SBOMs in 2026: Everyone's generating them, no one's using them
ID: 2c33406a-eec1-50ef-9388-1f585af1e953
STIX ID: report--2c33406a-eec1-50ef-9388-1f585af1e953
Feed Name: Aikido Security's Blog
ENISA's SBOM Adoption State of Play 2026 survey (334 organisations) shows the Cyber Resilience Act is driving SBOM adoption but reveals a major gap between generating SBOMs and actually using them for vulnerability and licensing management; many suppliers do not provide complete or accurate SBOMs, format and completeness issues persist (CycloneDX vs SPDX), and organisations cite skills and resource shortfalls. The article interprets these findings, highlights that smaller companies often lead in maturity, and promotes Aikido Security's tooling for automated SBOM generation, enrichment, supplier SBOM consumption, and developer/build-server visibility as practical mitigations to move beyond mere compliance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
