World Congress 2026 Europe

One Pipeline, Three Regulator - SBOM Compliance for the Developer

July 9, 2026 16:50 – 17:20 · 30 min Airstream 1

What this session covers

You shipped your app to the EU market, and three people are knocking: a CRA auditor, a NIS-2 assessor and your ISO 27001 lead. Different paragraphs, same question - what’s in your software, and can you prove it?

This hands-on session answers it with engineering, not paperwork! We clarify the steps: sign commits keylessly with Sigstore gitsign (and find them in the Rekor transparency log), generate an SBOM in both SPDX and CycloneDX with OpenSSF Protobom and bomctl, then scan it against trustworthy data with OSV-Scanner - because in 2024 the NVD backlog broke CVE feeds, and the OpenSSF OSV schema is how you route around it.

We map each step to the clause it satisfies: - CRA Annex I - NIS-2 Article 21, - ISO27001 A.5.21/A.8.8. The twist: only the CRA names the SBOM - the other two simply can’t be met without one.

You’ll leave with four commands that turn three compliance regimes into a by-product of how you already ship. No legal background needed.

What you’ll learn - Which exact CRA, NIS-2 and ISO 27001 clauses drive SBOM and provenance work - and the “one names it, two need it” distinction. - Keyless commit signing with Sigstore gitsign, verified in the Rekor transparency log. - Ending the SPDX-vs-CycloneDX fight with OpenSSF Protobom and bomctl. - Why CVE data fragmented in 2024, and how the OpenSSF OSV schema + OSV-Scanner give version-accurate results from your SBOM.

Related talks at this congress

Open session

World Congress 2026 Europe

July 10, 2026 · 11:40–12:10

Stage 8 - powered by Red Hat

Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?

Matthew Brady

Sales Engineering Manager at Black Duck

Matthew Brady
Open session

World Congress 2026 Europe

July 10, 2026 · 11:40–12:10

Stage 10 - powered by TikTok

The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most

Marcus Wermuth

VP of R&D at Safety Cybersecurity

Marcus Wermuth
Open session

World Congress 2026 Europe

July 10, 2026 · 11:00–11:30

Stage 8 - powered by Red Hat

Beyond SBOMs: The Future of Container Supply Chain Security

Mohammad-Ali A'râbi

Senior Software Engineer at JobRad

Mohammad-Ali A'râbi
Open session

World Congress 2026 Europe

July 8, 2026 · 13:30–15:30

Room M6 (40 Seats)

Trust code you didn't write: From code review to confidence

Ben Hutchison, Carl Fagerlin

Ben Hutchison
Carl Fagerlin
All sessions at this congress