Home / Courses / EU Product Compliance / SBOM and Product Vulnerability Management
EU Product Compliance

SBOM and Product Vulnerability Management

A software bill of materials is no longer documentation hygiene — it is the precondition…

Code BII-SBOM 3-Day Almaty, Dubai, Istanbul, Online Online + Classroom
Overview

Course Description

A software bill of materials is no longer documentation hygiene — it is the precondition for regulatory compliance. Under the Cyber Resilience Act, manufacturers must report actively exploited vulnerabilities within 24 hours from September 2026. That is impossible without knowing which components are inside the product, including products shipped years ago.

This course builds SBOM and vulnerability management capability. Participants learn SBOM formats and standards, generation approaches including binary analysis for legacy products, component identification and dependency mapping, vulnerability data sources and correlation, exploitability assessment and VEX, triage and prioritisation, disclosure and reporting workflows, and the automation required to operate at scale.

Objectives

What you will achieve

By the end of this training course, participants will be able to:

  • Explain SBOM purpose, formats and standards
  • Generate SBOMs including for legacy and binary-only products
  • Identify components and map dependencies
  • Correlate vulnerability data from multiple sources
  • Assess exploitability and apply VEX
  • Triage and prioritise vulnerabilities
  • Operate disclosure and regulatory reporting workflows
  • Automate SBOM and vulnerability management at scale
Training methodology

How the course is delivered

The course combines SBOM methodology with practical generation, correlation and triage exercises using realistic product component inventories. Participants build reporting workflows against CRA timelines.

The programme is driven by the September 2026 CRA reporting deadline and its practical dependency: you cannot report what you do not know is inside your product.

Who should attend

Designed for

This training course is ideal for:

  • Product security and engineering teams
  • Software and firmware developers
  • Compliance professionals preparing for CRA
  • Supply chain and procurement staff assessing vendors
  • Anyone required to report vulnerabilities under the CRA
Course outline

Daily programme

DAY 01SBOM Foundations
  • Why SBOM: regulatory and security drivers
  • SBOM formats and standards
  • Generation approaches
  • Legacy and binary-only products
DAY 02Components and Vulnerabilities
  • Component identification and naming
  • Dependency mapping
  • Vulnerability data sources
  • Correlation and matching
DAY 03Exploitability and Reporting
  • Exploitability assessment and VEX
  • Triage and prioritisation
  • Disclosure and reporting workflows
  • Automation, tooling, workshop
Certificate

Certification & accreditation

BII Certificate of Completion

BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.

Schedule

Upcoming sessions

DatesVenueFormatFee
02 - 04 Nov 2026 Dubai Classroom US$ 3950 Register
07 - 09 Sep 2026 Almaty Classroom US$ 3950 Register
08 - 10 Feb 2027 Online Online US$ 3950 Register
12 - 14 Oct 2026 Istanbul Classroom US$ 3950 Register
Enrolment

Register, request in-house, or download the agenda

Choose an action and share your details — our team responds within one business day with dates, fees and the full programme.

Poster