Product Security · P0

Software Supply Chain Security & SBOM Readiness

A customer asks for an SBOM, a regulator asks how you would know if a component you ship carried a known exploited vulnerability, and the honest answer is a package manifest and hope. Software supply chain security is the ability to say what is in your product, where it came from, whether it is vulnerable, and how you would find out.

This assessment provides a readiness indicator based on the information provided. It is not an audit, a certification, or a guarantee of security outcomes.

Who it is for

The companies this problem finds first.

Software vendors selling to federal, critical-infrastructure or enterprise buyers

Companies with large open-source dependency trees

Product makers facing the EU Cyber Resilience Act

Companies that use third-party and AI components they did not build

When it comes up

The moments that turn this from a someday into a now.

  • Customer or federal SBOM request
  • Critical open-source vulnerability with unknown exposure
  • Cyber Resilience Act or secure-software attestation obligation
  • Build or CI compromise in the news, and the board asks "could that be us?"
  • Acquisition of a product with an unknown component tree
What we assess

9 areas, one control library.

Every area maps to controls already in the platform's single control library, so evidence collected here counts toward every other framework the business has adopted.

Software product and release inventory

Component and dependency inventory (SBOM)

Component vulnerability monitoring, including known exploited vulnerabilities

Open-source licence policy and compliance

Build pipeline integrity, provenance and signing

Third-party and vendor software risk

Dependency update and patch cadence

Supplier security requirements and contracts

Monitoring and alerting on new component risk

What you get

Deliverables you can hand to a buyer, a board or a regulator.

  • Software product register with per-product SBOM status and freshness
  • Component inventory imported from CycloneDX or SPDX, with vulnerability and licence status
  • Monitoring alerts: known exploited vulnerabilities in shipped components, denied licences, stale SBOMs
  • Pipeline integrity and provenance findings
  • Supplier software-risk requirements
  • Remediation roadmap and customer-facing SBOM handling process
Frameworks behind it

The sources every control cites.

Requirement statements are plain-English summaries for planning; the source instrument controls. Which of these reach your business is a question the assessment records with its reasoning, not one this page answers.

  • NIST Secure Software Development Framework (SSDF) v1.1, SP 800-218
  • NIST Cybersecurity Framework 2.0
  • ISO/IEC 27001
  • NIST SP 800-53
Value by role

What each executive gets out of it.

CEO

Answer the SBOM question the day it is asked, not the quarter after.

CFO

Component risk becomes a monitored inventory instead of an unbudgetable surprise.

CTO / engineering

One product-to-component-to-vulnerability view engineering can act on, fed from the SBOMs you already generate.

General counsel

Licence exposure and supplier obligations tracked per product, per release.

CISO / security lead

Known exploited vulnerabilities in shipped code surface as alerts tied to the products and customers affected.

How it fits

Integrated capabilities, not a separate programme.

Engagement tiers

Product Security · Enterprise Growth · Continuous Assurance. Tiers describe depth and cadence; there is no per-regulation price.

Usually bought by

CTO / engineering, Head of engineering, CISO / security lead, Chief product officer

Part of these packages

SaaS Enterprise Readiness · AI Company · EU Expansion

FAQ

The objections, answered directly.

Dependency bots see one repository at a time and do not know which products, releases or customers a component reaches. The register answers the question buyers and regulators ask.

Federal buyers, critical-infrastructure customers and the CRA are moving that from a request to a condition. Having the inventory before the request is the cheap version.

It becomes your problem the moment it is in your product or your environment. Supplier requirements and monitoring are part of this service for that reason.

Start with the free check.

Free check: a short, scored indicator of where you stand and the evidence that would close each gap. A consultant follows up to scope the full readiness engagement.

Start the free Free checkSpeak with an advisor