Docs Standards and Compliance SLSA SBOM
SLSA SBOM position
Stefan Coetzee created 2026-05-12 updated 2026-05-12 1 min read position
Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.
SLSA + SBOM Position
What they do well
Concrete supply-chain integrity — moving beyond vague "supply chain security."Tooling ecosystem mature for major build systems.Regulatory alignment — CRA, NIS2, EO 14028, CMMC all reference.SLSA levels progression supports incremental adoption.SBOM formats stable (SPDX, CycloneDX).
What they do poorly
Operational adoption gap — SBOM generation widespread, SBOM consumption / use less mature.AI / ML-SBOM emerging — model + training data + dependencies; current SBOM formats incomplete.Open-source maintainer burden — supply-chain pressure shifts to maintainers.Multi-format friction — SPDX vs CycloneDX.Vulnerability matching to SBOM components imperfect.
Evidence
US federal SBOM mandate via EO 14028. EU CRA component identification requirements approaching. Major build platforms (GitHub, GitLab, CircleCI) supporting SLSA provenance. Industry SBOM adoption rapid.
Personal calibration
For client SDLC engagements: SLSA + SBOM emerging baseline. For AI features: ML-SBOM concept worth tracking but operational tooling limited.
See also
position slsa-sbom
Linked from