---
canonical: https://anchore.com/blog/software-supply-chain-security-in-2025-sboms-take-center-stage/
meta-article:author: https://www.facebook.com/anchore/
meta-article:publisher: https://www.facebook.com/anchore/
meta-article:section: Blog
meta-article:tag: Syft
meta-description: Explore Anchore’s 2025 insights on SBOM adoption, driven by accelerating software supply chain attacks, rising DevSecOps demands, and global regulatory shifts.
meta-fb:admins:
meta-fb:app_id:
meta-fb:pages:
meta-generator: NitroPack
meta-msapplication-TileImage: https://anchore.com/wp-content/uploads/2021/12/Anchore_Mark_Blue-100-1.png
meta-og:description: Explore Anchore’s 2025 insights on SBOM adoption, driven by accelerating software supply chain attacks, rising DevSecOps demands, and global regulatory shifts.
meta-og:image: https://anchore.com/wp-content/uploads/2025/01/Blog-3.png
meta-og:image:alt: Software Supply Chain Security in 2025: SBOMs Take Center Stage
meta-og:image:height: 627
meta-og:image:secure_url: https://anchore.com/wp-content/uploads/2025/01/Blog-3.png
meta-og:image:width: 1200
meta-og:locale: en_US
meta-og:site_name: Anchore
meta-og:title: SBOMs in 2025: Trends &amp; Predictions | Anchore
meta-og:type: article
meta-og:url: https://anchore.com/blog/software-supply-chain-security-in-2025-sboms-take-center-stage/
meta-robots: index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1
meta-twitter:card: summary
meta-twitter:creator: @https://twitter.com/anchore
meta-twitter:description: Explore Anchore’s 2025 insights on SBOM adoption, driven by accelerating software supply chain attacks, rising DevSecOps demands, and global regulatory shifts.
meta-twitter:image: https://anchore.com/wp-content/uploads/2025/01/Blog-3.png
meta-twitter:site: @https://twitter.com/anchore
meta-twitter:title: SBOMs in 2025: Trends &amp; Predictions | Anchore
meta-viewport: width=device-width, initial-scale=1, shrink-to-fit=no
meta-zd-site-verification: dv553ct6shh2dm82a2xqnq
title: SBOMs in 2025: Trends &amp; Predictions | Anchore
---
 [https://www.googletagmanager.com/ns.html?id=GTM-5XP4C89](https://www.googletagmanager.com/ns.html?id=GTM-5XP4C89)

[](https://anchore.com)

  

-  
   [Platform](javascript:;)

  
  
  
   [Platform Overview](/platform/)

   [Secure & Protect](/platform/secure/)

   [Automated Compliance](/platform/enforce/)

   [SBOM Management](/platform/sbom/)

   [ Open Source](/opensource/)

  
  The first SBOM-powered platform for securing your software supply chain.

  Anchore Enterprise is the first SBOM-powered software supply chain management platform for continuous security and compliance.

  Ensure the security of software products you release or host as SaaS and provide SBOMs and assurance for your customers.

  Embed security and compliance checks into each step of your development lifecycle for more secure cloud-native applications.

  Manage internal and external SBOMs in a single location to track software supply chain issues.

-  
   [Public Sector](javascript:;)

  
  
  
   [Anchore Federal](/platform/public-sector/)

   [NIST Compliance](/compliance/nist/)

   [DoD Software Factory](/dod-software-factory/)

-  
   [Use Cases](javascript:;)

  
  
  
   [SBOM Management](/sbom/)

   [Container Vulnerability Scanning](/container-vulnerability-scanning/)

   [Open Source Security](/open-source-security/)

   [DevSecOps](</devsecops/ >)

   [Container Registry Scanning](/container-registry-scanning/)

   [FedRAMP](/fedramp/)

   [Federal Compliance](/federal-compliance/)

-  
   [Resources](javascript:;)

  
  
  
  
   
  Resource Hub

   [All Resources](/resources/)

   [Case Studies](/case-studies/)

   [White Papers](/white-papers/)

   [Webinars](/webinars/)

   [Blog](/blog/)

   [Events](/events/)

  
  
   
  Developer Hub

   [Open Source](/opensource/)

   [Enterprise Documentation](https://docs.anchore.com/)

   [Integrations](/integrations/)

  
   
  Knowledge Center

   [Compliance](/compliance/)

   [SBOM](/sbom/what-is-an-sbom/)

   [Software Supply Chain Security](/software-supply-chain-security/)

-  
   [Pricing](/pricing/)

-  
   [Company](javascript:;)

  
  
  
   [About Us](/about-us/)

   [Support Portal](https://support.anchore.com/)

   [Partners](/partners/)

   [Careers & Culture](/careers/)

   [Press & News](/newsroom/)

 [](#search)

      

 [Contact Us](https://get.anchore.com/contact/) [Free Trial](https://get.anchore.com/free-trial/)

 [](https://anchore.com)

 

 Platform

 [Platform Overview](/platform/)

 [Secure & Protect](/platform/secure/)

 [Automated Compliance](/platform/enforce/)

 [SBOM Management](/platform/sbom/)

[Open Source](/opensource/)

 Public Sector

 [Anchore Federal](/platform/public-sector/)

 [NIST Compliance](/compliance/nist/)

 [DoD Software Factory](/dod-software-factory/)

 Use Cases

 [SBOM Management](/sbom/)

 [Container Vulnerability Scanning](/container-vulnerability-scanning/)

 [Open Source Security](/open-source-security/)

 [DevSecOps](</devsecops/ >)

 [Container Registry Scanning](/container-registry-scanning/)

 [FedRAMP](/fedramp/)

 [Federal Compliance](/federal-compliance/)

 Resources

Resource Hub

 [All Resources](/resources/)

 [Case Studies](/case-studies/)

 [White Papers](/white-papers/)

 [Webinars](/webinars/)

 [Blog](/blog/)

 [Events](/events/)

Developer Hub

[Open Source](/opensource/)

[Enterprise Documentation](https://docs.anchore.com/)

[Integrations](/integrations/)

Knowledge Center

[Compliance](/compliance/)

[SBOM](/sbom/what-is-an-sbom/)

[Software Supply Chain Security](/software-supply-chain-security/)

 Pricing

[Pricing Overview](/pricing/)

 Company

 [About Us](/about-us/)

 [Support Portal](https://support.anchore.com/)

 [Partners](/partners/)

 [Careers & Culture](/careers/)

 [Press & News](/newsroom/)

  [Contact Us](https://get.anchore.com/contact/) [Free Trial](https://get.anchore.com/free-trial/) 

[](https://anchore.com)

  

-  
   [Platform](javascript:;)

  
  
  
   [Platform Overview](/platform/)

   [Secure & Protect](/platform/secure/)

   [Automated Compliance](/platform/enforce/)

   [SBOM Management](/platform/sbom/)

   [ Open Source](/opensource/)

  
  The first SBOM-powered platform for securing your software supply chain.

  Anchore Enterprise is the first SBOM-powered software supply chain management platform for continuous security and compliance.

  Ensure the security of software products you release or host as SaaS and provide SBOMs and assurance for your customers.

  Embed security and compliance checks into each step of your development lifecycle for more secure cloud-native applications.

  Manage internal and external SBOMs in a single location to track software supply chain issues.

-  
   [Public Sector](javascript:;)

  
  
  
   [Anchore Federal](/platform/public-sector/)

   [NIST Compliance](/compliance/nist/)

   [DoD Software Factory](/dod-software-factory/)

-  
   [Use Cases](javascript:;)

  
  
  
   [SBOM Management](/sbom/)

   [Container Vulnerability Scanning](/container-vulnerability-scanning/)

   [Open Source Security](/open-source-security/)

   [DevSecOps](</devsecops/ >)

   [Container Registry Scanning](/container-registry-scanning/)

   [FedRAMP](/fedramp/)

   [Federal Compliance](/federal-compliance/)

-  
   [Resources](javascript:;)

  
  
  
  
   
  Resource Hub

   [All Resources](/resources/)

   [Case Studies](/case-studies/)

   [White Papers](/white-papers/)

   [Webinars](/webinars/)

   [Blog](/blog/)

   [Events](/events/)

  
  
   
  Developer Hub

   [Open Source](/opensource/)

   [Enterprise Documentation](https://docs.anchore.com/)

   [Integrations](/integrations/)

  
   
  Knowledge Center

   [Compliance](/compliance/)

   [SBOM](/sbom/what-is-an-sbom/)

   [Software Supply Chain Security](/software-supply-chain-security/)

-  
   [Pricing](/pricing/)

-  
   [Company](javascript:;)

  
  
  
   [About Us](/about-us/)

   [Support Portal](https://support.anchore.com/)

   [Partners](/partners/)

   [Careers & Culture](/careers/)

   [Press & News](/newsroom/)

 [](#search)

      

 [Contact Us](https://get.anchore.com/contact/) [Free Trial](https://get.anchore.com/free-trial/)

 [](https://anchore.com)

 

 Platform

 [Platform Overview](/platform/)

 [Secure & Protect](/platform/secure/)

 [Automated Compliance](/platform/enforce/)

 [SBOM Management](/platform/sbom/)

[Open Source](/opensource/)

 Public Sector

 [Anchore Federal](/platform/public-sector/)

 [NIST Compliance](/compliance/nist/)

 [DoD Software Factory](/dod-software-factory/)

 Use Cases

 [SBOM Management](/sbom/)

 [Container Vulnerability Scanning](/container-vulnerability-scanning/)

 [Open Source Security](/open-source-security/)

 [DevSecOps](</devsecops/ >)

 [Container Registry Scanning](/container-registry-scanning/)

 [FedRAMP](/fedramp/)

 [Federal Compliance](/federal-compliance/)

 Resources

Resource Hub

 [All Resources](/resources/)

 [Case Studies](/case-studies/)

 [White Papers](/white-papers/)

 [Webinars](/webinars/)

 [Blog](/blog/)

 [Events](/events/)

Developer Hub

[Open Source](/opensource/)

[Enterprise Documentation](https://docs.anchore.com/)

[Integrations](/integrations/)

Knowledge Center

[Compliance](/compliance/)

[SBOM](/sbom/what-is-an-sbom/)

[Software Supply Chain Security](/software-supply-chain-security/)

 Pricing

[Pricing Overview](/pricing/)

 Company

 [About Us](/about-us/)

 [Support Portal](https://support.anchore.com/)

 [Partners](/partners/)

 [Careers & Culture](/careers/)

 [Press & News](/newsroom/)

  [Contact Us](https://get.anchore.com/contact/) [Free Trial](https://get.anchore.com/free-trial/) 

# Software Supply Chain Security in 2025: SBOMs Take Center Stage

By: Josh Bressers

Jan 14, 2025

{minutes} min read

 

 [](http://www.linkedin.com/shareArticle?mini=true&url=https://anchore.com/blog/software-supply-chain-security-in-2025-sboms-take-center-stage/) [](http://www.facebook.com/sharer.php?u=https://anchore.com/blog/software-supply-chain-security-in-2025-sboms-take-center-stage/) [](http://reddit.com/submit?url=https://anchore.com/blog/software-supply-chain-security-in-2025-sboms-take-center-stage/) [](http://twitter.com/share?url=https://anchore.com/blog/software-supply-chain-security-in-2025-sboms-take-center-stage/)

In recent years, we’ve witnessed software supply chain security transition from a quiet corner of cybersecurity into a primary battlefield. This is due to the increasing complexity of modern software that obscures the full truth—applications are a tower of components of unknown origin. Cybercriminals have fully embraced this hidden complexity as a ripe vector to exploit.

[Software Bills of Materials (SBOMs)](https://anchore.com/sbom/what-is-an-sbom/) have emerged as the focal point to achieve visibility and accountability in a software ecosystem that will only grow more complex. SBOMs are an inventory of the complex dependencies that make up modern applications. SBOMs help organizations scale vulnerability management and automate compliance enforcement. The end goal is to increase transparency in an organization’s supply chain where [70-90% of modern applications are open source software (OSS) dependencies](https://www.linuxfoundation.org/blog/blog/a-summary-of-census-ii-open-source-software-application-libraries-the-world-depends-on). This significant source of risk demands a proactive, data-driven solution.

Looking ahead to 2025, we at [Anchore](https://anchore.com/), see two trends for SBOMs that foreshadow their growing importance in software supply chain security:

1. Global regulatory bodies continue to steadily drive SBOM adoption
2. Foundational software ecosystems begin to implement build-native SBOM support

In this blog, we’ll walk you through the contextual landscape that leads us to these conclusions; keep reading if you want more background.

## Global Regulatory Bodies Continue Growing Adoption of SBOMs

As supply chain attacks surged, policymakers and standards bodies recognized this new threat vector as a critical threat with national security implications. To stem the rising tide supply chain threats, global regulatory bodies have recognized that SBOMs are one of the solutions.

Over the past decade, we’ve witnessed a global legislative and regulatory awakening to the utility of SBOMs. Early attempts like the US Cyber Supply Chain Management and Transparency Act of 2014 may have failed to pass, but they paved the way for more significant milestones to come. Things began to change in 2021, when the [US Executive Order (EO) 14028](https://anchore.com/sbom/latest-cybersecurity-executive-order-requires-an-sbom/) explicitly named SBOMs as the foundation for a [secure software supply chain](https://anchore.com/software-supply-chain-security/what-is-sscs/). The following year the [European Union’s Cyber Resilience Act (CRA)](https://anchore.com/sbom/eu-cra/) pushed SBOMs from “suggested best practice” to “expected norm.”

The one-two punch of the US’s EO 14028 and the EU’s CRA has already prompted action among regulators worldwide. In the years following these mandates, numerous global bodies issued or updated their guidance on software supply chain security practices—specifically highlighting SBOMs. Cybersecurity offices in Germany, India, Britain, Australia, and Canada, along with the broader European Union Agency for Cybersecurity (ENISA), have each underscored the importance of transparent software component inventories. At the same time, industry consortiums in the US automotive (Auto-ISAC) and medical device (IMDRF) sectors recognized that SBOMs can help safeguard their own complex supply chains, as have federal agencies such as the FDA, NSA, and the Department of Commerce.

By the close of 2024, the pressure mounted further. In the US, the [Office of Management and Budget (OMB) set a due date](https://anchore.com/blog/an-overview-ssdf-attestation-form/) requiring all federal agencies to comply with the [Secure Development Framework (SSDF)](https://anchore.com/blog/about-new-nist-ssdf/), effectively reinforcing SBOM usage as part of secure software development. Meanwhile, across the Atlantic, the EU CRA officially became law, cementing SBOMs as a cornerstone of modern software security. This constant pressure ensures that SBOM adoption will only continue to grow. It won’t be long until SBOMs become table stakes for anyone operating an online business. We expect the steady march forward of SBOMs to continue in 2025.

In fact, this regulatory push has been noticed by the foundational ecosystems of the software industry and they are reacting accordingly.

## Software Ecosystems Trial Build-Native SBOM Support

Until now, [SBOM generation](https://anchore.com/sbom/how-to-generate-an-sbom-with-free-open-source-tools/) has been relegated to afterthought in software ecosystems. Businesses scan their internal supply chains with software composition analysis (SCA) tools; trying to piece together a picture of their dependencies. But as SBOM adoption continues its upward momentum, this model is evolving. In 2025, we expect that leading software ecosystems will promote SBOMs to a first-class citizen and integrate them natively into their build tools.

Industry experts have recently begun advocating for this change. Brandon Lum, the SBOM Lead at Google, notes, “[The software industry needs to improve build tools propagating software metadata.](https://get.anchore.com/how-sboms-protect-google-sw-supply-chain/)” Rather than forcing downstream consumers to infer the software’s composition after the fact, producers will generate SBOMs as part of standard build pipelines. This approach reduces friction, makes application composition discoverable, and ensures that software supply chain security is not left behind.

We are already seeing early examples:

- **Linux Ecosystem (Yocto):** The Yocto Project’s [OpenEmbedded build system now includes native SBOM generation](https://docs.yoctoproject.org/dev/dev-manual/sbom.html). This demonstrates the feasibility of integrating SBOM creation directly into the developer toolchain, establishing a blueprint for other ecosystems to follow.
- **Python Ecosystem:** In 2024, [Python maintainers explored proposals for build-native SBOM support](https://github.com/psf/sboms-for-python-packages), motivated by the regulations such as, the Secure Software Development Framework (SSDF) and the EU’s CRA. They’ve envisioned a future where projects, package maintainers, and contributors can easily annotate their code with software dependency metadata that will automatically propagate at build time.
- **Perl Ecosystem:** The [Perl Security Working Group has also begun exploring internal proposals for SBOM generation](https://github.com/CPAN-Security/security.metacpan.org/blob/main/docs/supplychain-sbom.md), again driven by the CRA’s regulatory changes. Their goal: ensure that Perl packages have SBOM data baked into their ecosystems so that [compliance](https://anchore.com/compliance/) and security requirements can be met more effortlessly.
- **Java Ecosystem:** The Eclipse Foundation and VMware’s Spring Boot team have introduced plug-ins for Java build tools like Maven or Gradle that streamline SBOM generation. While not fully native to the compiler or interpreter, these integrations lower the barrier to SBOM adoption within mainstream Java development workflows.

In 2025 we won’t just be talking about build-native SBOMs in abstract terms—we’ll have experimental support for them from the most forward thinking ecosystems. This shift is still in its infancy but it foreshadows the central role that SBOMs will play in the future of cybersecurity and software development as a whole.

## Closing Remarks

The writing on the wall is clear: supply chain attacks aren’t slowing down—they are accelerating. In a world of complex, interconnected dependencies, every organization must know what’s inside its software to quickly spot and respond to risk. As SBOMs move from a nice-to-have to a fundamental part of building secure software, teams can finally gain the transparency they need over every component they use, whether open source or proprietary. This clarity is what will help them respond to the next [Log4j](https://anchore.com/log4j/how-to-detect-and-remediate-log4j-log4shell-at-scale/) or [XZ Utils](https://anchore.com/blog/we-dont-know-how-to-fix-the-xz-problem-but-we-can-detect-it/) issue before it spreads, putting security team’s back in the driver’s seat and ensuring that software innovation doesn’t come at the cost of increased vulnerability.

Learn about the role that SBOMs for the security of your organization in this white paper.

[Download Now](https://get.anchore.com/sbom-cybersecurity-whitepaper/)

 [](https://get.anchore.com/sbom-cybersecurity-whitepaper/)

 [Visually hidden](https://anchore.com/blog/top-stig-compliance-tools/)

 

Feb 24, 2026

#### Top STIG Compliance Tools to Automate Security Configuration & Audits

Read the Blog

 [Visually hidden](https://anchore.com/blog/no-crystal-ball-but-2026-directions/)

 

Feb 17, 2026

#### We have no crystal ball but we do have some directions for 2026

Read the Blog

 [Visually hidden](https://anchore.com/blog/the-s-in-sbom-is-for-system/)

 

Feb 10, 2026

#### The “S” in SBOM is for system

Read the Blog

### Speak with our security experts

Learn how Anchore’s SBOM-powered platform can help secure your software supply chain.

 [Contact Us](https://get.anchore.com/contact/)

 [](https://anchore.com)

Anchore is a leader in software supply chain security for modern cloud-native environments.

Large enterprises and government agencies use our software composition analysis solutions to generate and manage SBOMs, automate vulnerability scanning, enforce compliance at scale, and more.

## Platform

[Anchore Enterprise](/platform/enterprises/)

[Anchore Federal](/platform/public-sector/)

## Federal

[NIST Compliance](/compliance/nist/)

[Software Factory](/dod-software-factory/)

## Solutions

[CI/CD Security](/cicd/)

[Container Registry Scanning](/container-registry-scanning/)

[Container Security](/container-security/)

[Container Vulnerability Scanning](/container-vulnerability-scanning/)

[FedRAMP compliance](/fedramp/)

[Federal Compliance](/federal-compliance/)

## Resources

[Blog](/blog/)

[Docs](https://docs.anchore.com/current/)

[Open Source](/opensource/)

[Integrations](/integrations/)

[Partners](/partners/)

[Events](/events/)

[Webinars](/webinars/)

[Videos](/videos/)

## Learn

[Compliance](/compliance/)

[DevSecOps](/devsecops/what-is-devsecops/)

[SBOM](/sbom/what-is-an-sbom/)

[Software Supply Chain Security](/software-supply-chain-security/what-is-sscs/)

## Connect

[Support Portal](https://support.anchore.com/)

[Contact Us](https://get.anchore.com/contact/)

[Request a Demo](https://get.anchore.com/demo-request/)

## Company

[About Us](/about-us/)

[Become a Partner](https://get.anchore.com/become-a-partner/)

[Careers](/careers/)

[Press & News](/newsroom/)

[Support](https://support.anchore.com/hc/en-us)

Platform

- [Anchore Enterprise](/platform/enterprises/)
- [Anchore Federal](/platform/public-sector/)

Federal

- [NIST Compliance](/compliance/nist/)
- [Software Factory](/dod-software-factory/)

Solutions

- [CI/CD Security](/cicd/)
- [Container Registry Scanning](/container-registry-scanning/)
- [Container Security](/container-security/)
- [Container Vulnerability Scanning](/container-vulnerability-scanning/)
- [FedRAMP compliance](/fedramp/)
- [Federal Compliance](/federal-compliance/)

Resources

- [Blog](/blog/)
- [Docs](https://docs.anchore.com/current/)
- [Open Source](/opensource/)
- [Integrations](/integrations/)
- [Partners](/partners/)
- [Events](/events/)
- [Webinars](/webinars/)
- [Videos](/videos/)

Learn

- [Compliance](/compliance/)
- [DevSecOps](/devsecops/what-is-devsecops/)
- [SBOM](/sbom/what-is-an-sbom/)
- [Software Supply Chain Security](/software-supply-chain-security/what-is-sscs/)

Connect

- [Support Portal](https://support.anchore.com/)
- [Contact Us](https://get.anchore.com/contact/)
- [Request a Demo](https://get.anchore.com/demo-request/)

Company

- [About Us](/about-us/)
- [Become a Partner](https://get.anchore.com/become-a-partner/)
- [Careers](/careers/)
- [Press & News](/newsroom/)
- [Support](https://support.anchore.com/hc/en-us)

 [](https://anchore.com)

Anchore is a leader in software supply chain security for modern cloud-native environments.

Large enterprises and government agencies use our software composition analysis solutions to generate and manage SBOMs, automate vulnerability scanning, enforce compliance at scale, and more.

 [https://github.com/anchore/](https://github.com/anchore/) [https://twitter.com/anchore/](https://twitter.com/anchore/) [https://www.linkedin.com/company/anchore/](https://www.linkedin.com/company/anchore/) [https://www.youtube.com/channel/UC3HczVqyiAqz1aNxBIMS3pQ](https://www.youtube.com/channel/UC3HczVqyiAqz1aNxBIMS3pQ) [RSS](/feed.xml)

© Anchore 2021 - 2026. All Rights Reserved. [Legal](/legal) [Privacy Policy](/legal)