---
sourceDocument: Australia Governance, Risk, and Compliance
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/governance-risk-compliance

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Governance, Risk, and Compliance

ft:clusterId :

    - grc

bundleId :

    - grc

workflow :

    - Technology


---

# Activate SBOM

# Activate SBOM support {#ariaid-title1}

* Release version: Australia
* 
* Updated May 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Install the required applications and verify prerequisites to enable SBOM collection in Third-party Risk Management (TPRM).

## Before you begin

* Verify that the Smart Assessment Engine is enabled. SBOM collection is not supported for Classic assessments.
* Check your entitlements to determine whether you have access to this application and all associated ServiceNow Store applications. For more information, see [Get entitlement for a ServiceNow product or application](https://store.servicenow.com/$appstore.do#!/store/help?article=KB0030186).

{#sbom-activate__ul_xsy_l4t_fjc}

Role required: admin

## About this task

An SBOM (Software Bill of Materials) is a structured inventory of the software components in a product. In TPRM, SBOM collection is performed through engagement-level external assessments using the Smart Assessment Engine. Installing the core SBOM applications makes the required data structures and processing capabilities available in your instance. Installing the optional vulnerability response
applications adds vulnerability context for individual SBOM components.{#sbom-activate__sbom-activate-context-1}

## Procedure

1. Navigate to AllSystem ApplicationsAll Available ApplicationsAll. {#sbom-activate__sbom-activate-step-nav}
{#sbom-activate__sbom-activate-step-nav}
2. Install the required SBOM applications.  
   Find each application using the filter criteria and search bar, then select Install for each one.
   {#sbom-activate__table_aty_l4t_fjc__entry__2}

   | Application | ID |
   |-|-|
   | SBOM Core | `sn_sbom_core` |
   | Data Model for SBOM | `sn_sbom_dm` |
   [Table 1. Required SBOM applications]

   {#sbom-activate__table_aty_l4t_fjc}  
   Core SBOM data structures and processing capabilities are available in the instance. {#sbom-activate__sbom-activate-step-core}
{#sbom-activate__sbom-activate-step-core}
3. **Optional:** Install the optional vulnerability response applications if you require vulnerability insights for SBOM components.  
   Find each application using the filter criteria and search bar, then select Install for each one.
   {#sbom-activate__table_bty_l4t_fjc__entry__2}

   | Application | ID |
   |-|-|
   | SBOM Response | `sn_sbom_resp` |
   | Vulnerability Response | `sn_vul` |
   [Table 2. Optional SBOM vulnerability response applications]

   {#sbom-activate__table_bty_l4t_fjc}  
   Note:  
   These applications enable vulnerability context for SBOM components but are not required to collect SBOM files. {#sbom-activate__sbom-activate-step-optional}
{#sbom-activate__sbom-activate-step-optional}
4. Verify that SBOM fields and related lists are available on an engagement record.
   1. Navigate to the Vendor Management Workspace using one of the following methods:  
      * Select WorkspacesVendor Management Workspace.
      * Navigate to AllThird-party Risk ManagementVendor Management Workspace.
      {#sbom-activate__ul_dty_l4t_fjc}
   2. Open an engagement record.
   3. Confirm that the SBOM required field is visible on the engagement record, and that the SBOM document related list appears on the engagement.

   {#sbom-activate__substeps_cty_l4t_fjc}  
   The instance is ready to collect SBOM information through engagement-level external assessments. {#sbom-activate__sbom-activate-step-verify}
{#sbom-activate__sbom-activate-step-verify}{#sbom-activate__steps_zsy_l4t_fjc}

## What to do next

After installing SBOM support, you can request an SBOM from a third party through an engagement-level external assessment. For next steps, see [Request a software bill of materials from an engagement](https://servicenow-prod.fluidtopics.net/m2u04m24uAeK0oZbM8hAKw "Turn on SBOM collection on a due diligence request and send the external assessment to collect SBOM data from an engagement contact.").
**Related concepts**   

* [Exploring software bill of materials collection](https://servicenow-prod.fluidtopics.net/D5HKQ8~8LGj40YZyW_mXww "Third-party Risk Management (TPRM) collects software bill of materials (SBOM) files through engagement-level due diligence. This topic covers the users and workflow involved.")
* [Collecting software bill of materials](https://servicenow-prod.fluidtopics.net/tKBQ5MvyeX~S5Dq2WfvExQ "A software bill of materials provides an inventory of the components, libraries, and dependencies included in a vendor's software. Third-party Risk Management (TPRM) supports collecting SBOM files as part of the due diligence process.")  
**Related tasks**   

* [Request a software bill of materials from an engagement](https://servicenow-prod.fluidtopics.net/m2u04m24uAeK0oZbM8hAKw "Turn on SBOM collection on a due diligence request and send the external assessment to collect SBOM data from an engagement contact.")
* [Review an SBOM submission from an engagement](https://servicenow-prod.fluidtopics.net/jG3yj_LCt3V0evQEVR89Yg "Track processing status and review the outcome of a SBOM submission from an engagement, including successful upload, failed upload, and decline.")  
**Related reference**   

* [SBOM records and relationships in Third-party Risk Management](https://servicenow-prod.fluidtopics.net/9ycIyON5lxlYjnJWbhXaKQ "The records, related lists, and relationships created when you collect SBOM data in Third-party Risk Management, and how those records relate to engagements and third parties.")

*[\>]: and then


