> Markdown version of [/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # One Pipeline, Three Regulator - SBOM Compliance for the Developer Turn complex regulations like the EU Cyber Resilience Act into a natural byproduct of your pipeline. Automate SBOM compliance and vulnerability scanning without drowning in paperwork. - **Speakers:** [Marcus Ross](https://www.wearedevelopers.com/@marcus-ross) - **Event:** World Congress 2026 Europe - **Published:** July 9, 2026 - **Duration:** 28:29 - **URL:** https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer ## Summary Software developers face mounting pressure to prove the security of their supply chains, driven by three major frameworks: the EU's Cyber Resilience Act (CRA), the NIS-2 directive, and ISO 27001. While only the CRA explicitly mandates a software bill of materials (SBOM) with a strict 10-year retention rule, satisfying the supply chain security clauses of NIS-2 and ISO 27001 effectively requires one. Rather than drowning in paperwork, engineering teams can turn these three complex regulatory regimes into a natural byproduct of how they already ship code. The technical pathway to compliance involves establishing provenance, standardizing formats, and maintaining accurate vulnerability scanning. Developers can replace the friction of long-lived GPG keys by using Sigstore's `gitsign` for keyless commit signing—verified via the Rekor transparency log—and `cosign` for release artifacts. To resolve the ongoing SPDX versus CycloneDX format debate, teams can leverage OpenSSF Protobom and `bomctl` to seamlessly convert between standards losslessly. Finally, in response to the 2024 NVD data crisis that fragmented CVE feeds, the OpenSSF OSV schema and `osv-scanner` provide a highly accurate, API-driven, and offline-capable alternative for automated vulnerability routing. Beyond tooling, effective remediation demands a cultural shift in how organizations handle risk. Because achieving a codebase with zero CVEs is practically impossible, security cannot be isolated to developers or SOC teams alone. True resilience requires cross-functional collaboration where technical teams expose vulnerabilities through SBOMs, and business risk owners decide on acceptable risk thresholds and remediation timelines, making compliance a shared organizational strategy rather than an isolated engineering chore. **Keywords:** SBOM compliance, CRA framework, NIS-2 directive, ISO 27001 requirements, supply chain security, software bill of materials, sigstore gitsign, keyless commit signing, OpenSSF protobom, SPDX and CycloneDX formats, rekor transparency log, OSV-scanner, CVE data fragmentation, NVD backlog workarounds, vulnerability remediation, technology risk ownership ## Chapters 1. **Legal frameworks mandating software bill of materials** (00:03) — European regulations like the Cyber Resilience Act require product teams to build transparency by tracking software components. 1. **Satisfying ISO 27001 supply chain and vulnerability requirements** (06:55) — Using a software bill of materials acts as an inventory to provide technical evidence for ISO 27001 audits. 1. **Securing code provenance with digital identity signatures** (09:18) — Cryptographically tying developer identity to code commits secures code systems against spoofing and establishes verifiable provenance. 1. **Implementing keyless commit signing with Sigstore gitsign** (12:05) — Configuring version control with ephemeral certificates simplifies developer onboarding by signing code without long-lived keys. 1. **Distinguishing between basic sign-offs and cryptographic signatures** (14:02) — Recognizing the distinction between simple text sign-offs and cryptographic signatures prevents unverified release artifacts. 1. **Resolving the SPDX and CycloneDX format dilemma** (16:36) — Using open-source tools to flawlessly convert between formats eliminates friction inside continuous integration pipelines. 1. **Navigating the CVE data crisis and fragmented vulnerability streams** (19:27) — Consolidating multiple package ecosystem feeds counters the data crisis caused by slowdowns at the National Vulnerability Database. 1. **Scanning software distributions with the OpenSSF OSV schema** (22:01) — Leveraging the OSV-Scanner allows offline, version-accurate vulnerability matching directly against a software bill of materials. 1. **Collaborating on risk appetite and CVE remediation strategies** (24:26) — Facilitating discussions between engineering and security operations establishes realistic vulnerability remediation expectations instead of aiming for zero. 1. **Unifying software compliance into standard delivery pipelines** (26:33) — Embedding code provenance and bill of materials generation directly into deployment commands turns compliance into a natural byproduct. ## Related Moments - [Mapping the complete software supply chain attack surface](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) (from "Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?") - [Automating compliance checks into delivery pipelines](https://www.wearedevelopers.com/videos/1983-compliance-risk-shipping-open-source-ai-and-containers) (from "Compliance & Risk: Shipping Open Source, AI, and Containers") - [Navigating software integration compliance in safety automotive environments](https://www.wearedevelopers.com/videos/367-intelligent-data-selection-for-continual-learning-of-ai-functions) (from "Intelligent Data Selection for Continual Learning of AI Functions") - [Core principles for implementing DevSecOps in teams](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) (from "DevSecOps: Security in DevOps") - [Exploring advanced security tooling and community dependency vetting](https://www.wearedevelopers.com/videos/1041-reviewing-3rd-party-library-security-easily-using-openssf-scorecard) (from "Reviewing 3rd party library security easily using OpenSSF Scorecard") - [Adopting actionable frameworks for software bills of materials](https://www.wearedevelopers.com/videos/376-walking-into-the-era-of-supply-chain-risks) (from "Walking into the era of Supply Chain Risks") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Future of Open Source: A Deep Dive - Scott Chacon at WeAreDevelopers World Congress 2024](https://www.wearedevelopers.com/magazine/471-the-future-of-open-source-a-deep-dive-scott-chacon-at-wearedevelopers-world-congress-2024) ## Related Jobs - [Senior Open Source Advisor](https://www.wearedevelopers.com/jobs/ext/1278113-senior-open-source-advisor) at **ZEISS Group** - [Senior Software Engineer](https://www.wearedevelopers.com/jobs/ext/15942-senior-software-engineer) at **GitHub** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio** - [Senior Software Engineer, Enterprise Products](https://www.wearedevelopers.com/jobs/ext/1841248-senior-software-engineer-enterprise-products) at **GitHub** - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub**