Deterministic Consent Gate: analytics remain disabled until explicit opt-in. No third-party trackers are loaded.

Capability Specification

Automated software bill-of-materials (SBOM) generation

Supply Chain Security Scanning

Automated software bill-of-materials (SBOM) generation defines a core capability outcome delivered by Supply Chain Security Scanning, including implementation intent and execution coverage.

NIS2DORA

Purpose

Translate Supply Chain Security Scanning intent into a concrete capability stream that can be executed, measured, and accepted by the delivery team.

Scope Context

Dependency intelligence pipeline with policy gates for release readiness.

Inputs

- Current-state architecture and operating model

- Approved bundle scope and target compliance obligations

- Delivery constraints, timeline, and responsible owners

Outputs

- Implemented capability increment with ownership mapping

- Execution notes and evidence pointers for review

- Operational handover requirements for production use

Acceptance Criteria

- Capability can be demonstrated in a controlled walkthrough

- Owner, scope, and change boundaries are explicit

- Linked controls and evidence references are complete

Compliance Evidence Notes

- [NIS2] Capability execution mapped in Supply Chain Security Scanning control evidence

- [DORA] Capability execution mapped in Supply Chain Security Scanning control evidence

Specification Schema

Owner Role

Capability Stream Owner

Approval Sign-Off

Product owner and platform lead

Versioning Policy

Revisioned per release with backward-compatibility notes

Review Cadence

Sprint review and monthly capability maturity checkpoint

Evidence Retention

Operational evidence retained for at least 12 months

Required Sections

- Capability objective and intended business outcome

- Technical scope and dependency matrix

- Implementation steps and ownership mapping

- Validation checklist and acceptance evidence

- Operational handover and support model