Skip to content

Without an SBOM

Eight questions, one PDF report.

For teams that do not yet have a bill of materials to upload. The report computes an exposure score, lists gaps, and proposes a checklist. Generated on the server, without artificial intelligence.

  1. 01Do you have an up-to-date list of products containing software that you sell in Europe?
  2. 02Can you produce an SBOM (CycloneDX or SPDX) for every currently shipped version?
  3. 03Is someone named as responsible for deciding when an actively exploited flaw appears?
  4. 04How quickly could you tell which shipped products embed a given library?
  5. 05Are versions that are no longer sold, but still installed at customers, inventoried?
  6. 06Do you continuously monitor vulnerabilities already exploited in the wild (CISA KEV catalog or equivalent)?
  7. 07Do you keep a dated history of what you decided after an alert (fix, not affected, accept)?
  8. 08Do you have a channel to inform customers of a flaw in a product already shipped?