Software Bill of Materials (SBOM)

Next meeting scheduled for June 18, 2025

The topic will be “Considerations for BOM Operationalization in the Energy Sector.”

Supporting SBOM adoption across the energy sector community

DOE CESER is the sector risk management agency for the energy sector, and in collaboration with the U.S. Department of Homeland Security Cybersecurity and Infrastructure Security Agency (CISA), leads the DOE CESER Energy Sector Software Bills of Materials (SBOM) and Hardware Bill of Materials (HBOM) Quarterly Working Group to support BOM adoption across the energy sector community. This working group supports BOM adoption through facilitating the discussion of use cases, research priorities, and ongoing challenges across ESIB stakeholders. Attendees include, but are not limited to, vendors, asset owners, and government stakeholders.

The Quarterly Working Group has evolved from the SBOM Proof of Concept Group, which began April 2021 to advance BOM development in the energy sector and share information with the stakeholder community.

DOE CESER Energy Sector SBOM and HBOM Quarterly Working Group

Energy Sector SBOM and HBOM Quarterly Working Group

Lucas Tate (PNNL) and Rob Erbes (INL) have identified key challenges to Software Bill of Materials (SBOM) operationalization in the Energy Sector Industrial Base (ESIB). Lucas and Rob discuss several of these critical challenges, with the intent of gaining feedback and initiating conversation with industry to ultimately propose research to remove some of these barriers and increase the operationalization of BOMs.

Meeting Video Library

How to Build SBOM from Binaries

Using CyTRICS program research to tell a "round-about" story of SBOMs....

VEX Energy Overview

An update to VEX vulnerabilities and some tricks for addressing them....

Debrief of S4 SBOM Exercise

Discuss exercises and feedback from the S4x22 conference session; CISA working group updates and CycloneDx...

SBOM Transports

Energy Sector Software Bill of Materials discussion: survey results of software bill of materials transports....

Venues for SBOM Discussion

A review of SBOM’s activities from past year and preview of discussion opportunities and path...

Energy SBOM Retrospective

A retrospective analysis of the past year of Energy SBOM work and brainstorming for the...

Additional Resources

The National Telecommunications and Information Administration (NTIA) led an early multi-stakeholder effort to develop informational and technical resources for SBOMs between 2018-2021.

Click Learn More to review these foundational resources.

The Energy SBOM POC effort is a partnership between DOE CESER and DHS CISA. CISA is leading other SBOM-related efforts that inform and draw from this work. Click Learn More to review the CISA workstreams and resources.
April 30, 2021 Auburn University’s McCrary Institute hosted a panel discussion on growing policy support for BOMs, implementation challenges, and strategic use cases. Panelists include representatives from DOE, Idaho National Laboratory, NTIA, Unisys, and Microsoft Azure.
CESER Partners with CISA to Release New Framework for Software Bill of Materials Sharing.

Sponsor and Participating Organizations