (serial numbers, firmware versions, hardware variants), normalizes diagnostic logs, and can verify SDM package authenticity even for dumps transported via USB or other media.

Looking ahead

B&R is working toward integrated SBOM capabilities within the development environment. The goal is to make SBOM generation a seamless part of the engineering workflow reducing manual effort and ensuring consistency across the entire project lifecycle.

Why You Don't Need to Manage Our SBOMs

As a manufacturer, B&R takes responsibility for the entire software supply chain within our products. This is a key principle of both the CRA and IEC 62443.

Each manufacturer is responsible for their own level in the supply chain. What this means for you:

B&R monitors and patches vulnerabilities

in all components within our products. You do not need to monitor or patch individual subcomponents inside B&R software.

You focus on your direct dependencies:

As a machine builder, your SBOM documents the components you directly integrate including B&R products as single entries.

Practical reality:

Even if you had full visibility into every nested dependency within a B&R product, you would have no ability to patch or replace individual subcomponents independently. That responsibility stays with B&R.

With this approach the supply chain becomes managable and able to scale through the significant amount of vulnerabilities we're all facing.

SBOMs and CRA Compliance

SBOMs play an essential role in demonstrating compliance with several CRA obligations:

Cyber Security by Design

  • SBOMs provide evidence of structured component management during development.
  • B&R's IEC 62443-4-1 certified development process ensures all necessary information for complete SBOMs is maintained from the start.

Vulnerability handling and reporting

  • B&R monitors security advisories and vulnerability databases to identify potential risks in software components.
  • For current security information, visit our Cyber Security Advisories and Notices page.

Documentation obligations

  • SBOMs contribute to transparent technical documentation and lifecycle support.
  • This follows the CRA regulations, as well as the ones from the IEC 62443.

Closing the Loop

While the CRA focuses heavily on manufacturers, SBOMs benefit the entire supply chain. Modern Cyber Security programs increasingly rely on automated vulnerability analysis platforms such as Dependency-Track or similar solutions. These systems ingest SBOMs and continuously monitor them against public vulnerability databases.

This closes the loop between SBOM creation, vulnerability monitoring, and product lifecycle security at every level of the supply chain, handled by the responsible party.

国と言語を選ぶ

B&R Logo