# Core Concepts (/docs/operational-model/core-concepts)

The operational model references these concepts throughout its workflows and guidance. Read them in any order.

<Cards>
  <Card title="Software Bill of Materials (SBOM)" description="What an SBOM contains, how products and components relate, and which formats encode that information." href="/docs/operational-model/core-concepts/sbom" />

  <Card title="Vulnerability Exploitability eXchange (VEX)" description="How VEX communicates whether a known vulnerability affects a specific product." href="/docs/operational-model/core-concepts/vex" />

  <Card title="Maturity Levels" description="Operational characteristics that distinguish L1 and L2 SBOM maturity." href="/docs/operational-model/core-concepts/maturity-levels" />
</Cards>