Compliance Automation
Users can now set custom rules for evaluating their SBOMs and these are automatically re-evaluated each day. If something changes, for example a change in the compliance standard or in the SBOM itself, the change will be reflected in the daily evaluation.
Compliance with industry or customer-defined standards is monitored daily basis with clear visualization of compliance status as well as the reason for failure.
We’re also introducing shared compliance standards to automate compliance validation against key cybersecurity frameworks, so clients can stay audit-ready without costly manual reviews. Beginning with our “Exiger Recommended” baseline, we will expand to support existing and emerging standards, including:
- EO 14028
- NIST Minimum SBOM Requirements
- CISA Minimum SBOM Requirements
- Cyber Resilience Act (CRA)
- Trade Agreements Act (TAA)
- NDAA 889
Expanded Supplier Visibility
Exiger now identifies suppliers at both the SBOM and component levels, providing users a clear picture of who’s behind their software. This expanded visibility exposes FOCI (Foreign Ownership, Control, or Influence) risks — no matter how deeply embedded the supplier’s software component are.
A new geographic visualization shows where suppliers are located globally and helps teams understand where risk is concentrated across their supplier base.
SBOM Version Management and CI/CD
Product teams updating software frequently can produce a large volume of SBOMs as new versions are released. Exiger now enables product development teams to version-manage SBOMs, tracking all iterations in a single interface to improve visibility and traceability across changing versions.
- For automated builds, the platform will create new SBOM versions with each build and provide a pinning feature so teams can select which versions are tracked in inventory.
- We’ve also made it faster and easier to create SBOMs via multiple input options, including drag-and-drop file uploads directly into inventory, accelerating time to analysis.
For each software package in your inventory, every SBOM version is listed along with its history to add clarity and make versions easier to track.
Table of Contents
Get in Touch
Learn how you can build a more resilient software supply chain.