Skip to content

Receiving and Using SBOMs

An SBOM Consumer is any organization or individual that receives Software Bills of Materials and uses them to make informed decisions about the software they depend on. As defined by the CISA SBOM Sharing Primer, consumers are the endpoint of the SBOM ecosystem — the ones who turn static component inventory data into actionable intelligence.

Not all SBOM consumers operate the same way. The right starting point depends on your organization’s size, operational model, and regulatory context. Select the type that fits your situation:

SBOMs work alongside other documents like VEX and CSAF to communicate vulnerability status and exploitability. See Connected SBOM Artifacts for how these fit together.