# Scale SBOM > Scale SBOM is a free, open source operational framework for software transparency. It turns SBOM and VEX standards into guidance that engineering, security and procurement teams can act on. Every page is available as markdown by appending `.md` to its URL, or by requesting it with `Accept: text/markdown`. The full text of all pages is in [llms-full.txt](https://scalesbom.org/llms-full.txt). ## Docs - [Operational SBOM Framework](https://scalesbom.org/docs.md): From SBOM and VEX standards to operational execution - **Framework Structure** - Content Requirements - [Content Requirements](https://scalesbom.org/docs/content-requirements.md): What information belongs in your transparency documents - [SBOM Requirements](https://scalesbom.org/docs/content-requirements/sbom-requirements.md): Maturity levels, required metadata, component expectations, and dependency guidance - **Concepts** - [Concepts](https://scalesbom.org/docs/content-requirements/concepts.md): Start here for standards, terminology, and encoding rules - [Standards and Frameworks](https://scalesbom.org/docs/content-requirements/concepts/standards-and-frameworks.md): Normative references and standards underpinning the content requirements - [Artifact Fundamentals](https://scalesbom.org/docs/content-requirements/concepts/artifact-fundamentals.md): Terminology, requirement levels, roles, and core concepts for transparency artifacts - [Formats and Encoding](https://scalesbom.org/docs/content-requirements/concepts/formats-and-encoding.md): Accepted SBOM and VEX formats, encoding rules, and validation - **Topical Guidance** - [Components](https://scalesbom.org/docs/content-requirements/components.md): Identity, provenance, and field requirements for SBOM components - [Suppliers](https://scalesbom.org/docs/content-requirements/suppliers.md): Supplier identification, attestation, and signing requirements - [Vulnerabilities](https://scalesbom.org/docs/content-requirements/vulnerabilities.md): Vulnerability identification, tracking, and disclosure in SBOMs and related artifacts - [VEX / VDR](https://scalesbom.org/docs/content-requirements/vex-vdr.md): Vulnerability Exploitability eXchange and Vulnerability Disclosure Report requirements - [Licenses](https://scalesbom.org/docs/content-requirements/licenses.md): License identification, expression syntax, and compliance requirements for SBOM components - **Resources** - [SBOM Examples](https://scalesbom.org/docs/content-requirements/examples.md): Download example SBOM, VEX, and VDR documents in standardized formats - Operational Model - [Operational Model](https://scalesbom.org/docs/operational-model.md): How to integrate software transparency into your organization's operations - Getting Started - [Getting Started](https://scalesbom.org/docs/operational-model/getting-started.md): Identify your role, set your ambition level and find the right entry point - Core Concepts - [Core Concepts](https://scalesbom.org/docs/operational-model/core-concepts.md): Foundational concepts for SBOM and VEX operations - [Software Bill of Materials (SBOM)](https://scalesbom.org/docs/operational-model/core-concepts/sbom.md): What a Software Bill of Materials contains and how it is structured. - [Vulnerability Exploitability eXchange (VEX)](https://scalesbom.org/docs/operational-model/core-concepts/vex.md): How VEX communicates vulnerability impact and how its statuses work. - [Vulnerabilities](https://scalesbom.org/docs/operational-model/core-concepts/vulnerabilites.md): How software vulnerabilities are identified, tracked, scored and prioritized across the CVE ecosystem - [Maturity Levels](https://scalesbom.org/docs/operational-model/core-concepts/maturity-levels.md): Operational characteristics that distinguish L1 and L2 SBOM maturity - Use Cases - [Use Cases](https://scalesbom.org/docs/operational-model/use-cases.md): Practical applications of SBOMs and VEX across security, compliance, and operations - [Release Management](https://scalesbom.org/docs/operational-model/use-cases/release-management.md): How SBOMs coordinate the software release lifecycle from build through distribution to end-of-life - [Vulnerability Management](https://scalesbom.org/docs/operational-model/use-cases/vulnerability-management.md): Using SBOMs and VEX to detect, assess, and act on vulnerabilities across producer and consumer workflows - [License Compliance](https://scalesbom.org/docs/operational-model/use-cases/license-compliance.md): Using SBOM license data for systematic compliance management across open-source and commercial dependencies - [Supplier Transparency](https://scalesbom.org/docs/operational-model/use-cases/supplier-transparency.md): Using SBOM supplier data to assess third-party risk, enforce procurement policies, and maintain ongoing supplier assurance - [Regulatory Compliance](https://scalesbom.org/docs/operational-model/use-cases/regulatory-compliance.md): What the EU Cyber Resilience Act requires of manufacturers, and where SBOM and VEX fit in - Workflows - [Workflows](https://scalesbom.org/docs/operational-model/workflows.md): Generating, distributing, and monitoring SBOMs and VEX documents - [Generate SBOMs](https://scalesbom.org/docs/operational-model/workflows/generate-sboms.md): When to generate SBOMs, how the generation pipeline works, and where to store the results - [Vulnerability Disclosure](https://scalesbom.org/docs/operational-model/workflows/vulnerability-disclosure.md): Structured process for producers to assess, disclose, and communicate vulnerabilities to customers and authorities - **Role-based Guides** - [Role-based Guides](https://scalesbom.org/docs/roles.md): Choose the guide that matches how you work with SBOM, VEX, and VDR - Producer Guide - [Producer Guide](https://scalesbom.org/docs/roles/producer.md): Orientation for organisations that build and ship software and need to provide transparency artifacts - Consumer Guide - [Consumer Guide](https://scalesbom.org/docs/roles/consumer.md): Orientation for organisations that procure and operate software and need visibility into what they run - Explorer Guide - [Explorer Guide](https://scalesbom.org/docs/roles/explorer.md): Figure out where to start with SBOMs, VEX, and VDR based on your situation - **Resources** - [Maturity Assessment](https://scalesbom.org/docs/assessments/maturity) - External Resources - [External Resources](https://scalesbom.org/docs/external-resources.md): Curated index of authoritative documents for software transparency work - About - [About](https://scalesbom.org/docs/about.md): What the Scale SBOM framework is, who it is for and who maintains it