Course Description
A software bill of materials is no longer documentation hygiene — it is the precondition for regulatory compliance. Under the Cyber Resilience Act, manufacturers must report actively exploited vulnerabilities within 24 hours from September 2026. That is impossible without knowing which components are inside the product, including products shipped years ago.
This course builds SBOM and vulnerability management capability. Participants learn SBOM formats and standards, generation approaches including binary analysis for legacy products, component identification and dependency mapping, vulnerability data sources and correlation, exploitability assessment and VEX, triage and prioritisation, disclosure and reporting workflows, and the automation required to operate at scale.
What you will achieve
By the end of this training course, participants will be able to:
- Explain SBOM purpose, formats and standards
- Generate SBOMs including for legacy and binary-only products
- Identify components and map dependencies
- Correlate vulnerability data from multiple sources
- Assess exploitability and apply VEX
- Triage and prioritise vulnerabilities
- Operate disclosure and regulatory reporting workflows
- Automate SBOM and vulnerability management at scale
How the course is delivered
The course combines SBOM methodology with practical generation, correlation and triage exercises using realistic product component inventories. Participants build reporting workflows against CRA timelines.
The programme is driven by the September 2026 CRA reporting deadline and its practical dependency: you cannot report what you do not know is inside your product.
Designed for
This training course is ideal for:
- Product security and engineering teams
- Software and firmware developers
- Compliance professionals preparing for CRA
- Supply chain and procurement staff assessing vendors
- Anyone required to report vulnerabilities under the CRA
Daily programme
- Why SBOM: regulatory and security drivers
- SBOM formats and standards
- Generation approaches
- Legacy and binary-only products
- Component identification and naming
- Dependency mapping
- Vulnerability data sources
- Correlation and matching
- Exploitability assessment and VEX
- Triage and prioritisation
- Disclosure and reporting workflows
- Automation, tooling, workshop
Certification & accreditation
BII Certificate of Completion
BII Certificate of Completion Upon successful completion, participants receive a BII Development Institute Certificate of Completion with a unique reference code that is independently verifiable. Our certificates are recognised internationally and reflect successful completion of your chosen programme.