Towards the Analysis of Software Supply Chain and EU Regulations

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Software supply chain is becoming a relevant topic in cybersecurity, especially the software bill of materials (SBOM) in order to manage libraries and components dependencies. In addition, several European Union (EU) regulations have been approved in the context of cybersecurity. They provide horizontal cybersecurity requirements such as the Cyber Resilience Act (CRA). However, the link between SBOM and the EU regulations is not clear. Therefore, this paper provides an overview of the current literature’ state of the art in SBOMs and highlights its relationships with EU regulations. In fact, there is an evident increase of published research papers since the US executive order for improving Nation’s Cyber Security under the Biden’s administration, but there is scarce reference to legislations. Finally, we analyze the occurrence of key search strings within EU legislations.

Original languageEnglish
Title of host publicationSystems, Software and Services Process Improvement - 32nd European Conference, EuroSPI 2025, Proceedings
EditorsMurat Yilmaz, Paul Clarke, Andreas Riel, Richard Messnarz, Mikus Zelmenis, Ivi Anna Buce
PublisherSpringer Science and Business Media Deutschland GmbH
Pages170-183
Number of pages14
ISBN (Print)9783032042903
DOIs
Publication statusPublished - 2026
Event32nd European Conference on Systems, Software and Services Process Improvement, EuroSPI 2025 - Riga, Latvia
Duration: 17 Sept 202519 Sept 2025

Publication series

NameCommunications in Computer and Information Science
Volume2658 CCIS
ISSN (Print)1865-0929
ISSN (Electronic)1865-0937

Conference

Conference32nd European Conference on Systems, Software and Services Process Improvement, EuroSPI 2025
Country/TerritoryLatvia
CityRiga
Period17/09/2519/09/25

Keywords

  • CRA
  • EU regulations
  • SBOM
  • software supply chain

Fingerprint

Dive into the research topics of 'Towards the Analysis of Software Supply Chain and EU Regulations'. Together they form a unique fingerprint.

Cite this