Choose Language
Google Translate
Skip to content
Facebook X-twitter Instagram Linkedin Youtube
  • sales@cybernx.com
  • +91 90823 52813
CyberNX Logo
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting 
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • English
    • English (US)
Contact Us
CyberNX Logo
  • English
    • English (US)
  • Home
  • About
    • About Us
    • CERT-In Empanelled Cybersecurity Auditor
    • Awards & Recognition
    • Our Customers
  • Services

    Peregrine

    • Managed Detection & Response
    • AI Managed SOC Services
    • Elastic Stack Consulting
    • CrowdStrike Consulting
    • Threat Hunting Services
    • Digital Risk Protection Services
    • Threat Intelligence Services
    • Digital Forensics Services
    • Brand Risk & Dark Web Monitoring
    • Full Stack Observability

    Pinpoint

    • Red Teaming Services
    • Vulnerability Assessment
    • Penetration Testing Services 
    • Secure Code Review Services
    • Cloud Security Assessment
    • Phishing Simulation Services
    • Breach and Attack Simulation Services

    nCompass

    • Cybersecurity Audit Services
    • Virtual CISO Services
    • DPDP Act Consulting
    • ISO 27001 Consulting
    • RBI Master Direction Compliance
    • SEBI CSCRF Framework Consulting
    • SEBI Cloud Framework Consulting
    • Security Awareness Training
    • Cybersecurity Staffing Services

    NXRadar

    • SBOM Solutions
    • CBOM Solutions
    • AIBOM Solutions
  • Industries
    • Banking
    • Financial Services
    • Insurance
  • Resources
    Blogs
    Case Studies
    Downloads
    Whitepapers
    Buyer’s Guide
    Research & Guides
  • Careers
  • Contact

SBOM Examples Explained: Types, Formats and a Real Sample

4 min read
26 Views
  • SBOM

The software bill of materials (SBOM) no longer needs an introduction. Every security and engineering team in India has heard the term by now. What still creates confusion is the practical side. What does an SBOM look like when you open one? How many kinds are there? And how do you tell a useful one from just a box-ticking one?

In August 2026, a new Shai-Hulud supply-chain campaign hit the npm ecosystem, initially compromising widely used packages including “keyv” and “cacheable” before spreading to hundreds of additional package versions. The campaign again highlighted a simple question for security teams: do we use an affected component, and where?

This guide is built around that question. You will see SBOM examples grouped by lifecycle stage, the two formats regulators accept, and a real sample file you can read line by line.

Table of Contents

What goes inside an SBOM

Before looking at real files, it helps to know what a complete one carries. India already has a field-level answer to that.

The CERT-In Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM (Version 2.0), published on 09 Jul 2025, list 21 minimum data fields for an SBOM. CERT-In also co-authored the 2026 Minimum Elements for a Software Bill of Materials with CISA and international partners, which added a few elements like component licence, component hash algorithm and SBOM tool name.

But if you strip them both down, every serious SBOM carries the same core:

  • Component name and version: the exact release you run, not the product family
  • Component producer: who built or published it
  • Unique identifier: a package URL that tools can match against vulnerability feeds
  • Licence: the legal terms attached to the component
  • Cryptographic hash: proof that the file you received is the one published
  • Dependency relationships: which component pulls in which, including transitive ones
  • Author, tool and timestamp: who generated the SBOM, using what, and when

SBOM examples by lifecycle stage

The most common misconception is that a product has one SBOM. It usually has several, and they disagree for good reasons. CISA’s community guidance on the types of SBOM documents groups them into six stages.

6 Types of SBOM Examples

  • Design SBOM: Built from the planned architecture, before the code exists. Useful during vendor evaluation, when you want to know what a product intends to include.
  • Source SBOM: Generated from the development environment and manifest files. It shows declared dependencies and is easy to automate inside a repository.
  • Build SBOM: Created during the build itself, using source files, dependency data and build metadata. A mature CI/CD pipeline can generate this type automatically as part of the build, and it can be signed alongside the artefact.
  • Analysed SBOM: Produced by inspecting a finished artefact such as a container image or firmware. Valuable for legacy systems where the build environment is long gone.
  • Deployed SBOM: Describes what is installed on a running system, often assembled from other SBOMs. Closest to what an auditor pictures when asking for your inventory.
  • Runtime SBOM: Captured from software while it executes, including dynamically loaded components. It answers what is actually running, not what was shipped.

SBOM examples by format

Lifecycle stage tells you when an SBOM was made. Format decides how a machine reads it. Two open standards dominate, and CERT-In points to both.

  • CycloneDX: an OWASP standard with a security-first design, strong dependency and vulnerability data, and sibling formats for cryptography, AI and hardware
  • SPDX: a Linux Foundation standard, originally built for licence compliance and now widely used for full component inventories

Both are recognised SBOM formats, and are referenced in CERT-In’s technical guidance. Mature teams sometimes publish both of these.

Can you provide an example of an SBOM?

Here is a trimmed CycloneDX file for one application with one dependency. Real SBOM can run to thousands of component blocks, but the shape stays identical. Please note that some fields are intentionally shortened and are not valid production values.

{

“bomFormat”: “CycloneDX”,

“specVersion”: “1.6”,

“serialNumber”: “urn:uuid:3e671687-395b-41f5-a30f-a58921a69b79”,

“version”: 1,

“metadata”: {

“timestamp”: “2026-08-10T09:15:00+05:30”,

“component”: {

“type”: “application”,

“name”: “customer-portal”,

“version”: “4.2.0”

}

},

“components”: [

{

“type”: “library”,

“name”: “log4j-core”,

“version”: “2.24.3”,

“purl”: “pkg:maven/org.apache.logging.log4j/log4j-core@2.24.3”,

“licenses”: [ { “license”: { “id”: “Apache-2.0” } } ],

“hashes”: [ { “alg”: “SHA-256”, “content”: “a1b2c3d4e5f6…” } ]

}

]

}

It maps to the fields listed earlier:

  • specVersion: confirms the schema, which decides what a scanner can parse
  • serialNumber and version: identify the document, so you can prove which build it describes
  • timestamp: shows how fresh the inventory is
  • purl: matches the component to vulnerability advisories
  • licenses and hashes: cover the legal and integrity checks auditors ask for

A scanner reading this file can flag a vulnerable version in seconds. A PDF list of libraries cannot, which is why format matters more than volume.

What Indian regulators expect

SEBI’s Cybersecurity and Cyber Resilience Framework (CSCRF) has made the software bill of materials a named requirement for regulated entities, covering new procurement and existing critical systems. Three expectations come up in almost every audit conversation:

  • Coverage: new software supporting core and critical activities, with applicable SBOMs kept current
  • Depth: transitive dependencies, licences, hashes and encryption details
  • Freshness: kept updated with every upgrade or change

Legacy software that cannot produce an SBOM is not an automatic exemption. Regulated entities are expected to record the gap and back it with a leadership-approved risk plan.

Conclusion

SBOM examples get clearer once you separate three questions. When was it generated, what format is it in, and does it carry the fields a scanner and an auditor both need. A build SBOM in CycloneDX with hashes and transitive dependencies is a working control. A spreadsheet of library names is paperwork.

Most teams struggle to keeping hundreds of files current across environments, versions and vendors. That is the part we handle. Our SBOM solutions automate collection, storage and continuous analysis, so your SBOM stays audit-ready and mapped to SEBI, RBI and CERT-In expectations. Talk to our experts and turn your software inventory into a control you can use.

SBOM examples FAQs

What are SBOM examples in simple terms?

SBOM examples are real software bill of materials files that show what an inventory looks like in practice. They vary by lifecycle stage, such as source, build or runtime, and by format, usually CycloneDX or SPDX. Each lists components, versions, licences, identifiers and dependencies.

Can you provide an example of an SBOM?

A basic CycloneDX SBOM is a JSON file with a metadata block describing the application and a components array listing each library. Every entry carries a name, version, package URL, licence and hash. Production files follow the same structure across thousands of entries.

Which SBOM format should Indian enterprises use?

CERT-In points to both CycloneDX and SPDX as accepted machine-readable formats. CycloneDX has deeper security tooling support, while SPDX has strong licence compliance roots. Pick the one your pipeline and vendors already support, and stay consistent across releases.

Does SBOM cover AI and hardware components?

Not on its own. CERT-In extends the model with AIBOM for AI models and datasets, CBOM and QBOM for cryptographic and quantum readiness, and HBOM for hardware. A software SBOM sits alongside these instead of replacing them.

Gopakumar Panicker

Author
Gopakumar Panicker
LinkedIn

An accomplished security professional with extensive experience in Digital Security, Cloud Security, Cloud Architecture, Security Operations, and BFSI Compliance, Gopa has contributed to designing and strengthening enterprise-grade security environments, ensuring alignment with both technical and regulatory requirements. His work focuses on building resilient, scalable architectures and guiding organisations in elevating their operational maturity while meeting the stringent expectations of modern BFSI and cloud-driven ecosystems.

Share on

WhatsApp
LinkedIn
Facebook
X
Pinterest

For Customized Plans Tailored to Your Needs, Get in Touch Today!

Connect with us

RESOURCES

Related Blogs

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.
Understanding Automated SBOM Management Lifecycle

Automated SBOM Management Lifecycle: Turning Inventory into Answers

Ask your engineering team one question: which applications use this exact version of this library? In most companies the answer

Software Supply Chain Security: Definitive Guide

Software Supply Chain Security: What It Is and How to Get It Right

Software supply chain security has moved from a niche engineering concern to a core business requirement. The reason is complexity.

SBOM Use Cases: Turning Software Inventory into Everyday Defence

SBOM Use Cases: Turning Software Inventory into Real Defence

In Sep 2025, a self-replicating worm called Shai-Hulud began moving through the npm registry. It stole developer credentials, then used

RESOURCES

Cyber Security Knowledge Hub

Explore our resources section for insightful blogs, articles, infographics and case studies, covering everything in Cyber Security.

BLOGS

Stay informed with the latest cybersecurity trends, insights, and expert tips to keep your organization protected.

CASE STUDIES

Explore real-world examples of how CyberNX has successfully defended businesses and delivered measurable security improvements.

DOWNLOADS

Learn about our wide range of cybersecurity solutions designed to safeguard your business against evolving threats.
CyberNX Footer Logo
Book a Free Call

Peregrine

  • Managed Detection & Response
  • AI Managed SOC Services
  • Elastic Stack Consulting
  • CrowdStrike Consulting
  • Threat Hunting Services
  • Digital Risk Protection Services
  • Threat Intelligence Services
  • Digital Forensics Services
  • Brand Risk & Dark Web Monitoring
  • Full Stack Observability

Pinpoint

  • Red Teaming Services
  • Vulnerability Assessment
  • Penetration Testing Services
  • Secure Code Review Services
  • Cloud Security Assessment
  • Phishing Simulation Services
  • Breach and Attack Simulation Services

nCompass

  • Cybersecurity Audit Services
  • Virtual CISO Services
  • DPDP Act Consulting
  • ISO 27001 Consulting
  • RBI Master Direction Compliance
  • SEBI CSCRF Framework Consulting
  • SEBI Cloud Framework Consulting
  • Security Awareness Training
  • Cybersecurity Staffing Services

NXRadar

  • SBOM Solutions
  • CBOM Solutions
  • AIBOM Solutions
  • About
  • CERT-In
  • Awards
  • Careers
  • Sitemap
Facebook Twitter Instagram Youtube

Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy

  • English
    • English (US)
Copyright © 2026 CyberNX | All Rights Reserved | Terms and Conditions | Privacy Policy
Scroll to Top

WhatsApp us

Not Sure Where to Start with Cybersecurity?

We value your privacy. Your personal information is collected and used only for legitimate business purposes in accordance with our Privacy Policy.