Most standards work in this space focuses on compliance artifacts: SBOMs for the Cyber Resilience Act, attestations for procurement requirements. Less attention goes to the underlying tools developers actually use. The dependency graph that feeds the SBOM generator, the metadata lookup that powers vulnerability scanning, the notification when a new version ships.
Says standards in this topic are aimed at compliance. SBOMs for the Cyber Resilience Act e.g. [[Cyber Resilience Act CRA EU 20231026123507]]
