OW2con'26

State of the SBOM union: Are we ready for another Log4shell?
2026-06-03 , Main stage

Many regulations in many vertical industries as well as horisontal regulations like the EU Cyber Resilience Act point out the need for a Software Bill of Materials (SBOM). But what is the state of the SBOM universe with competing standards and a growing set of tools, all with a different perspective on usage, content and clarity. The use of SBOMs vary from basic license compliance to advanced documentation of the development and build process with signed attestations.
In this talk, we give an update of where we are, what you can expect today and the next steps on your SBOM journey!


  • SBOM requirements
  • SBOM types
  • SBOM vulnerability management
  • SBOM sharing
  • SBOM standards
  • SBOM tools

Olle E. Johansson is a well-known speaker and teacher. He has a long history of working with Open Standards and Open Source Software. As a developer in Asterisk.org he contributed code, documentation and created the Astricon conference. Today, Olle is active in OWASP CycloneDX and in the Eclipse Open Regulatory Compliance Working group with issues related to the EU Cyber Resilience Act. He is active in the IETF and a member of ISOC-SE, SNUS and the supporter group for Stockholm's botanical garden "Bergianska". In addition, Olle is project lead for the DNS TAPIR Open Source project that builds a cybersecurity platform to monitor DNS queries without sacrificing the user's right to privacy.

Anthony Harrison has been developing and delivering mission-critical applications for over 40 years working on various complex programs where he held various roles in software, systems and cyber engineering, as well as providing technical leadership for a number of programmes.

He is the Founder and Director of APH10, and co-founder of SBOM Europe, and is a leading source of expertise in Software Bill of Materials (SBOM). He has been developing open source software actively for a number of years; most recently, the applications have been related to supporting the software supply chain through utilities to generate and analyse software bills of materials (SBOMs).

He has been a mentor for the Google Summer of Code for the past four years via the Python Software Foundation and is a mentor for his local CoderDojo in Manchester teaching students Python.