SBOM Guide

Resources

Scale SBOM, SBOM Observer, authorities and links to sources.

  • Scale SBOM

    Scale SBOM is an open framework that defines how organisations can operationally work with SBOM, VEX and VDR in digital supply chains, with an operational model, content requirements, and a self-assessment tool.

  • SBOM Observer

    SBOM Observer collects SBOMs from build pipelines and suppliers, monitors the components against vulnerability and licence data and checks every release against your rules.

  • ENISA

    ENISA operates the Single Reporting Platform for the CRA and the European Vulnerability Database (EUVD), and publishes guidance on supply chain security.

  • Cybersecurity in Sweden

    The report Cybersecurity in Sweden 2024 from the Swedish National Cyber Security Centre (NCSC) covers risks in the supply chain, dependencies on suppliers and gaps in requirements.

  • External links

    Links to authorities, standards bodies and vulnerability databases in the EU and the US, and to reports from companies and industry organisations.