Recently Bob Martin and a colleague published the paper “Leveraging SBOMs Throughout the Enterprise SDLC” that examines how enterprises can leverage SBOMs throughout the full Software Development Lifecycle (SDLC) to support risk-informed decision-making, continuous monitoring, operational resilience, and regulatory compliance. Using a hypothetical enterprise named ACME, this paper walks through each SDLC phase—plan, design, implement, test, deploy, and maintain—and demonstrates how SBOM information can be generated, enriched, managed, and operationalized over time.
Practical examples based on SPDX 3.0.1 illustrate how organizations can capture software requirements, provenance, build information, third-party dependencies, licensing data, vulnerability information, and lifecycle relationships in machine-readable form.
The direct link to the pdf is <https://www.mitre.org/sites/default/files/2026-05/PR-25-01520-39-leveraging-sboms_throughout-the-enterprise-sdlc.pdf>