• Only one percent of SBOMs were entirely conformant with the minimum elements. The minimum elements appear to be a high bar for SBOMs. Further research will need to address whether the standard is too high, whether SBOM generation tools must evolve, or whether the underlying software artifacts lack necessary package metadata.
  • The single greatest reason that SBOMs don’t conform is because they lack specified suppliers for their components. Another one third of SBOMs fail to specify a name or version for all components.
  • A tool-by-tool analysis suggests that none of the tools appear to consistently create minimum elements-compliant SBOMs.Some tools do appear much better in complying with specific data fields.