Bytesafe/Scale SBOM

Operational SBOM Framework

From SBOM and VEX standards to operational execution

Scale SBOM turns SBOM and VEX standards into practical guidance for engineering, security, and procurement teams. It covers what transparency artifacts should contain, how to produce and consume them and where to start improving. The framework is free, open source, and welcomes contributions.

In the framework

What transparency artifacts are for

Software transparency helps producers answer what is in a product and helps consumers decide whether they can trust and operate it safely. SBOM and VEX artifacts make component inventory, vulnerability status, and supplier communication machine-readable and easier to manage at scale.

The EU Cyber Resilience Act (CRA) requires manufacturers to report actively exploited vulnerabilities from 11 September 2026 and to document software components in an SBOM from 11 December 2027. NIS2 and DORA add supply chain requirements for operators of essential services and financial entities. See Regulatory Compliance.

Scale SBOM provides the operational guidance to get there, whether your team is starting from scratch or tightening existing practices.

Where to start

On this page