SBOM Compliance Series (Part 4): Understanding BSI TR-03183-2 v2.0, 馃嚛馃嚜 Germany Compliance

Overview This is the fourth part of our SBOM compliance series. In the previous post, we discussed BSI TR-03183-2 v1.1, Germany鈥檚 SBOM compliance framework, and how to validate your SBOM using sbomqs. In this post, we will discuss BSI TR-03183-2 v2.0, the updated version released in September 2024, what changed, what it now expects from an SBOM, and how to check compliance. Let鈥檚 go. Context 馃嚛馃嚜 Germany鈥檚 Federal Office for Information Security (BSI) released version 2.0.0 of TR-03183-2 on 2024-09-20. This is a significant update, not just a clarification pass. v2.0 adds new required fields, introduces a brand new optional tier, tightens the language around vulnerability information. ...

March 25, 2026 路 18 min 路 3757 words 路 Vivek Sahu

SBOM Compliance Series (Part 3): Understanding BSI TR-03183-2 v1.1, Germany Compliance

Overview This is the third part of our SBOM compliance series. In the previous post, we discussed Framing Software Component Transparency (FSCT), how it builds on NTIA and shifts the focus from minimum presence to meaningful transparency. In this post, we will discuss BSI TR-03183-2 v1.1, Germany鈥檚 SBOM compliance framework, why it exists, what it expects from an SBOM, and how it compares to what we鈥檝e seen so far. Let鈥檚 go. ...

March 23, 2026 路 13 min 路 2627 words 路 Vivek Sahu