The Escrow Company Software Bill of Materials (SBOM) service offers organizations a comprehensive inventory of all components, libraries, and dependencies contained within software source code, including open-source and third-party elements.
As well as being an important part of modern Supply Chain Security and Vulnerability Management strategies, Governments and regulatory bodies are increasingly mandating or recommending SBOMs as part of broader efforts to strengthen software supply chain security.
An SBOM can be provided on its own, or combined with a Software Escrow or SaaS Escrow agreement to provide additional assurance that software composition is transparently documented for the Beneficiary.
Modern software applications often rely on a combination of proprietary code, open-source libraries, and third-party components.
Understanding what is contained within a software application is becoming increasingly important for software governance, supplier management, due diligence, mergers and acquisitions as well as long-term software supportability.
An SBOM provides transparency into software composition, helping organisations better understand the components that underpin critical software systems within them.
For beneficiaries of Software Escrow and SaaS Escrow agreements, this can provide additional visibility into the software assets upon which they depend.
The Escrow Company SBOM service includes:
The SBOM assessment produces three core deliverables:
Detailed Results
Delivered in JSON format for use by technical teams.
Human-Readable Excel Report
Designed to provide a clear inventory of software components and dependencies.
Executive Summary Report
A high-level summary report provided outlining key findings and observations.
The SBOM service can be applied to:
An SBOM provides a structured inventory of the software components contained within an application.
For beneficiaries, it offers additional visibility into software composition as part of an escrow arrangement. For software vendors, it demonstrates transparency around the components used within their software products.
As software ecosystems continue to grow in complexity, organisations are increasingly seeking greater visibility into the software assets they depend upon and the third-party components that support them.