Skip to main content
QUICK REVIEW

[Paper Review] A Survey on Mapping Digital Systems with Bill of Materials: Development, Practices, and Challenges

Shuai Zhang, Minzhao Lyu|arXiv (Cornell University)|Jan 16, 2026
Digital Platforms and Economics0 citations
TL;DR

This survey provides a cross-domain review of BOM developments (SBOM, CBOM, AIBOM, HBOM, SaaSBOM) for software, hardware, AI, data, and cryptographic assets, summarizing evolution, practices, uses, and research gaps.

ABSTRACT

Modern digital ecosystems, spanning software, hardware, learning models, datasets, and cryptographic products, continue to grow in complexity, making it difficult for organizations to understand and manage component dependencies. Bills of Materials (BOMs) have emerged as a structured way to document product components, their interrelationships, and key metadata, improving visibility and security across digital supply chains. This survey provides the first comprehensive cross-domain review of BOM developments and practices. We start by examining the evolution of BOM frameworks in three stages (i.e., pre-development, initial, and accelerated) and summarizing their core principles, key stakeholders, and standardization efforts for hardware, software, artificial intelligence (AI) models, datasets, and cryptographic assets. We then review industry practices for generating BOM data, evaluating its quality, and securely sharing it. Next, we review practical downstream uses of BOM data, including dependency modeling, compliance verification, operational risk assessment, and vulnerability tracking. We also discuss academic efforts to address limitations in current BOM frameworks through refinements, extensions, or new models tailored to emerging domains such as data ecosystems and AI supply chains. Finally, we identify four key gaps that limit the usability and reliability of today's BOM frameworks, motivating future research directions.

Motivation & Objective

  • Trace the historical and current evolution of BOM concepts from hardware to digital ecosystems.
  • Summarize domain-specific BOM practices, standards, and adoption across software, hardware, AI, data, and cryptographic assets.
  • Analyze data generation, quality, and sharing practices for BOM data.
  • Identify limitations and gaps in current BOM frameworks to motivate future research directions.

Proposed method

  • Conduct systematic literature searches across Google Scholar, ACM DL, IEEE Xplore, and arXiv targeting SBOM, CBOM, AIBOM, HBOM, and SaaSBOM.
  • Provide a cross-domain synthesis of BOM developments, standards, and industry adoption since 2020.
  • Describe the three-stage BOM evolution (pre-development, initial, accelerated) and map domain-specific standards and frameworks.
  • Summarize practical BOM data generation, management, and usage in security, compliance, and risk assessment.
  • Discuss academic efforts to refine or extend BOM models to emerging domains like AI, data ecosystems, and IoT.

Experimental results

Research questions

  • RQ1What are the historical and current developments of BOM frameworks across software, hardware, AI models and datasets, cryptographic assets, and SaaS?
  • RQ2How do industry practices generate, validate, and share BOM data, and what affects data quality and usability?
  • RQ3What are the practical uses of BOM data in dependency modeling, compliance, risk assessment, and vulnerability tracking?
  • RQ4What gaps exist in current BOM frameworks, and what future directions address emerging domains and challenges?

Key findings

  • BOM frameworks have evolved from hardware-centric to cross-domain coverage including SBOM, CBOM, AIBOM, HBOM, and SaaSBOM.
  • Regulatory and standards activity accelerated after 2021, with formalization of SBOMs (SPDX, CycloneDX) and domain extensions for AI, hardware, SaaS, and cryptography.
  • Industry practices emphasize data quality, sharing, and usability, while highlighting completeness and consistency issues across tools and ecosystems.
  • Four key gaps limit current BOM usability and reliability: coverage for AI and data ecosystems, standardized data sharing, runtime and provenance tracking, and scalability for dynamic environments.
  • Academic efforts propose extended models, augmented metadata, and runtime/build-time tracing to overcome metadata limitations.
  • There is ongoing work to generate BOM data without source code access and to augment BOMs with domain-specific fields (privacy, security, cryptography, provenance).

Better researchstarts right now

From reading papers to final review, dramatically reduce your research time.

No credit card · Free plan available

This review was created by AI and reviewed by human editors.