The global market for automotive software bills of materials (SBOMs) is forecast to grow from $440 million in 2026 to $1.8 billion by 2034 as vehicle software becomes more complex and manufacturers face tighter cybersecurity requirements.
According to research from Fortune Business Insights, the market is expected to expand at a compound annual growth rate of 19.3% between 2026 and 2034. The report attributes the growth to the rise of software-defined vehicles, increasingly complex software supply chains, cybersecurity regulation and the need to track vulnerabilities throughout the vehicle lifecycle.
An SBOM provides an inventory of the software components used in a product, helping manufacturers and suppliers identify dependencies and assess the potential impact of newly disclosed vulnerabilities.
The research forecasts electric vehicles to be the fastest-growing propulsion segment, with a 22.4% CAGR. Buses and coaches are expected to record the fastest growth among vehicle types, at 23.7%.
Growth is also expected further down the automotive supply chain. Tier 2 and lower-tier suppliers are forecast to expand at 22% annually, while professional and managed SBOM services, alongside vulnerability correlation, Vulnerability Exploitability eXchange (VEX) and remediation-management solutions, are each projected to grow at 20.4%.
China is expected to account for about $110m of the market in 2026, or roughly 24.8% of global revenue, according to the report. The US market is estimated at $80m, representing approximately 19% of global revenue.
The market is also shifting from SBOMs produced periodically towards continuously generated inventories integrated into software development and DevSecOps processes.
Matt Wyckhouse, Founder and CEO of Finite State, said the challenge was increasingly moving beyond simply producing an SBOM. “The interesting thing about the growth of the SBOM market is that the SBOM itself is becoming table stakes,” he said.
The greater challenge, he said, is determining what software is actually present in increasingly complex vehicle systems, assessing whether newly disclosed vulnerabilities create a material risk, and responding quickly.
“In automotive, that requires going well beyond traditional SCA and analysing the firmware and binaries that actually ship in the vehicle,” Wyckhouse said.
The shift matters as vehicle manufacturers increasingly depend on software developed across multiple suppliers and technology stacks. For automation and engineering teams, the implication is that software-component visibility is becoming part of the wider process of managing connected products throughout their operational lifecycles.
There’s plenty of other editorial on our sister site, Electronic Specifier! Or you can always join in the conversation by commenting below or visiting our LinkedIn page
