Right now, the main topic of conversation on everyone’s lips is AI. Of course, it’s a time of immense change, especially for developers creating apps using RAD techniques. But this year also introduces something that you absolutely do need to pay attention to, right now: new mandatory security legislation. These come in the form of the Cyber Resilience Act, more commonly known as CRA and the Digital Operational Resilience Act, referred to as DORA (nothing to do with the children’s cartoon of the same name). This comes hot on the heels of some significant new requirements for compulsory age verification for iOS and Android apps. More on that in a moment.

Table of Contents
What is an SBOM?
The word SBOM stands for “software bill of materials”, a standardized report that lists a product’s component parts including their license type and version. It’s required to have on hand for customers who request it, specifically in the European Union. It’s actually a pretty simple file, in JSON format, containing some brief details of the items that have gone into the software.

The format of an SBOM file is laid out and formalized at https://cisa.gov/sbom and by NIST (PDF link).

There are a number of other legal frameworks in various countries which refer to SBOM requirements such as the International Standards Organization: https://iso.org/standard/81870.html

All in all, whether you’re in the USA or Europe, or producing software which will be used in either of those regions it’s very likely that SCA, DORA, and SBOM are terms you’ll need to understand and assess the implications of with regard to your own compliance.
Being free or open-source software doesn’t absolve you of responsibility or potential penalties
There are no discriminations or allowances in the various regulations for authors of free or open-source software. If you don’t comply you can be on the hook for some unpleasantness. Also, hackers and other bandits have absolutely zero compassion for you. When you make it to the front page of Wired Magazine you want it to be for all the right reasons, not because you have become an unwitting pawn in a game of cyberwar chess.

I was very sad to see that the wonderful Notepad++ project was horribly abused by “state-sponsored hackers”. In other words, cyberwarfare. Don Ho, Notepad++’s author has been posting updates but, according to him, the Notepad++ update mechanism was completely abused, compromised, and infected by government-backed hackers for the period of June until December 2025. Don’s update explains what happened and how, (and an SBOM would not have made any difference), and he does try to explain the part his former web host played in the hack. That said, given the sheer number of users of Notepad++ if even a very tiny percentage decide to sue it would be irrelevant if they win or not – the costs of defending what would amount of 100s of legal cases is likely to be brutally life-changing.
Don’s a decent guy, a developer like you and I, and he didn’t deserve the attentions of a state-sponsored trojan/virus attack (who does?) but his situation is a wake-up call for all of us and, coupled with this year’s maturation of the legal software composition requirements and the drift towards to more and more government legislation in connection with it.
What next for Notepad++ users?
This kind of supply chain hack is becoming increasingly common. Sister company UltraEdit had experienced a near miss themselves nearly two decades ago – before Idera purchased the company. So, they have felt that terrible gut-punch of being attacked by professional hackers bent on using you to infect your users – and it forced them to completely reevaluate how they approached security. I’m sure it will also put Don Ho in a similar frame of mind too and eventually he will crawl from under that pile of bricks the hackers brought down on the Notepad++ project.
Now UltraEdit completely focuses on security, at the core of what they do. The best lesson is often the hardest, most painful lesson, no matter how unwanted. I’ve had a whole bunch of our MVPs swapping from Notepad++ to UltraEdit this week (they get complimentary licenses). A sad situation for Notepad++.

Upcoming security webinars, and Delphi’s 31st Birthday!
As luck would have it, we had already planned specific webinars regarding security. DerScanner, one of our tech partners, had arranged a deal with us at the end of last year (long before the news of the Notepad++ infection). We have another security-focused webinar pre-planned for March 6th exploring a whole collection of other security and compliance software specially aimed at Delphi and C++Builder. We’ll also be looking at the new features in InterBase 15 to support FIPs compliance among other things.
Using DerScanner’s SBOM analysis
The details of the deal are available from our sales partners and join me on February 10th too for Delphi’s 31st anniversary where I am told there will be some other announcements coming up – and a special must not miss top secret future feature preview by Marco Cantú. Sign up for that either by clicking the link in the emails or via this link.

Where can I see the “What is an SBOM” webinar replay?
Here’s the full replay of the live SBOM security webinar with Valerie Kim from Der Scanner.
Reduce development time and get to market faster with RAD Studio, Delphi, or C++Builder.
Design. Code. Compile. Deploy.
Free Delphi Community Edition Free C++Builder Community Edition





