PRAGUE, October 7 /PRNewswire/ -- At Open Source Summit Europe, the Linux Foundation today announced the release of the OpenChain Automotive Software Bill of Materials (SBOM) Framework 1.0, an open framework designed to establish a common approach for creating and sharing high-quality SBOMs in the automotive industry.
As software's importance in modern vehicles continues to grow, companies face increasing pressure to enhance visibility into their software components and dependencies while meeting evolving regulatory and cybersecurity requirements. The OpenChain Automotive SBOM Framework provides a practical foundation that the entire industry can adopt and further refine to address these challenges in the automotive sector.
The key components of this framework include:
- Provide a clear structure for describing software components and dependencies in an automotive SBOM.
- Provide guidance on required and recommended data fields, including completeness and quality standards.
- Aligned with existing SBOM standards, such as SPDX (ISO/IEC 5962)
- Use cases for suppliers and OEMs, including data exchange in the automotive supply chain.
This framework provides guidance on how to describe and exchange information about software components using a standardized format, enabling suppliers and OEMs to generate SBOMs that meet shared expectations with consistent standards for integrity, consistency, and availability. It is designed to support practical use cases such as software transparency, supply chain communication, and regulatory readiness.
Mary Meixia Wang, General Manager of the OpenChain project, said: “As the complexity of software-defined vehicles continues to rise, enhancing transparency and traceability between software components is becoming critical. This initial release provides practical guidance and helps promote more consistent SBOM practices across the automotive ecosystem.”
The initiative originated from early discussions among Keisuke Takase (Toyota), Ayumi Watanabe (Hitachi Solutions, Ltd.), and Masato Endo (Chair of the OpenChain Automotive Working Group), reflecting a shared commitment among all parties to enhance software transparency, traceability, and productivity in the automotive industry. Since then, the project has evolved through collaboration among organizations, industry associations, and domain experts within the automotive and software ecosystems. Their input helped identify common challenges and shaped a practical, broadly applicable framework grounded in real-world needs and emerging industry expectations.
The Automotive SBOM project belongs to the OpenChain Automotive Working Group and aims to complement existing standards such as SPDX (ISO/IEC 5962). This framework does not replace these standards but provides guidance on how to consistently apply them within the automotive industry.
This project welcomes participation from organizations and individuals worldwide and will continue to evolve based on industry feedback and adoption. To learn more about the OpenChain project and access the website or the OpenChain Automotive SBOM Framework, click here.
Supportive quote
Jiro Watabe, Senior Vice President and Executive Officer at Hitachi Solutions, Ltd., said: "The release of the OpenChain Automotive SBOM Framework marks a significant milestone for the automotive industry. By establishing a common approach to creating and sharing high-quality, trustworthy SBOM data, the framework enhances transparency and trust across the entire supply chain. We believe its adoption will help improve supply chain reliability and drive greater engineering efficiency and innovation in the automotive industry."
Hirofumi Inoue, President of Toyota Motor Corporation’s Advanced Research and Engineering Company, said: “As software-defined vehicles evolve, the scale and complexity of automotive software development continue to grow, making it increasingly important to share reliable SBOM information across the supply chain. We expect the OpenChain Automotive SBOM Framework to enable the industry to openly share effective processes and best practices, helping create an environment where engineers can dedicate more time and expertise to delivering value to customers.”
Tim Mackey, Head of Software Supply Chain Risk Strategy at Black Duck Software, Inc., said: "Effectively using SBOMs is more than just generating or releasing them on demand. Differences in requirements and expectations across organizations and regulatory bodies lead to SBOM quality issues—and shared frameworks and clear data structures and quality guidelines help address these issues at scale."
Stuart Dross, CEO of FossID, said: “The Automotive SBOM provides the industry with a much-needed common format to enhance software supply chain transparency. FossID is pleased to support this framework by helping automotive teams generate, import, convert, and validate SBOMs according to the new standard. Automating this process reliably is one way we plan to help accelerate the adoption of Automotive SBOM by automakers and their supplier ecosystems.”
Sugimoto Kazuma, General Manager of the Software Platform and Architecture Engineering Division at Nissan Motor Co., Ltd.'s Software-Defined Vehicle Engineering Department, said: "As vehicle development becomes increasingly software-centric, including the advancement of software-defined vehicles, understanding software composition has become a critical area of focus. By participating in this SBOM standardization initiative, Nissan will contribute to building a common industry foundation."
Carl-Eric Mols, Head of Volvo Cars’ Global Open Source Strategy, said: “Volvo Cars has embedded SBOM practices into its vehicle development process through the ‘Continuous SBOM’ initiative launched last year. By promoting a unified approach across the supply chain, we can enhance transparency and collaboration for everyone, while helping to evolve automotive SBOMs from mere license compliance and cybersecurity artifacts into the foundation of software trust, provenance, security, lifecycle governance, and supply chain intelligence.”
Regarding the OpenChain project
The OpenChain project, hosted by the Linux Foundation, focuses on building trust in open source supply chains. It develops open standards for open source compliance and security, helping organizations manage software licensing and risk across the global ecosystem.
About the Linux Foundation
The Linux Foundation is the world’s leading open-source platform for software, hardware, standards, and data collaboration. Projects under the Linux Foundation—including Linux, Kubernetes, Model Context Protocol (MCP), OpenChain, OpenSearch, OpenSSF, OpenStack, PyTorch, Ray, RISC-V, SPDX, and Zephyr—power global infrastructure. The Linux Foundation is committed to applying best practices and meeting the needs of contributors, users, and solution providers to create sustainable open collaboration models. For more information, visit linuxfoundation.org.
The Linux Foundation has registered trademarks and uses trademarks. For a list of Linux Foundation trademarks, see its trademark usage page: www.linuxfoundation.org/trademark-usage. Linux is a registered trademark of Linus Torvalds.
Media contact
Linux Foundation
[email protected]
