STP
SBOM Observer/

Getting Started

Assess readiness and plan your SBOM implementation journey

Before implementing SBOM and VEX practices, assess your organization's readiness, understand maturity levels, and plan resources appropriately. Rushing into implementation without preparation often leads to incomplete coverage, poor quality, or unsustainable manual processes.

Why start here

Organizations frequently ask "where do we start?" The answer depends on:

  • Your role (producer vs consumer)
  • Current capabilities and infrastructure
  • Available resources (time, budget, skills)
  • Regulatory drivers and timelines
  • Existing security and development practices

This section helps you:

  1. Assess readiness — identify capability gaps and dependencies before starting
  2. Understand maturity levels — know what "good" looks like at each stage
  3. Choose your starting point — select appropriate workflows for your context
  4. Plan resources — estimate realistic time, budget, and skill requirements

Quick self-assessment

Answer these questions to determine where to focus:

For producers:

For consumers:

  • Do you have a system to store and query SBOMs? → If no, see Resource Planning
  • Can you correlate SBOMs with vulnerability data? → If no, see Maturity Levels
  • Do you have processes for requesting SBOMs from suppliers? → If no, see Consumer Workflows

Maturity progression

Most organizations progress through these stages:

Level 1 (Basic) — Manual generation, basic formats, ad-hoc sharing

  • Characteristics: Manual SBOM creation, limited automation, basic metadata
  • Timeline: 1-3 months to establish
  • Outcome: Meet minimum compliance requirements

Level 2 (Advanced) — Automated generation, quality gates, systematic lifecycle management

  • Characteristics: CI/CD integration, validation pipelines, VEX coordination, comprehensive metadata
  • Timeline: 6-12 months from Level 1
  • Outcome: Operational excellence and proactive vulnerability management

See Maturity Levels Overview for detailed characteristics and progression strategies.

Common starting scenarios

Scenario 1: Regulatory compliance deadline

Context: You must provide SBOMs to customers or regulators within 3 months.

Recommended path:

  1. Start with Organizational Readiness rapid assessment
  2. Target Level 1 (Basic) initially
  3. Use Producer Workflows - Generate SBOMs for manual approach
  4. Plan Level 2 automation after meeting deadline

Scenario 2: Customer request for transparency

Context: Major customer requests SBOMs as procurement requirement.

Recommended path:

  1. Review Resource Planning for one-time vs ongoing costs
  2. Evaluate Choosing Your Starting Point based on product portfolio size
  3. Consider Security and Access Control for sensitive products

Scenario 3: Improving vulnerability management

Context: You want to use SBOMs to accelerate vulnerability response (e.g., Log4j scenarios).

Recommended path:

  1. Start as consumer: Consumer Workflows
  2. Focus on Vulnerability Management use case
  3. Understand SBOM and VEX Lifecycle for dynamic updates
  4. Plan Integration with Tools

Scenario 4: Supply chain transparency program

Context: Building comprehensive supply chain visibility across organization.

Recommended path:

  1. Complete Organizational Readiness full assessment
  2. Plan both producer and consumer capabilities
  3. Review Maturity Progression Pathways for long-term roadmap
  4. Consider Skills and Training requirements

Next steps

Choose your path:

On this page