SBOM and VEX consulting
SBOM & VEX Consulting
As an SBOM and VEX consultant, EmberKat helps product teams make component evidence part of release and vulnerability decisions, so it is current, explainable and useful to customers, auditors and engineering.
Discuss the scope↗Service definition
Turn component data into defensible decisions
The work establishes what each release contains, which vulnerabilities matter in the product’s actual use, who makes the decision and what evidence can be shared without turning a document into a false promise.
Scope
Work included in the scope
- 01
SBOM scope, format and release-ownership review
- 02
Dependency inventory and supplier-input assessment
- 03
Vulnerability triage and VEX decision workflow
- 04
Customer evidence, disclosure and sharing boundaries
- 05
CI/CD integration and release-evidence design
- 06
CRA technical-documentation and readiness mapping
Client problems
Use this service when
- 01
A customer asks for an SBOM and nobody owns the answer across releases.
- 02
A vulnerability feed produces alerts without product-context decisions.
- 03
The team cannot reproduce what was shipped in a previous version.
- 04
Security evidence is exported manually and becomes stale immediately.
Deliverables
Documents and decisions provided
- 01
SBOM ownership and release-evidence model
- 02
Component, supplier and vulnerability data-flow map
- 03
VEX decision rules and accountable approval route
- 04
Customer-sharing and disclosure boundaries
- 05
Prioritised implementation plan for product and delivery teams
Common questions
Questions to settle before the work starts
Short answers to the questions that usually determine whether this is the right engagement.
- What is the difference between SBOM and VEX?
- An SBOM says which components are in a release. VEX says whether a known vulnerability in one of those components actually affects the product in its specific configuration and use.
- Does the CRA require publishing an SBOM to every customer?
- The product team needs an SBOM as part of its technical documentation and vulnerability handling. Whether a customer receives it is a separate evidence-sharing decision, not an automatic instruction to publish it publicly.
- Can SBOM and VEX consulting work with our existing tools?
- Usually. The review starts with the current source, build, dependency and vulnerability data paths, then defines the minimum control and ownership changes needed before recommending new tooling.
From the glossary
- CI/CDcontinuous integration and continuous delivery
- The automated pipeline that builds, tests and releases software every time it changes.
- SBOMSoftware Bill of Materials
- A list of every component inside a piece of software — an ingredients label, in a form a machine can read.
- CRACyber Resilience Act, Regulation (EU) 2024/2847
- An EU law that puts security requirements on the product itself — effectively anything containing software that is sold in the EU.
- VEXVulnerability Exploitability eXchange
- A statement of whether a known flaw in a component actually affects your product.
Related engagement
Cyber Resilience Act Consulting
Connect SBOM, VEX and vulnerability handling to the broader CRA product-security lifecycle.
View engagement↗