The SBOMs, evidence, and audit trail standards ask for
Most modern security standards now carry explicit software-supply-chain and SBOM requirements. Verifi produces the artifacts they ask for: a bill of materials, vulnerability evidence, and a record of what was blocked, fixed, and why.
SBOMs you can hand over
Generate a software bill of materials in CycloneDX or SPDX, with VEX so the list carries exploitability answers, not just components.
Vulnerability evidence, known and novel
Detect known issues from authoritative advisory data and novel ones no feed has listed, then filter by what is reachable in your code.
A remediation audit trail
Every block and every automated fix traces back to the finding, the decision, and the policy version that caused it. That trail is the evidence an auditor asks for.
Verifi supports and evidences these requirements. It does not by itself make you compliant, which is an organisational judgement made with your assessor. The clauses below are a scoping aid: always check the current text of each standard, because it changes (the US federal requirement, for one, moved to a risk-based model in 2026).
Legal obligations
Where the requirement is law in a jurisdiction or sector.
EU NIS2 Directive
EU directive, 2022/2555Article 21(2)(d) requires supply-chain security, and 21(2)(e) requires vulnerability handling and disclosure in the acquisition, development, and maintenance of systems.
Verifi: Detection and registry blocking to vet components, plus automated vulnerability handling and remediation.
EU Cyber Resilience Act
EU regulation, 2024/2847Annex I requires an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies, plus vulnerability handling and security updates over the support period.
Verifi: Generates SBOMs in CycloneDX or SPDX, detects vulnerabilities, and drives the fixes. The strongest SBOM mandate of the set.
EU GDPR
EU regulation, 2016/679Article 32 requires appropriate, state-of-the-art technical measures to secure the processing of personal data. It does not name SBOMs.
Verifi: Dependency detection and blocking are part of those technical measures where a vulnerable component would put personal data at risk.
US EO 14028 and NIST SSDF
US federalDirects secure development aligned with the NIST SSDF (SP 800-218), with SBOMs as preferred conformance evidence. As of 2026 the federal attestation and SBOM requirement is risk-based and at agency discretion, not a blanket mandate.
Verifi: SBOMs and detection aligned with SSDF practices. Positioned as aligned with the framework, not as meeting a hard mandate.
US FDA, FD&C Act 524B
US, medical devicesManufacturers of cyber devices must provide an SBOM covering commercial, open-source, and off-the-shelf components, plus a plan to monitor and patch vulnerabilities.
Verifi: SBOM generation and ongoing vulnerability monitoring for the device software estate.
Voluntary, certifiable, or audited
Where the requirement is a certification, an audit report, or an adopted best practice.
ISO/IEC 27001:2022
Certifiable ISMSAnnex A 8.8 covers management of technical vulnerabilities, and 8.28 covers secure coding, including the risk in third-party libraries.
Verifi: Continuous detection, a vulnerability inventory, and policy-based decisions on what to act on.
NIST SSDF, SP 800-218
US frameworkPW.4 vet and maintain third-party components, PS.3 provenance, RV.1 identify and analyse vulnerabilities, RV.2 remediate.
Verifi: Maps across the whole framework. The cleanest framework-level fit for Verifi.
NIST SP 800-53 Rev. 5
US control catalogRA-5 vulnerability scanning, and the Supply Chain Risk Management (SR) family for provenance and component authenticity.
Verifi: Detection, provenance signals, and registry blocking.
OWASP
Industry frameworkTop 10 A06:2021 Vulnerable and Outdated Components, and CycloneDX, the OWASP machine-readable SBOM standard.
Verifi: Detects vulnerable and outdated components and exports CycloneDX SBOMs.
CIS Controls v8
Industry framework16.4 maintain an inventory of third-party software components (a bill of materials), and 16.5 use trusted, up-to-date components.
Verifi: SBOMs, detection, and registry blocking of untrusted components.
SOC 2
AICPA Trust Services CriteriaCC7.1 detect and monitor vulnerabilities, and CC9.2 vendor and third-party risk. Auditors want evidence of management and remediation.
Verifi: Detection plus an audit trail that gives the auditor the evidence directly.
PCI DSS 4.0.1
Payments standard6.3.1 manage vulnerabilities including third-party and open-source, and 6.3.2 keep an inventory of custom and third-party components used to identify and address vulnerabilities. Mandatory since 31 March 2025.
Verifi: SBOMs, detection, and remediation tracking against the inventory.
The formats that thread through all of it
SPDX (ISO/IEC 5962:2021) and CycloneDX are the two common machine-readable SBOM formats these standards accept. The NTIA minimum elements set the baseline fields. VEX adds machine-readable exploitability, so an SBOM carries answers rather than just a component list, which is exactly what Verifi decisioning and reachability produce.
Map Verifi to your framework
Tell us which standards you report against and we will walk through the specific clauses and the evidence Verifi produces for each.