SBOM: an inventory that is only useful if it is generated at build time
The point of an SBOM is answering “are we affected?” in an hour instead of a fortnight. Produced by scanning a finished artefact, it usually cannot.
A flat parts list looks simpler and answers none of the questions a BOM exists for — what to buy, what it costs, and what a change breaks.
A bill of materials lists everything required to build a product: components, sub-assemblies, quantities, and how they fit together. It is the document purchasing buys from, production builds from, finance costs from and engineering changes — which is why disagreements between departments are usually disagreements about the BOM.
The first decision is structure. A flat list of every part is easy to produce and cannot express that a product contains three of one sub-assembly, each containing four of a component. A multi-level BOM can, and that is what makes it possible to cost a change, to buy at the right level, and to know what else is affected when a part is superseded.
The engineering BOM describes the product as designed; the manufacturing BOM describes it as built, including packaging, consumables, and the sequence in which sub-assemblies come together. Companies that maintain only one end up with either an engineering document that cannot be built from or a production document that no longer reflects the design. Keeping both, with a defined relationship between them, is more work and is what prevents the recurring argument about which version is right.
Approved alternates belong on the BOM, not in someone’s memory. When a component goes on allocation, the question is which substitute is already approved — and if the answer lives with one engineer rather than in the document, production stops while it is found out.
Rolled-up cost is where BOM errors surface financially: a quantity entered per assembly rather than per unit, a sub-assembly counted twice, scrap factors applied at the wrong level. Because the roll-up produces a plausible number regardless, these errors survive until a margin looks wrong. Reconciling a costed BOM against an actual build once, physically, is the cheapest audit available and usually finds at least one of them.
Ettex Sheets holds the structure with levels and quantities where they can be checked and rolled up, Ettex Records keeps the drawings, specifications and approved-manufacturer evidence each line refers to, and the process for changing any of it is covered in engineering change order. Keeping it current at scale is covered in bom management.
Being direct: this is a spreadsheet and a document file, not a PLM or ERP system. Past a few hundred parts with real revision control, a dedicated system is the right purchase; what this covers is the structure and discipline that any system will otherwise inherit badly.
A structured list of the components, sub-assemblies and quantities required to build a product, used by purchasing, production, finance and engineering.
The engineering BOM describes the product as designed; the manufacturing BOM describes it as built, including packaging, consumables and assembly sequence.
Multi-level, wherever sub-assemblies exist. A flat list cannot express hierarchy, which is what costing and change impact depend on.
On the BOM itself, as approved manufacturer entries — not in an engineer’s memory, where they are unavailable during a shortage.
The point of an SBOM is answering “are we affected?” in an hour instead of a fortnight. Produced by scanning a finished artefact, it usually cannot.
Type 1 says the controls were designed properly on one day. Type 2 says they worked for months. Enterprise buyers ask for the second and accept the first only as a step towards it.
Registration costs nothing and lapses on a date nobody diarises. An expired entity cannot be awarded a contract or paid on an existing one.