4.2.2026Embarcadero bundles SBOM reports and security scans in limited-time offer
Software teams are getting asked a question more often than ever:
"Can you provide your SBOM?" Whether it comes from a customer, an auditor, or procurement,
it usually arrives at the worst possible time—right before a release or during a renewal.
A new limited-time promotion for Delphi / RAD Studio Enterprise & Architect licenses is designed
to make that request easier to handle. The offer says new licenses include
SBOM generation and application security scans at no additional cost, delivered through a partnership
with DerScanner. The deadline mentioned in the promo is February 28.
What’s included
According to the promotion, buyers receive:
- Two SCA (Software Composition Analysis) scans to generate a verifiable SBOM
- A SAST scan to identify potential security issues in Delphi code
- A code quality scan to surface structural problems early
- A standardized report meant to be easy to share with customers, security teams, or auditors
What an SBOM is—and why it matters
An SBOM (Software Bill of Materials) is a standardized inventory of the components that make up your
software—typically including third-party libraries, versions, and licensing information.
SBOMs matter because they help teams:
- Answer customer and audit requests quickly
- Respond faster to newly disclosed vulnerabilities
- Reduce supply-chain risk by making dependencies visible
- Support license compliance by documenting what’s included
The promotion also argues that SBOM expectations are rising sharply, especially for companies selling into regulated
markets or enterprise buyers.
How to get an SBOM for a commercial software project
Most teams generate SBOMs in one of these practical ways:
-
Use an SCA tool in your CI/CD pipeline
Automatically scans dependencies and exports SBOMs (commonly in SPDX or CycloneDX formats) as part of release
builds.
-
Generate from your build/package systems
Some ecosystems can export dependency data that can be converted into an SBOM, especially if your dependency
metadata is well maintained.
-
Treat SBOMs as release artifacts
Version the SBOM alongside the build it represents, store it with your release outputs, and keep it traceable to
a specific commit/build.
-
Use a bundled or managed solution
Some commercial toolchains and service providers offer SBOM generation alongside security scanning and reporting,
which can reduce setup and overhead.
SBOMs are becoming a routine part of doing business for commercial software teams. The easiest way to avoid a
last-minute scramble is to make SBOM generation part of your normal release process—so when someone asks, you
already have it ready.
Vendor info