Digital product security

SBOM

Software component inventory and supply chain vulnerability management.

What it involves

What we do

We generate and maintain the software bill of materials (SBOM) for your products, integrate it into the development lifecycle and monitor vulnerabilities in third-party and open-source components.

What's included

  • Automated SBOM generation (SPDX, CycloneDX)
  • Integration into CI/CD and release management
  • Continuous monitoring of component vulnerabilities
  • Open-source licence management
  • Delivery of SBOMs to customers and regulators
  • Third-party component usage policies

Who it's for

  • Manufacturers subject to the CRA
  • Software suppliers to the public and critical sectors
  • Development teams with a large open-source footprint

Deliverables

  • SBOM per product and version
  • Automated process
  • Component vulnerability reports

Reference frameworks and standards

CRASPDXCycloneDXNTIA

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does SBOM fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.