EmberKat

SBOM and VEX consulting

SBOM & VEX Consulting

As an SBOM and VEX consultant, EmberKat helps product teams make component evidence part of release and vulnerability decisions, so it is current, explainable and useful to customers, auditors and engineering.

Discuss the scope
Typical durationUsually 2–4 weeks
Starting priceFrom €12,500 excl. VAT
Commercial basisWritten scope and proposal

Service definition

Turn component data into defensible decisions

The work establishes what each release contains, which vulnerabilities matter in the product’s actual use, who makes the decision and what evidence can be shared without turning a document into a false promise.

Scope

Work included in the scope

  1. 01

    SBOM scope, format and release-ownership review

  2. 02

    Dependency inventory and supplier-input assessment

  3. 03

    Vulnerability triage and VEX decision workflow

  4. 04

    Customer evidence, disclosure and sharing boundaries

  5. 05

    CI/CD integration and release-evidence design

  6. 06

    CRA technical-documentation and readiness mapping

Client problems

Use this service when

  1. 01

    A customer asks for an SBOM and nobody owns the answer across releases.

  2. 02

    A vulnerability feed produces alerts without product-context decisions.

  3. 03

    The team cannot reproduce what was shipped in a previous version.

  4. 04

    Security evidence is exported manually and becomes stale immediately.

Deliverables

Documents and decisions provided

  1. 01

    SBOM ownership and release-evidence model

  2. 02

    Component, supplier and vulnerability data-flow map

  3. 03

    VEX decision rules and accountable approval route

  4. 04

    Customer-sharing and disclosure boundaries

  5. 05

    Prioritised implementation plan for product and delivery teams

Common questions

Questions to settle before the work starts

Short answers to the questions that usually determine whether this is the right engagement.

What is the difference between SBOM and VEX?
An SBOM says which components are in a release. VEX says whether a known vulnerability in one of those components actually affects the product in its specific configuration and use.
Does the CRA require publishing an SBOM to every customer?
The product team needs an SBOM as part of its technical documentation and vulnerability handling. Whether a customer receives it is a separate evidence-sharing decision, not an automatic instruction to publish it publicly.
Can SBOM and VEX consulting work with our existing tools?
Usually. The review starts with the current source, build, dependency and vulnerability data paths, then defines the minimum control and ownership changes needed before recommending new tooling.

From the glossary

CI/CDcontinuous integration and continuous delivery
The automated pipeline that builds, tests and releases software every time it changes.
SBOMSoftware Bill of Materials
A list of every component inside a piece of software — an ingredients label, in a form a machine can read.
CRACyber Resilience Act, Regulation (EU) 2024/2847
An EU law that puts security requirements on the product itself — effectively anything containing software that is sold in the EU.
VEXVulnerability Exploitability eXchange
A statement of whether a known flaw in a component actually affects your product.
The full glossary

Related engagement

Cyber Resilience Act Consulting

Connect SBOM, VEX and vulnerability handling to the broader CRA product-security lifecycle.

View engagement