Skip to main content
Image coming soon

Reference of choice on SBOM governance calls across your ecosystem

$199.00
Adding to cart… The item has been added

A tailored course, built for your situation

Reference of choice on SBOM governance calls across your ecosystem

Become the named authority peers turn to when software supply chain decisions need grounding

$199 one-time
24-hour access provisioning 30-day money-back guarantee Hand-built implementation playbook
12 modules. 12 chapters per module. 144 chapters total.
12 modules, each with 12 chapters (144 chapters total), text-based, plus downloadable templates and a hand-built implementation playbook delivered alongside course access.

Who this is for

Senior technical practitioner influencing software supply chain governance through toolchain design and policy implementation

Who this is not for

This is not for junior analysts, entry-level compliance staff, or those without influence over software delivery or security tooling decisions.

What you walk away with

  • Named reference in cross-organizational SBOM discussions
  • Artefacts and narratives adopted by peers without modification
  • Confident, source-backed responses to vendor and partner challenges
  • Repeatable SBOM structuring that becomes team standard
  • Visibility in ecosystem conversations beyond your immediate team

The 12 modules (with all 144 chapters)

Module 1. SBOM as organisational currency
Understand how SBOMs are shifting from compliance artifacts to strategic coordination tools across product, security, and legal teams. Learn to position SBOM work as foundational to trust and interoperability.
12 chapters in this module
  1. Defining SBOM beyond compliance
  2. Mapping stakeholders by dependency
  3. Identifying decision leverage points
  4. Aligning with software delivery rhythm
  5. Linking to incident response
  6. Connecting to vendor onboarding
  7. Tracking ecosystem adoption signals
  8. Benchmarking internal maturity
  9. Setting expectations with engineering
  10. Documenting scope boundaries
  11. Establishing feedback loops
  12. Versioning policy basics
Module 2. Composing canonical SBOM structure
Build consistently structured SBOMs that serve multiple audiences , from developers to legal reviewers , without rework. Use templates grounded in real-world toolchain constraints.
12 chapters in this module
  1. Choosing between SPDX and CycloneDX
  2. Normalising component naming
  3. Handling dynamic dependencies
  4. Including provenance metadata
  5. Excluding irrelevant components
  6. Versioning component references
  7. Adding relationship clarity
  8. Documenting toolchain source
  9. Adding licensing annotations
  10. Structuring for automation
  11. Optimising file size and parse speed
  12. Validating schema conformance
Module 3. Generating SBOMs with accuracy
Integrate SBOM generation into CI/CD pipelines using tooling-agnostic patterns. Ensure completeness and correctness without slowing delivery velocity.
12 chapters in this module
  1. Identifying generation triggers
  2. Capturing build-time context
  3. Scanning container layers
  4. Analyzing package managers
  5. Detecting transitive dependencies
  6. Integrating SCA output
  7. Validating against runtime profiles
  8. Automating format conversion
  9. Signing SBOM artefacts
  10. Storing with build artifacts
  11. Version linking to releases
  12. Handling ephemeral builds
Module 4. Validating SBOM completeness
Apply a checklist-driven approach to verify SBOM quality before sharing externally. Reduce friction in audits and partner reviews with higher first-time acceptance.
12 chapters in this module
  1. Checking required fields
  2. Confirming component hierarchy
  3. Validating SPDX ID uniqueness
  4. Cross-referencing build logs
  5. Matching runtime inventory
  6. Reviewing license accuracy
  7. Auditing dependency depth
  8. Checking for obfuscation
  9. Verifying timestamp integrity
  10. Ensuring human readability
  11. Testing machine parseability
  12. Documenting exceptions
Module 5. Communicating SBOM value to legal
Frame SBOM content in terms legal teams rely on , licensing obligations, indemnification risks, and third-party compliance. Bridge technical detail with contractual clarity.
12 chapters in this module
  1. Mapping components to license types
  2. Highlighting copyleft risks
  3. Summarising obligations clearly
  4. Identifying attribution requirements
  5. Documenting license compatibility
  6. Flagging unapproved licenses
  7. Creating legal executive summaries
  8. Linking to vendor contracts
  9. Responding to audit requests
  10. Updating policy in response to change
  11. Archiving for future reference
  12. Training legal on key fields
Module 6. Securing SBOM integrity
Implement tamper-proofing and access controls that make SBOMs trustworthy. Use cryptographic signatures and access logging to establish chain of custody.
12 chapters in this module
  1. Signing with digital certificates
  2. Choosing signature scope
  3. Using cosign for attestations
  4. Verifying signature authenticity
  5. Logging access attempts
  6. Controlling distribution channels
  7. Encrypting sensitive metadata
  8. Auditing changes over time
  9. Integrating with PKI
  10. Documenting revocation process
  11. Storing in immutable storage
  12. Monitoring for anomalies
Module 7. Integrating SBOM into incident response
Enable faster vulnerability triage by linking SBOMs to threat intelligence and runtime telemetry. Make SBOMs actionable during security events.
12 chapters in this module
  1. Linking CVEs to components
  2. Prioritising by exploit likelihood
  3. Mapping SBOM to asset inventory
  4. Automating impact assessment
  5. Sharing with SOC teams
  6. Updating during patch cycles
  7. Documenting response rationale
  8. Creating runbooks for reuse
  9. Archiving for post-event review
  10. Improving future accuracy
  11. Validating fix completeness
  12. Reporting resolution status
Module 8. Governance model design for SBOM
Define ownership, update cadence, and review cycles that keep SBOMs accurate and authoritative. Establish lightweight governance that scales.
12 chapters in this module
  1. Assigning stewardship roles
  2. Setting update frequency
  3. Defining approval workflows
  4. Creating versioning rules
  5. Establishing quality gates
  6. Documenting change rationale
  7. Reviewing with cross-functional leads
  8. Auditing governance adherence
  9. Measuring improvement over time
  10. Adjusting for scale
  11. Publishing governance charter
  12. Training new contributors
Module 9. Vendor SBOM exchange standards
Navigate the landscape of incoming and outgoing SBOMs from partners. Apply consistent evaluation criteria to vendor-provided data.
12 chapters in this module
  1. Requesting SBOM at procurement
  2. Validating third-party SBOMs
  3. Assessing completeness gaps
  4. Responding to format mismatches
  5. Negotiating quality improvements
  6. Documenting acceptance criteria
  7. Archiving vendor submissions
  8. Tracking supplier progress
  9. Using SBOM in due diligence
  10. Providing feedback loops
  11. Standardising templates
  12. Automating ingestion
Module 10. Toolchain interoperability patterns
Design SBOM integrations that work across different SCA tools, CI systems, and repositories. Avoid vendor lock-in with portable patterns.
12 chapters in this module
  1. Normalising output formats
  2. Creating transformation pipelines
  3. Validating across tools
  4. Handling schema drift
  5. Using middleware layers
  6. Building compatibility tables
  7. Testing across environments
  8. Documenting known issues
  9. Sharing best practices
  10. Optimising for scale
  11. Reducing conversion overhead
  12. Standardising naming
Module 11. Building team-wide SBOM fluency
Equip engineers and product managers to create and use SBOMs without central oversight. Scale accuracy through education and tooling.
12 chapters in this module
  1. Creating onboarding materials
  2. Running hands-on workshops
  3. Developing internal documentation
  4. Providing templates
  5. Offering review support
  6. Celebrating improvements
  7. Publishing common mistakes
  8. Gamifying accuracy
  9. Sharing success stories
  10. Gathering feedback
  11. Iterating on resources
  12. Measuring fluency growth
Module 12. Establishing recognised practice
Position your approach as the model others follow. Create shareable artefacts, public references, and documented patterns that elevate your influence.
12 chapters in this module
  1. Publishing internal playbooks
  2. Presenting at cross-team forums
  3. Writing case studies
  4. Sharing templates externally
  5. Contributing to open standards
  6. Engaging with working groups
  7. Mentoring peers
  8. Responding to ecosystem queries
  9. Tracking citations
  10. Updating for new regulations
  11. Maintaining version history
  12. Archiving deprecated versions

How this maps to your situation

  • Preparing for external audit or certification
  • Rolling out new toolchain integration
  • Responding to vendor due diligence request
  • Leading internal software transparency initiative

Before vs. after

Before
SBOMs are generated inconsistently, reviewed reactively, and treated as compliance overhead.
After
Your SBOMs are proactively structured, widely trusted, and routinely cited by peers across teams and partners.

What's included with your purchase

  • 12 modules with 12 chapters each (144 chapters)
  • Downloadable templates and worked examples for every module
  • Hand-built implementation playbook delivered alongside course access
  • 30-day money-back guarantee

Delivery and format

  • Course and learning environment access provisioned within 24 hours of purchase
  • Hand-built implementation playbook delivered alongside course access

Format: Text-based modules and chapters in the Art of Service learning environment, plus downloadable templates and worked examples for every chapter, plus the hand-built implementation playbook delivered alongside course access.

Time investment: Approximately 3-4 hours per module, designed for integration into real-world work over 6-8 weeks.

If nothing changes
Without sharpening SBOM practice, efforts remain siloed, artefacts lack authority, and influence defaults to others.

How this compares to the alternatives

Unlike generic security certifications or tool-specific trainings, this course focuses on the cross-cutting governance and influence patterns that make SBOM work stick and scale across organisations.

Frequently asked

Is this course specific to a particular SBOM format?
No. We cover both SPDX and CycloneDX, with pattern-based guidance that applies across formats and tools.
How is the course structured?
12 modules, each containing 12 chapters (144 chapters total).
Will this help me if my team doesn’t use SBOMs yet?
Yes. The course includes strategies for initiating and socialising SBOM practices, even in low-readiness environments.
$199 one-time. Approximately 3-4 hours per module, designed for integration into real-world work over 6-8 weeks..

Within 24 hours your account in the learning environment is provisioned and the tailored implementation playbook is delivered alongside it.

30-day money-back guarantee· 144 chapters· Hand-built playbook included· Account access within 24 hours