Understanding Stakeholder Expectations and Practices in Software Composition Analysis Tools
Yudai Yamamoto, Momoka KIHARA, Satoshi HARA, Takayuki Sasaki, Katsunari Yoshioka · IEICE Transactions on Fundamentals of Electronics Communications and Computer Sciences · 2026
Software supply chain security has become increasingly important, and Software Composition Analysis (SCA) tools are expected to serve as a primary means for identifying open-source software (OSS) components and generating Software Bills of Materials (SBOMs). However, prior research has mainly focused on technical performance, such as detection accuracy in identifying OSS components and vulnerabilities, and has not sufficiently examined the differences in expectations and perceptions between vendors who design and provide these tools and users who deploy them in practice. In this study, we conducted semi-structured interviews with SCA tool vendors and enterprise users to qualitatively analyze perception gaps among stakeholders. In addition, we presented SCA tool accuracy evaluation results to vendors and users. We then collected their interpretations and reactions to the concrete performance data. Our analysis revealed three gaps: (1) a gap between the high level of accuracy expected by users and the actual accuracy of current tools, (2) differences among vendors regarding the perceived role and responsibility of SCA tools, and (3) a mismatch between vendors' assumptions of continuous use during development and users' actual practices centered on acceptance testing. Furthermore, we found that regulatory compliance is often a primary motivation for adoption, suggesting that SBOM generation can become an end in itself and may lead to “compliance theater,” where the process does not necessarily result in meaningful risk reduction. This study highlights the need for vendors to clarify intended use cases and detection limitations, for users to define their usage requirements more explicitly, and for the broader ecosystem to establish third-party evaluation infrastructures and standardization. Our findings provide design and operational implications for improving the effective use of SCA tools in software supply chain security.