Software Supply Chain Advisory

Turn software transparency into a strategic advantage

Expert counsel for security, engineering, and product leaders navigating transparency mandates, CycloneDX SBOM adoption, and a rapidly evolving regulatory landscape.

Standards &
Leadership
Chair, OWASP CycloneDX Founder, Ecma International TC54 Chair, OWASP Global Board of Directors Creator, OWASP Dependency-Track Coauthor, OWASP SCVS Coauthor, Package-URL
Why this matters now

Built for leaders who cannot afford to get supply chain wrong

Pressure from every direction

Regulators are writing new rules. Customers are demanding evidence. Attackers are exploiting the gaps. Software supply chain risk is now a board level concern, and the organizations that treat it strategically will pull ahead of those treating it as compliance paperwork.

Standards from the source

I founded the CycloneDX standard, created the OWASP Dependency-Track platform, and founded the Ecma committee that is standardizing the next generation of software transparency. That means your team gets advice grounded not in interpretation of the standards, but in authorship of them.

Senior, selective, focused

Engagements are intentionally senior, selective, and outcome focused. I work with a small number of organizations at a time so each gets substantive attention from the person whose work they are most likely already using.

What I do

Five areas where deep expertise changes the outcome

Each engagement is scoped to your program maturity, timeline, and regulatory posture. Most clients start with a focused assessment and expand from there.

Practice area

Software Bill of Materials (SBOM) and xBOM strategy

Design, implement, and operationalize a production grade Software Bill of Materials (SBOM) program using CycloneDX. Covers generation, quality, distribution, vulnerability and exploitability transparency through Vulnerability Disclosure Reports (VDR) and Vulnerability Exploitability eXchange (VEX), attestations, and expansion into Cryptography Bill of Materials (CBOM), Artificial Intelligence Bill of Materials (AIBOM), Software as a Service Bill of Materials (SaaS-BOM), and Manufacturing Bill of Materials.

Practice area

Regulatory readiness

Map your software supply chain program to the EU Cyber Resilience Act (CRA), U.S. Executive Order 14028, the NIST Secure Software Development Framework (SSDF), U.S. Food and Drug Administration (FDA) premarket cybersecurity guidance, and related mandates. Translate obligations into engineering backlog items rather than legal anxiety.

Practice area

Supply chain hardening

Reduce risk across the software you build and the software you consume. The OWASP Software Component Verification Standard (SCVS) sets the high level requirements calibrated to your risk tolerance, paired with threat modeling for the supply chain, component intelligence, vulnerability prioritization, open source policy, and provenance verification at scale.

Practice area

Executive advisory and training

Board briefings, maturity assessments, and private training for security, product, and engineering leaders. Keynotes and workshops calibrated to your audience, from first time SBOM readers to teams deploying cryptographic transparency.

Practice area

Artificial intelligence in the secure supply chain

Advisory on bringing AI into the same transparency discipline as the rest of the supply chain through the Artificial Intelligence Bill of Materials (AIBOM), and on using agentic AI well for secure code review, design review, threat modeling, and triage. Guidance on secure by default patterns for agentic systems, aligned to the OWASP Top 10 for Large Language Model Applications, the OWASP AI Security Verification Standard (AISVS), the EU AI Act, NIST SP 800-218A, and CRA Annex I.

Authored, not interpreted

Advice from the person writing the standards you will need to comply with

The landscape is shifting on multiple fronts at once:

  • CycloneDX became an international standard (ECMA-424) in 2024.
  • The EU Cyber Resilience Act entered into force in December 2024, with vulnerability reporting due September 11, 2026 and full conformity by December 2027. Its Annex I Part II Software Bill of Materials (SBOM) mandate is satisfied by CycloneDX.
  • The Transparency Exchange API is redefining how that evidence is discovered and shared.
  • U.S. Food and Drug Administration (FDA) guidance is making SBOM a precondition for medical device approval.
  • Post quantum cryptography, the transition to algorithms that resist attack from future quantum computers, is now a stated federal objective.
  • Artificial intelligence regulation is converging fast, with the EU AI Act layering risk based obligations on top of the CRA and NIST SP 800-218A extending the Secure Software Development Framework (SSDF) into generative AI. The CycloneDX Artificial Intelligence Bill of Materials (AIBOM) is how transparency keeps pace.

Every one of those changes started as a working group draft I helped shape. Clients who engage early translate that foresight into roadmap decisions their competitors will be reacting to in eighteen months.

If transparency is the future of software risk, your advisor should be the person who wrote the transparency standard. The engagement thesis
Steve Springett, Chair of OWASP CycloneDX and founder of Ecma International TC54
Steve Springett, Chair of OWASP CycloneDX and founder of Ecma International TC54.
Recent focus

Where clients are spending time in 2026

  • CycloneDX 1.7 adoption and migration from legacy Software Bill of Materials (SBOM) formatsStrategy, tooling
  • EU Cyber Resilience Act conformity assessments and technical documentationRegulatory
  • Cryptography Bill of Materials (CBOM) and post quantum cryptography readiness inventoriesCBOM, post quantum
  • Transparency Exchange API pilots for vendor and customer SBOM distributionStandards
  • Dependency-Track scale out and tuning for large application portfoliosOperational
  • Machine readable attestations to evidence regulatory and contractual software assurance obligationsCompliance
  • Artificial Intelligence Bill of Materials (AIBOM) rollouts for products embedding models, datasets, and agentic tool useAI supply chain
  • Agentic coding workflows applied to secure code review, design review, and threat modeling, with guardrails for review and provenanceAI assisted security
  • Secure by default patterns for agentic systems and Model Context Protocol (MCP) integrations, mapped to OWASP AISVS and the LLM Top 10Agentic AI

Ready to move faster than the regulation cycle?

Short introductory calls are free. Describe your situation and I will tell you honestly whether an engagement makes sense, and if not, where to start.