The Software Transparency Framework
Three practical pillars: what to include, how to run it, and how to track progress.
Content Requirements
Field-by-field guidance for SBOMs and VEX. Learn exactly what information belongs in your transparency documents with real-world examples.
Operational Model
End-to-end workflows for producers and consumers. How to generate, distribute, and integrate transparency data into your security pipeline.
Maturity Assessment
Measure your current capabilities and identify gaps. A structured self-assessment to benchmark your organization and prioritize improvements.
Built with industry-leading standards
Start Your Journey
Pick the path that fits your role in the software supply chain.
Producer
You manufacture, supply, or distribute software. Learn what to provide and how to communicate vulnerability impact effectively.
Consumer
You procure and secure software. Understand how to request, interpret, and integrate vendor transparency data.
Explorer
New to transparency? Browse the full framework, understand the pillars, and find where to start based on your needs.
Build your software
transparency foundation.
Join the community of organizations implementing open standards for a more secure and transparent software supply chain.
