SBOM licence disposition checklist
A reusable review checklist for component normalisation, allow/deny/needs-review states and provenance-backed handoff.
How to use it
Copy, assign owners, then attach real evidence.
A checklist is useful only if each item has an owner and a verifiable state. Do not mark an item complete because a tool returned a green badge.
- [ ] SBOM format/version validated - [ ] Component identity normalised - [ ] Licence expression parsed where available - [ ] Allow/deny/needs-review policy applied - [ ] Human dispositions recorded for ambiguous components - [ ] Input/tool provenance included in final evidence pack
Checklist
What complete should mean.
SBOM format/version validated
Component identity normalised
Licence expression parsed where available
Allow/deny/needs-review policy applied
Human dispositions recorded for ambiguous components
Input/tool provenance included in final evidence pack
Primary / official source basis
Keep the checklist tied to the current source.
Reviewed 2026-08-31. Source owner: SPDX / OWASP CycloneDX.
The template is an operating aid, not certification.
Use the checklist to structure evidence, ownership and review. It does not replace the authoritative system, regulator, specialist audit, legal advice or professional judgement that may apply to the underlying job.
- Not a legal opinion or licence clearance
- Not a vulnerability scanner or CVE-coverage claim
- No arbitrary remote clone/build, uploaded-code execution or CRA certification