# Operational Model (/docs/operational-model)

The Operational Model provides practical guidance for implementing Software Bills of Materials (SBOMs), Vulnerability Exploitability eXchange (VEX), and Vulnerability Disclosure Reports (VDRs) within your organization. This guide focuses on workflows, processes, and integration strategies rather than content specifications.

While [Content Requirements](/docs/content-requirements) defines *what information* should be in your transparency artifacts, the Operational Model explains *how to produce, distribute, and use* those artifacts.

## What this guide covers [#what-this-guide-covers]

This guide helps you assess organizational readiness, choose appropriate workflows based on your role and maturity level, understand when to update SBOMs versus VEX documents, integrate transparency practices into existing development and security processes, and progress from manual processes to automated, policy-driven operations.

It applies to software producers generating and distributing SBOMs and VEX documents, software consumers requesting and using transparency artifacts, and security, procurement, development, or operations teams integrating SBOM data into their workflows.

## How to navigate this guide [#how-to-navigate-this-guide]

**If you're just starting**, begin with [Getting Started](/docs/operational-model/getting-started) to assess readiness, identify whether you're acting as a producer or consumer, and choose a practical next step. Understanding [Core Concepts](/docs/operational-model/core-concepts) like *SBOM*, *VEX* and *Vulnerabilities* prevents common mistakes.

**For software producers**, explore [Workflows](/docs/operational-model/workflows) covering SBOM generation and vulnerability disclosure. Start with [Generate SBOMs](/docs/operational-model/workflows/generate-sboms).

**For software consumers**, review the [Supplier Transparency](/docs/operational-model/use-cases/supplier-transparency) and [Vulnerability Management](/docs/operational-model/use-cases/vulnerability-management) use cases, which cover supplier requests, SBOM ingestion, data quality and monitoring.

**For specific problems**, jump directly to [Use Cases](/docs/operational-model/use-cases) covering vulnerability management, supplier transparency, license compliance, release management and regulatory compliance.

**For improving existing practices**, use [Maturity Levels](/docs/operational-model/core-concepts/maturity-levels) and the [Maturity Assessment](/docs/assessments/maturity) to identify the next operational improvements to prioritize.

**For deeper context**, combine [Core Concepts](/docs/operational-model/core-concepts) with the relevant [Use Cases](/docs/operational-model/use-cases) to understand how lifecycle, disclosure, and operational trade-offs apply in practice.

## Relationship to other resources [#relationship-to-other-resources]

This Operational Model complements the [Content Requirements](/docs/content-requirements) which defines required fields and data quality standards, and the [Assessment Tool](/docs/assessments/maturity) which measures your organization's transparency maturity.