Safeguard Documentation Center
Third Party Risk Manager

SBOM Requests

Request and collect SBOMs from your software vendors

SBOM Requests

Streamline the process of requesting, collecting, and validating SBOMs from your third-party software vendors.

Creating Requests

Single Request

  1. Navigate to the vendor
  2. Click Request SBOM
  3. Select the product(s)
  4. Choose request template
  5. Customize message (optional)
  6. Set deadline
  7. Click Send

Bulk Requests

Request SBOMs from multiple vendors:

  1. Go to Vendors
  2. Select vendors to contact
  3. Click Bulk Request
  4. Configure request settings
  5. Review and send

Request Templates

Standard Template

Default request including:

  • SBOM format requirements (SPDX, CycloneDX)
  • Required fields (EO 14028 compliance)
  • Submission instructions
  • Deadline information

Custom Templates

Create templates for specific needs:

  1. Go to SettingsRequest Templates
  2. Click Create Template
  3. Customize content
  4. Save for reuse

Request Tracking

Monitor request status:

StatusDescription
SentRequest delivered
ViewedRecipient opened email
In ProgressVendor acknowledged
SubmittedSBOM received
ValidatedSBOM verified
RejectedSubmission rejected

Automated Follow-ups

Configure automatic reminders:

  • First reminder: 7 days before deadline
  • Second reminder: At deadline
  • Escalation: 7 days after deadline

Submission Portal

Vendors can submit via:

  • Email attachment
  • Secure upload portal
  • API submission
  • Direct integration

Validation

When an SBOM is received:

  1. Format validation (valid SPDX/CycloneDX)
  2. Completeness check (required fields)
  3. Compliance verification (EO 14028)
  4. Automatic vulnerability scan
  5. Notification to requestor

Rejection Workflow

If an SBOM doesn't meet requirements:

  1. Review validation failures
  2. Click Request Revision
  3. Specify needed corrections
  4. Vendor receives update request

On this page