Skip to content
Release: Australia · Updated: 2026-05-12 · Official documentation · View source

Activate SBOM support

Install the required applications and verify prerequisites to enable SBOM collection in Third-party Risk Management (TPRM).

Before you begin

  • Verify that the Smart Assessment Engine is enabled. SBOM collection is not supported for Classic assessments.
  • Check your entitlements to determine whether you have access to this application and all associated ServiceNow Store applications. For more information, see Get entitlement for a ServiceNow product or application.

Role required: admin

About this task

An SBOM (Software Bill of Materials) is a structured inventory of the software components in a product. In TPRM, SBOM collection is performed through engagement-level external assessments using the Smart Assessment Engine. Installing the core SBOM applications makes the required data structures and processing capabilities available in your instance. Installing the optional vulnerability response applications adds vulnerability context for individual SBOM components.

Procedure

  1. Navigate to All > System Applications > All Available Applications > All.

  2. Install the required SBOM applications.

    Find each application using the filter criteria and search bar, then select Install for each one.

    ApplicationID
    SBOM Coresn_sbom_core
    Data Model for SBOMsn_sbom_dm

    Core SBOM data structures and processing capabilities are available in the instance.

  3. Install the optional vulnerability response applications if you require vulnerability insights for SBOM components.

    Find each application using the filter criteria and search bar, then select Install for each one.

    ApplicationID
    SBOM Responsesn_sbom_resp
    Vulnerability Responsesn_vul

    Note: These applications enable vulnerability context for SBOM components but are not required to collect SBOM files.

  4. Verify that SBOM fields and related lists are available on an engagement record.

    1. Navigate to the Vendor Management Workspace using one of the following methods:

      • Select Workspaces > Vendor Management Workspace.
      • Navigate to All > Third-party Risk Management > Vendor Management Workspace.
        1. Open an engagement record.
    2. Confirm that the SBOM required field is visible on the engagement record, and that the SBOM document related list appears on the engagement.

    The instance is ready to collect SBOM information through engagement-level external assessments.

What to do next

After installing SBOM support, you can request an SBOM from a third party through an engagement-level external assessment. For next steps, see Request a software bill of materials from an engagement.

Related topics

Exploring software bill of materials collection

Collecting software bill of materials

Request a software bill of materials from an engagement

Review an SBOM submission from an engagement

SBOM records and relationships in Third-party Risk Management