
Yet another checklist item.
The SBOM will just wind up being another checklist item. Something that someone on the team will have to fill out to satisfy a "requirement". Good programmers who do security properly will see no change to their work except having to fill out a form. Bad programmers will see no change to their work except having to fill out a form.
Liability is the answer: Make someone somewhere pay damages if the software is insecure, and then you'll start to see changes.