Operational SBOM Framework
From SBOM and VEX standards to operational execution
Scale SBOM turns SBOM and VEX standards into practical guidance for engineering, security, and procurement teams. It covers what transparency artifacts should contain, how to produce and consume them and where to start improving. The framework is free, open source, and welcomes contributions.
In the framework
Content Requirements
What good SBOM and VEX artifacts need to contain.
Operational Model
How to produce, share, and consume transparency artifacts in practice.
Assessment Tool
Measure your current maturity and see what to improve next.
What transparency artifacts are for
Software transparency helps producers answer what is in a product and helps consumers decide whether they can trust and operate it safely. SBOM and VEX artifacts make component inventory, vulnerability status, and supplier communication machine-readable and easier to manage at scale.
The EU Cyber Resilience Act (CRA) requires manufacturers to report actively exploited vulnerabilities from 11 September 2026 and to document software components in an SBOM from 11 December 2027. NIS2 and DORA add supply chain requirements for operators of essential services and financial entities. See Regulatory Compliance.
Scale SBOM provides the operational guidance to get there, whether your team is starting from scratch or tightening existing practices.
Where to start
- New here? Start with the Explorer guide.
- Build and ship software? Use the Producer guide.
- Buy and operate software? Use the Consumer guide.