Free Tool

SBOM Policy Template
one signed document for scope, generation, signing, VEX, inbound vendor SBOMs, retention, and framework crosswalk

A free, copy-ready software bill of materials (SBOM) policy template. Twelve structured sections covering policy purpose and authority, outbound SBOM generation in CycloneDX 1.5 or SPDX 2.3 with NTIA Minimum Elements coverage, component depth and accuracy, signing and SLSA provenance with Sigstore Cosign and in-toto, publication and customer delivery channels, inbound third-party SBOM acceptance and ingestion, vulnerability matching and VEX (CSAF or CycloneDX VEX) publication policy, roles and RACI, retention and disposal per product class, framework crosswalk for NIST SSDF, CISA Self-Attestation, Executive Order 14028, EU Cyber Resilience Act, NIS2, DORA, FDA pre-market, and FAR/DFARS, governance and exception path, and document control with signed approval. Built for internal AppSec, product security, supply chain security, GRC, and CISO programmes that need a defensible policy artefact the procurement reviewer, the regulator, the build engineer, and the vulnerability manager all read on the same document.

No credit card required. Free plan available forever.

Loading tool...

Run the SBOM policy against the live component record, not against a separate spreadsheet

SecPortal carries every SBOM-derived finding, every inbound vendor SBOM import, every VEX status decision, and every retention disposition on one workspace so the policy commitments and the audit read are the same record. Free plan available.

No credit card required. Free plan available forever.