Portal
Compliance
EO 14028 and regulatory compliance verification
Compliance
Portal provides automated compliance verification for EO 14028, FedRAMP, and other regulatory requirements.
EO 14028 Compliance
Executive Order 14028 requires software vendors selling to the US government to provide SBOMs meeting specific criteria.
Automated Verification
Portal automatically validates SBOMs against EO 14028 requirements:
| Requirement | Description | Status |
|---|---|---|
| Minimum Fields | All NTIA minimum fields present | ✅/❌ |
| Component ID | Unique identifiers for all components | ✅/❌ |
| Supplier Info | Vendor/supplier data included | ✅/❌ |
| Version Info | Specific version details | ✅/❌ |
| Dependencies | Relationships defined | ✅/❌ |
| Hash Values | Cryptographic verification | ✅/❌ |
Compliance Score
Each SBOM receives a compliance score:
- 100% - Fully compliant
- 80-99% - Minor gaps
- 50-79% - Significant gaps
- Below 50% - Major remediation needed
Gap Analysis
View specific gaps and remediation steps:
- Open the SBOM
- Navigate to Compliance tab
- View the gap analysis
- Follow remediation guidance
FedRAMP Compliance
For organizations requiring FedRAMP certification:
- FedRAMP HIGH control mapping
- IL7 (Impact Level 7) support
- Continuous monitoring integration
- Control inheritance documentation
NTIA Minimum Elements
The NTIA defines minimum SBOM elements:
| Element | Description |
|---|---|
| Supplier Name | Name of entity that creates/distributes |
| Component Name | Name assigned to the component |
| Version | Version identifier |
| Unique Identifier | PURL, CPE, or other unique ID |
| Dependency Relationship | Upstream/downstream relationships |
| Author | Name of SBOM author |
| Timestamp | Date/time of SBOM generation |
Compliance Reports
Generate audit-ready reports:
- Select SBOMs for reporting
- Choose report type:
- EO 14028 Compliance Report
- NTIA Minimum Elements Report
- Gap Analysis Report
- Full Audit Package
- Export as PDF or Excel
- Include supporting documentation
Automated Remediation
Fix common compliance gaps automatically:
- Add missing supplier information
- Generate unique identifiers
- Complete dependency mapping
- Add required timestamps