End-to-End Compliance Workflow¶
This section shows how a vulnerability travels through the platform, from discovery in a scanned SBOM to a fully documented resolution. Later sections explain each step in detail.
Note
SBOM Upload → Automated Vulnerability Scan → Vulnerability Queue (Triage) → Notification Sent to Vendor and/or Customer → Acknowledgment → VEX Request / Response → Fix Confirmed
Who does what, at each stage¶
1. SBOM submission and scanning¶
A vendor uploads an SBOM for a product assigned to them, or an organization uploads one directly. The moment a file is uploaded, SBOM360 automatically scans it for known vulnerabilities and calculates a component and severity breakdown. Scan status moves from Pending to Scanning to Completed (or Failed).
2. Vulnerability triage¶
Every vulnerability discovered across every linked SBOM appears in the organization's Vulnerability Queue, sorted with critical and unreviewed issues first. The security team reviews CVSS score, EPSS exploit probability, and CISA Known Exploited Vulnerabilities (KEV) status, then marks each item as reviewed, escalated, or leaves it unreviewed.
3. Notification¶
When a vulnerability requires disclosure, the organization sends a notification to the affected vendor, the affected customers, or both. The platform automatically determines which customers are affected based on their registered deployments. Once sent, the notification is tracked through its workflow steps until the recipient acknowledges it.
4. VEX exchange¶
Vendors and customers can request or submit a VEX (Vulnerability Exploitability eXchange) statement at any point, declaring officially whether a product is Affected, Not Affected, Fixed, or Under Investigation. This closes the loop between what a customer's scanner detects and the vendor or organization's official assessment.
5. Resolution and documentation¶
As fixes are applied, notifications are marked Patched and VEX statements are updated to Fixed. All actions are logged for audit purposes.
Tip
At every stage, each portal's dashboard tells you exactly what — if anything — you need to do next. There is no need to guess where a vulnerability or notification stands.