SBOM Monitoring Checklist
Use this checklist to review SBOM completeness, component changes, vulnerability status, and follow-up actions for a software asset.
SBOM Asset Identification
Target Software or Product Name
*
Application or Service Identifier
*
Owner or Team
*
Environment
*
Please Select
Production
Staging
Development
Testing
Other
Vendor or Supplier Name
Current Software Version or Build
*
SBOM Source Type
*
Please Select
Uploaded file
Generated from tool
Third-party provided
Manual record
SBOM Version or Date Reviewed
*
 -
Month
 -
Day
Year
Date
Attach SBOM Document
Upload a File
Drag and drop files here
Choose a file
Cancel
of
SBOM Monitoring Checklist
SBOM review checklist
*
Rows
Reviewed
Status
Completeness of component inventory
1
2
Direct dependencies present
3
4
Transitive dependencies present
5
6
Package names and versions verified
7
8
License data reviewed if relevant
9
10
Component ownership identified
11
12
Known vulnerabilities checked
13
14
Dependency drift assessed
15
16
Newly introduced components reviewed
17
18
Removed components reviewed
19
20
Overall SBOM freshness
*
1
2
3
4
5
Confidence in data quality
*
Low
1
2
3
4
5
6
7
8
9
High
10
1 is Low, 10 is High
Risk level
*
Low
1
2
3
4
5
6
7
8
9
High
10
1 is Low, 10 is High
Monitoring triggers
*
New release
Scheduled review
Vulnerability alert
Supplier update
Dependency change
Incident response
Ad hoc audit
Findings and notes
Reviewer action needed
Please Select
No action required
Monitor closely
Update SBOM
Escalate to owner
Blocked pending review
Review Timing and Follow-up
Review Date
*
 -
Month
 -
Day
Year
Date
Next Scheduled Review Date
*
 -
Month
 -
Day
Year
Date
Remediation Deadline
 -
Month
 -
Day
Year
Date
Follow-up Owner
*
First Name
Middle Name
Last Name
Corrective Actions / Notes
Escalation Needed
Yes
No
Supporting Evidence / Export
Upload a File
Drag and drop files here
Choose a file
Cancel
of
Submit Checklist
Should be Empty: