Manage SBOM Requirements
Assign owners, track progress and document how applicable CERT-In requirements and practices are implemented.
Cybersecurity / India & South Asia
Strengthen software supply-chain visibility.
Section 1 — About CERT-In SBOM
The Indian Computer Emergency Response Team (CERT-In) has issued technical guidelines for Software Bill of Materials (SBOM) to improve transparency and security across the software supply chain.
The current Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM Version 2.0 encourage organizations-particularly government entities, essential services, public-sector organizations, and software and IT service providers in India—to make SBOM creation and availability part of software development and procurement practices.
An SBOM provides visibility into software components and dependencies, helping organizations strengthen vulnerability management, supply-chain security, compliance and incident response.
Section 2 — CERT-In SBOM with Controllo
Controllo helps teams manage CERT-In SBOM-related governance, risks, controls and supporting documentation from one connected workspace.
Assign owners, track progress and document how applicable CERT-In requirements and practices are implemented.
Maintain vendor, asset and organizational risks alongside relevant software supply-chain controls.
Organize policies, procedures and supporting evidence against applicable requirements with clear traceability.
Track third-party risks and maintain visibility into suppliers supporting critical software and services.
Connect AWS, Azure and GCP to bring cloud assets, configurations and relevant security signals into the wider security program.
Analyze implementation descriptions, policies and evidence to identify potential gaps and receive detailed recommendations in seconds.
Highlight
Section 3 — Why Controllo for CERT-In SBOM?
Manage CERT-In requirements within the same GRC platform used for other Indian and global frameworks.
Connect vendor and software-related risks with relevant requirements.
Keep governance documents and supporting evidence connected and review-ready.
Use Secura AI to identify incomplete implementation or documentation before assessment.
Manage CERT-In requirements, supply-chain risk and evidence from one connected GRC platform.