Stay compliant with regulations and ahead of industry trends. Manage your Software Bill of Materials (SBOM) effortlessly across your entire software portfolio.
Secure Your Software Supply Chain: Manage Risk, Compliance, and Regulations
With more than 90% of companies using open source software (OSS), protecting your software supply chain is critical to mitigating security, legal, and quality risks to your business. Make safer open source choices across the software development life cycle (SDLC), and innovate fearlessly with less risk.
We're bringing Sonatype's best-in-class component scanning and vulnerability data together with market-leading SBOM management support to provide procurement, regulations compliance, and security teams with the tools they need to manage SBOMs for their software and the SBOMs they receive for their third-party software.
Comprehensive SBOM management and compliance at scale enhances your overall security posture, enabling you to stay ahead of evolving cybersecurity threats:
Generate, unify, and distribute accurate SBOMs (Software Bill of Materials) in CycloneDX and SPDX formats from a centralized platform.
Streamline risk prioritization and compliance management, addressing security, audit, and regulatory requirements efficiently.
Get started today with Sonatype SBOM Manager!
As the industry-leading software supply chain management platform, the Sonatype Platform is the choice of organizations currently using or evaluating solutions such as Mend, Jfrog, Snyk, or GitLab. Sonatype provides a comprehensive and integrated solution for all aspects of the software development lifecycle, from secure development to release automation, helping organizations reduce risk and accelerate their time to market.
Highlights
Simplify compliance, identify critical risks, and guide vendor negotiations with third party software audit through SBOM Managers smart and scalable database.
Meet regulation and compliance standards by sharing SBOMs at scale with automated VEX information and keep your customers and regulators up to date.
Automatically monitor first party and third party SBOMs for new security vulnerability and malware risks and respond quickly powered by Sonatypes industry leading component intelligence.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
This listing offers one pricing dimension for the SaaS version of Sonatype SBOM Manager. You buy under a contract, and the unit covers 500 SBOMs (software bills of materials). Pricing scales by the volume of SBOMs you need to manage, so you select capacity based on how many SBOMs your organization tracks. There are no separate tiers or instance sizes to compare. You commit to the contract term and the SBOM quantity it covers, giving you a single, capacity-based option to plan against.
Top-of-mind questions for buyers
What counts as one SBOM for billing purposes?
An SBOM is a software bill of materials, a detailed inventory of components in a software application. The unit covers 500 of these records. You can ingest SBOMs in both CycloneDX and SPDX formats, from internal and third-party sources, including AI model bills of materials.
What happens if I need to manage more than 500 SBOMs?
The unit is priced in blocks of 500 SBOMs. To manage more, you add capacity by increasing the quantity you purchase under your contract. Cost scales with the number of SBOM records you track. Contact the vendor for capacity beyond your current commitment.
Does the SBOM count include continuously monitored records and stored versions?
The product ingests, validates, and stores SBOMs, keeping version history and both original and augmented copies in a central repository. It continuously monitors ingested SBOMs for new vulnerabilities. The 500-SBOM unit sets your managed capacity. For how stored versions count against that capacity, contact the vendor.
Request a private offer to receive a custom quote.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FerroRepo is a Rust-native universal artifact repository that runs as a single self-contained binary and speaks the wire protocols of Sonatype Nexus Repository 3 and JFrog Artifactory, so existing Maven, npm, pip, cargo, docker, and helm clients work unchanged.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.