SBOM Submission Process

Explains the submission channels for the prepared SBOM file, the email template, and the post-submission process.

1. Submission Unit

The submission unit is one delivered product. A product where several nodes form one cluster is no exception; you do not need one per node.

  • If all nodes have the same configuration, generate from a single representative node and submit that.
  • If the installed software differs by node role (for example a management node and a storage node), generate per role and submit them together.

One product may come with several SBOM files. A server generated as separate layers is submitted with the files as they are, not merged, and SK Telecom’s system treats the documents registered against the same product version as a single combined list. Each file needs its own name, and a resubmission must reuse the same name. For the naming rule, see the submit each layer section of How to Generate an SBOM.

2. When to Submit

  • At initial delivery after concluding a software contract
  • When a major or minor version of the software is updated
  • When a regular submission schedule specified in the contract arrives

3. How to Submit

The SBOM file is submitted to SK Telecom’s business unit and security team representatives via email (or a channel designated by the representative).

  • Email subject: [SBOM Submission] SupplierName_ProjectName_Version
  • Attachment: The generated SBOM file (password-protected archive files are not allowed)

Required information in the body:

  1. Delivery contract number
  2. Representative information (name, department, contact)
  3. Project information (system name, detailed version)
  4. Tool used and its version (e.g., BomLens, cdxgen)

4. Post-Submission Validation and Actions

The submitted SBOM is registered in TOSCA, the internal open source and SBOM management system, and then validated according to the procedure below. TOSCA is an internal system, so suppliers do not need access to it.

StageDescriptionProcessing Deadline
Format validationCheck for missing required fields. Notify of rejection if not metWithin 3 days of receipt
Security vulnerability analysisAutomatically analyze whether Critical/High severity vulnerabilities are detected-
Action requestRequest a patch plan or a written justification when serious vulnerabilities are foundCritical: 7 days / High: 30 days

The validation results and action requests are communicated to the supplier and the security team representative through the business unit representative.