- 130 CVEs daily in 2025: The National Vulnerability Database logged this many new vulnerabilities, highlighting the scale of security challenges.
- 92% concerned about AI-generated code: A 2024 Venafi survey revealed widespread unease among security decision-makers regarding AI coding assistants.
- FDA mandate for binary-verified SBOMs: Medical device submissions now require verified SBOMs, closing a major loophole in software transparency.
Experts agree that the shift toward binary-level analysis is critical to bridging the SBOM accuracy gap, ensuring regulatory compliance, and mitigating risks from AI-generated code and complex supply chains.
The SBOM Accuracy Gap: How Binary-Level Scans Tackle AI and Regulatory Risk
TORONTO, ON – July 06, 2026 – In the intricate world of modern software, trust is a fragile commodity. The global software supply chain, a complex web of proprietary code, open-source components, and third-party libraries, has become a primary target for cyberattacks. In response, regulators worldwide have championed the Software Bill of Materials (SBOM) as a foundational tool for transparency—a detailed inventory intended to reveal every component within a piece of software. Yet, a critical accuracy gap threatens to undermine this effort. Most SBOMs are only as good as the manifests developers declare, leaving a significant blind spot for what is actually built and deployed.
This gap is being exploited by the very trends the industry is embracing. The proliferation of AI coding assistants introduces unaudited dependencies, while complex build processes obscure the final product's true composition. Addressing this challenge is Toronto-based cybersecurity firm Insignary, which is gaining recognition for a “binary-first” approach that moves beyond developer declarations to analyze the final, compiled software. The company's recent acknowledgment as a Sample Vendor for Reachability Analysis in Gartner's 2026 Hype Cycle for Secure Software Engineering highlights a strategic shift in the market: the move from simple attestation to verifiable proof.
The Regulatory Hammer Falls on Software Transparency
The era of simply trusting a vendor’s security claims is officially over. Governments are no longer accepting a signed form as proof of software integrity; they are demanding the ability to verify it themselves. This shift is most evident in the United States with Executive Order 14028 and the subsequent OMB Memorandum M-26-05. These directives empower federal agencies to independently validate the SBOMs of software they procure, effectively raising the compliance bar for any company selling to the U.S. government.
Nowhere is this demand for verifiable accuracy more stringent than in the medical device industry. The FDA’s Section 524B now mandates that every premarket submission for a connected medical device must include a binary-verified SBOM. This specific language closes a major loophole, requiring manufacturers to provide a complete inventory of all compiled software components, not just those listed in source-code manifests. The implication is clear: if it’s in the final code that runs on the device, it must be on the SBOM, along with its known vulnerabilities.
This regulatory pressure is not isolated to North America. Canada's Critical Cyber Systems Protection Act (CCSPA), which took effect in June 2026, imposes mandatory supply chain risk management on critical infrastructure operators in banking, energy, and transportation. Similarly, the EU’s Cyber Resilience Act is pushing for greater accountability across the software lifecycle. This global trend makes one thing certain: having an accurate, verifiable SBOM is no longer a best practice but a non-negotiable requirement for market access.
“SBOMs are increasingly becoming a regulatory requirement around the world,” said Taek Wan Kim, President & CEO of Insignary, in a recent statement. “However, software transparency is only as reliable as the accuracy of an SBOM itself. You cannot verify an SBOM by reading the manifest that created it. You verify an SBOM by examining the software that was actually built, shipped, and deployed.”
Beyond the Manifest: Why Binary Analysis Matters
Traditional Software Composition Analysis (SCA) tools have been the workhorses of application security for years, scanning source code and package manager files like package.json or pom.xml to identify declared open-source dependencies. While valuable, this method has inherent limitations. It often misses undeclared transitive dependencies, components statically linked during the build process, and proprietary libraries delivered only as binaries—the so-called “black boxes” of the software world.
This is where binary-first analysis creates a strategic advantage. By examining the compiled executable—the same code that runs in production—platforms like Insignary Clarity aim to create a definitive record of a program’s composition. Using patented binary fingerprinting technology, the platform can identify components, their versions, and their licenses without access to the original source code. This provides a ground truth that is essential for verifying third-party software or assessing legacy applications where the source may be lost.
Furthermore, the challenge isn't just about finding every component; it's about understanding which vulnerabilities pose a real threat. With the National Vulnerability Database logging roughly 130 new CVEs daily in 2025, security teams are drowning in alerts. This is where Reachability Analysis, the technology for which Gartner recognized Insignary, becomes a critical differentiator. By analyzing the application’s code paths, it determines whether a vulnerable function within a dependency can actually be executed. If a vulnerable piece of code is present but never called, it poses a significantly lower risk. This allows organizations to triage vulnerabilities based on exploitability, cutting through the noise of “alert fatigue” and focusing remediation efforts where they matter most.
Taming the Wild West of AI-Generated Code
The software supply chain's complexity is being amplified by the rapid adoption of AI coding assistants. While these tools promise unprecedented productivity, they also introduce a new frontier of risk. A 2024 Venafi survey found that 92% of security decision-makers are concerned about the security of AI-generated code, with many considering an outright ban. The core problem is a lack of transparency. AI models, trained on vast repositories of public code, can inject snippets or entire libraries that are never declared in a manifest, creating hidden dependencies and a shadow supply chain.
Traditional SCA tools, reliant on those manifests, are often blind to these additions. This is why the concept of an “AI Bill of Materials” (AIBOM), a feature of Insignary’s platform, is gaining traction. By applying binary analysis to software containing AI-generated code, organizations can uncover these hidden components and assess their associated security and licensing risks.
The binary-first approach is uniquely suited for this challenge because it is agnostic to how the code was written—whether by a human developer or an AI assistant. It analyzes the final product, providing a complete picture that includes AI-introduced elements. When combined with Reachability Analysis, this capability allows security teams to not only identify vulnerabilities introduced by AI but also to determine if they are actually exploitable within the application, providing a rational basis for managing this emerging risk vector.
From Niche Technology to Mainstream Strategy
The convergence of tightening regulations and the rise of AI is transforming binary analysis from a niche forensic tool into a cornerstone of mainstream business strategy. Insignary’s repeated citation in four separate Gartner reports over the past two years signals this growing relevance. The technology is no longer just for security purists but for CISOs, compliance officers, and business leaders who need to manage risk across their entire software portfolio.
This strategic importance is reflected in the company's global expansion, supported by key partnerships with consulting firm BearingPoint in Europe and a joint SBOM initiative with Cybertrust Japan and TechMatrix in Japan. These collaborations are focused on markets with mature regulatory frameworks, where the demand for verifiable software trust is highest. As one Gartner report notes, “An SBOM is foundational to managing the complexity and securability of modern software deployments.”
For companies operating in critical infrastructure, defense, medical, and financial services, proving what is inside their software is becoming as important as what that software does. The ability to look past the manifest and verify the binary is emerging as the new standard for building a future-proof, resilient, and trustworthy business.
