We had a vendor security review today and they asked one question that caught us off guard:
“Can you share the SBOM for your application?”
We do vulnerability scans, and we track dependencies in Continuous Integration, but we’ve never actually produced an SBOM as a deliverable.
What exactly counts as an SBOM, and what are people expecting when they ask for it?