SBOMs in Practice: SPDX vs CycloneDX and What Actually Breaks
SPDX vs CycloneDX compared honestly, how to generate SBOMs that match production, and the failure modes that sink real adoption — plus the EU CRA deadlines now in force.
SPDX vs CycloneDX compared honestly, how to generate SBOMs that match production, and the failure modes that sink real adoption — plus the EU CRA deadlines now in force.
The SEC’s July 2023 cybersecurity rule put public companies on a four-business-day material-incident filing clock — turning breach disclosure into a rehearsed, enforceable, executive-owned security capability.
Since January 2024, ships manage cyber risk under IMO-derived requirements enforced by flag and port-state control, IACS E26 and E27 give class societies assessment criteria, and the US Coast Guard can detain deficient vessels. Bridge, cargo, propulsion, SATCOM and crew IT share one hull: treat the vessel as an OT estate.
Food plants, logistics firms, waste management, research labs: 18 sectors are in scope, plus everyone their covered customers drag in via contracts. The duties read like an incident-readiness program — 24-hour early warning, 72-hour notification, personal accountability for executives — and the basics were overdue anyway.
Ireland’s DPC fined Meta €1.2B over EU-US transfers that Schrems II had already doomed — the largest GDPR fine ever, ordering suspension and deletion. Transfer-governance lessons for security teams.
From 2027 connected products without CRA-backed security lose the CE mark and the EU market. EN 303 645 already draws the floor: no default passwords, disclosure policy, update transparency. The real work is turning security into a documented lifecycle — threat models, SBOMs, tested updates — instead of a checkbox before the ceremony.