Compliance

The SBOMs, evidence, and audit trail standards ask for

Most modern security standards now carry explicit software-supply-chain and SBOM requirements. Verifi produces the artifacts they ask for: a bill of materials, vulnerability evidence, and a record of what was blocked, fixed, and why.

What Verifi provides

SBOMs you can hand over

Generate a software bill of materials in CycloneDX or SPDX, with VEX so the list carries exploitability answers, not just components.

Vulnerability evidence, known and novel

Detect known issues from authoritative advisory data and novel ones no feed has listed, then filter by what is reachable in your code.

A remediation audit trail

Every block and every automated fix traces back to the finding, the decision, and the policy version that caused it. That trail is the evidence an auditor asks for.

Verifi supports and evidences these requirements. It does not by itself make you compliant, which is an organisational judgement made with your assessor. The clauses below are a scoping aid: always check the current text of each standard, because it changes (the US federal requirement, for one, moved to a risk-based model in 2026).

Regulations

Legal obligations

Where the requirement is law in a jurisdiction or sector.

EU NIS2 Directive

EU directive, 2022/2555

Article 21(2)(d) requires supply-chain security, and 21(2)(e) requires vulnerability handling and disclosure in the acquisition, development, and maintenance of systems.

Verifi: Detection and registry blocking to vet components, plus automated vulnerability handling and remediation.

EU Cyber Resilience Act

EU regulation, 2024/2847

Annex I requires an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies, plus vulnerability handling and security updates over the support period.

Verifi: Generates SBOMs in CycloneDX or SPDX, detects vulnerabilities, and drives the fixes. The strongest SBOM mandate of the set.

EU GDPR

EU regulation, 2016/679

Article 32 requires appropriate, state-of-the-art technical measures to secure the processing of personal data. It does not name SBOMs.

Verifi: Dependency detection and blocking are part of those technical measures where a vulnerable component would put personal data at risk.

US EO 14028 and NIST SSDF

US federal

Directs secure development aligned with the NIST SSDF (SP 800-218), with SBOMs as preferred conformance evidence. As of 2026 the federal attestation and SBOM requirement is risk-based and at agency discretion, not a blanket mandate.

Verifi: SBOMs and detection aligned with SSDF practices. Positioned as aligned with the framework, not as meeting a hard mandate.

US FDA, FD&C Act 524B

US, medical devices

Manufacturers of cyber devices must provide an SBOM covering commercial, open-source, and off-the-shelf components, plus a plan to monitor and patch vulnerabilities.

Verifi: SBOM generation and ongoing vulnerability monitoring for the device software estate.

Frameworks and standards

Voluntary, certifiable, or audited

Where the requirement is a certification, an audit report, or an adopted best practice.

ISO/IEC 27001:2022

Certifiable ISMS

Annex A 8.8 covers management of technical vulnerabilities, and 8.28 covers secure coding, including the risk in third-party libraries.

Verifi: Continuous detection, a vulnerability inventory, and policy-based decisions on what to act on.

NIST SSDF, SP 800-218

US framework

PW.4 vet and maintain third-party components, PS.3 provenance, RV.1 identify and analyse vulnerabilities, RV.2 remediate.

Verifi: Maps across the whole framework. The cleanest framework-level fit for Verifi.

NIST SP 800-53 Rev. 5

US control catalog

RA-5 vulnerability scanning, and the Supply Chain Risk Management (SR) family for provenance and component authenticity.

Verifi: Detection, provenance signals, and registry blocking.

OWASP

Industry framework

Top 10 A06:2021 Vulnerable and Outdated Components, and CycloneDX, the OWASP machine-readable SBOM standard.

Verifi: Detects vulnerable and outdated components and exports CycloneDX SBOMs.

CIS Controls v8

Industry framework

16.4 maintain an inventory of third-party software components (a bill of materials), and 16.5 use trusted, up-to-date components.

Verifi: SBOMs, detection, and registry blocking of untrusted components.

SOC 2

AICPA Trust Services Criteria

CC7.1 detect and monitor vulnerabilities, and CC9.2 vendor and third-party risk. Auditors want evidence of management and remediation.

Verifi: Detection plus an audit trail that gives the auditor the evidence directly.

PCI DSS 4.0.1

Payments standard

6.3.1 manage vulnerabilities including third-party and open-source, and 6.3.2 keep an inventory of custom and third-party components used to identify and address vulnerabilities. Mandatory since 31 March 2025.

Verifi: SBOMs, detection, and remediation tracking against the inventory.

SBOM and exploitability formats

The formats that thread through all of it

SPDX (ISO/IEC 5962:2021) and CycloneDX are the two common machine-readable SBOM formats these standards accept. The NTIA minimum elements set the baseline fields. VEX adds machine-readable exploitability, so an SBOM carries answers rather than just a component list, which is exactly what Verifi decisioning and reachability produce.

Map Verifi to your framework

Tell us which standards you report against and we will walk through the specific clauses and the evidence Verifi produces for each.