EcoCitizenZ
Path 3 · Software & SBOM Essentials

Publish your software evidence posture publicly

Buyers are asking for software provenance and liability clarity. ECZ-ID gives you resolver-verifiable software trust objects — supply chain, cyber resilience, and product posture — so you become easier to evaluate in security review and procurement before a question becomes a blocker.

For: Software vendors · Product & security teams · Security-conscious buyers · Software supply chain operators · Liability-sensitive platforms

The SBOM essentials path — at a glance

1Identify your software surface2Select SBOM EssentialsTrustOps — acquire credentials3Return with trust objects4Verify via Resolver5Use in procurement and security contexts
Primary pack:SBOM EssentialsSoftware Supply Chain Passport · Cyber Resilience Passport · Product Passport·Provisioned in TrustOps. Verified through Resolver. Usable anywhere.
The Pressure Point

Why software liability posture is becoming a procurement requirement

The question is no longer whether buyers will ask about software provenance. It is whether your answer is already documented and independently verifiable.

Procurement is asking about software provenance

Enterprise buyers, government procurement, and security-sensitive platforms increasingly require software vendors to document provenance, supply chain integrity, and liability posture. SBOM requests — once rare — are becoming standard due diligence in security and procurement review.

Ambiguity creates friction — and risk

Software liability ambiguity slows procurement cycles. Buyers facing unclear provenance escalate to additional review, delay sign-off, or disqualify vendors entirely. ECZ-ID removes that ambiguity by making your software evidence posture publicly verifiable through Resolver — before a question becomes a blocker.

Proof you control the narrative

With resolver-verifiable software trust objects, you publish your own posture on your own terms. Buyers verify through Resolver; you do not need to produce custom documentation for every procurement context. One authoritative surface. Independently verifiable. Always current.

The SBOM Essentials Path

A complete, practical route from identification to deployed software evidence posture.

1
Identify your software or software supply chain surface
Understand which proof buyers are likely to require: SBOM provenance, supply chain integrity, cyber resilience posture, or liability attribution.
2
Acquire the ECZ-ID Business Passport (parent credential)
Your foundational identity object. Establishes resolver presence and anchors all child trust objects.
3
Add the SBOM Essentials
Software Supply Chain Passport + Cyber Resilience Passport + Product Passport. Primary path for software vendors facing liability or provenance requirements.
4
Acquire your credentials through TrustOps
Navigate to TrustOps /start, select your corridor, complete provisioning. Related paths include Cyber Governance Pack and AI Provenance Pack.
5
Return with your provisioned credentials and trust surfaces
Your passports, API keys, and resolver-verifiable identity surfaces are ready to use immediately after provisioning.
6
Verify your software identity and evidence posture through Resolver
Confirm all credentials are live and resolver-resolvable. Share your Resolver link with buyers, security teams, and procurement counterparties.
7
Use public proof in procurement, security review, and supply chain contexts
Embed Resolver links in security questionnaire responses, tender submissions, software provenance documentation, and partner-facing materials.
Trust Objects

What you acquire on the SBOM / software liability path

SBOM Essentials is the primary path. Related packs extend your posture for governance and AI-specific provenance requirements.

Primary

Software Supply Chain Passport

Documents your software supply chain integrity. Records components, dependencies, and provenance lineage. The primary trust object for SBOM-adjacent proof in procurement and security review.

Primary

Cyber Resilience Passport

Documents your cyber resilience posture. Required for buyers applying EU Cyber Resilience Act standards or security procurement frameworks. Independently resolver-verifiable.

Primary

Product Passport

Resolver-verifiable product identity. Extends SBOM proof to cover the product itself — what you ship, under what conditions, and with what attributable provenance chain.

Related pack

Cyber Governance Pack

For vendors operating in DORA-adjacent or regulated cyber governance contexts. Extends SBOM Essentials posture with risk policy and identity continuity for governance-sensitive buyers.

Related pack

AI Provenance Pack

For software vendors with AI components. Adds AI model and dataset provenance to your evidence posture. Relevant for buyers assessing AI liability, model provenance, and training data integrity.

Package: SBOM Essentials

Bundles Software Supply Chain, Cyber Resilience, Product Passport, and IoT Device Credential. Primary path for software vendors. Provisioned through TrustOps.

Acquire in TrustOps
SBOM Commercial Architecture

SBOM coverage tier structure

Three tiers for different scales of SBOM obligation. Essentials is the current live, self-service baseline. Managed and Enterprise are guided engagement pathways for organisations with deeper or multi-product requirements.

SBOM EssentialsLive · Self-service

Baseline credentialing package — software supply chain provenance, cyber resilience, product evidence record, and IoT device posture. Acquired through TrustOps.

£269.96 / month

SBOM ManagedGuided onboarding

Managed credential lifecycle across product releases. Provenance refresh coordination on patch cycles. Structured output for regulated buyer SBOM disclosure requirements. Delivered via TrustOps onboarding.

Contact TrustOps for guided onboarding

SBOM EnterpriseEnterprise engagement

Portfolio-level credential management for large-scale or multi-product SBOM obligations. Bespoke format integration. Dedicated evidence infrastructure for enterprise supply chains.

Enterprise contact via TrustOps

How It Works

Discover here. Acquire in TrustOps. Verify through Resolver.

This Developer Gateway is where you understand the path and prepare. TrustOps is where you acquire and manage credentials. Resolver is where buyers and security teams verify them.

Developer Gateway

Discover the software trust path. Understand trust objects. Prepare your credentialing plan.

TrustOps

Acquire your passports and credentials. Manage lifecycle and renewals. Handle all provisioning and pricing.

trustops.ecocitizenz.com/start

Resolver

Buyers and security teams verify your software evidence posture here. Public, independent, no account required.

resolver.ecocitizenz.org
After Credentialing

What resolver-verifiable software trust credentials make possible

Security questionnaire response

Replace lengthy manual questionnaire responses with a single Resolver link. Buyers verify your software evidence posture independently — no custom documentation per buyer.

Software procurement eligibility

Demonstrate documented software provenance and liability posture as a condition of enterprise procurement. Reduce friction in security review stages.

SBOM-adjacent proof in tenders

Include Resolver-verifiable software supply chain proof in tender responses and RFQ submissions where SBOM or software integrity documentation is required.

EU Cyber Resilience Act readiness

Cyber Resilience Passport supports alignment with emerging EU CRA requirements for software vendors placing products with digital elements into the EU market.

AI component liability clarity

AI Provenance Pack extends your posture to cover AI model and dataset provenance — relevant for buyers assessing AI liability and training data integrity.

Public software trust surface

Your Resolver profile is a permanent, always-current public surface. Share once; reuse across every procurement context, security audit, and partner evaluation.

What the software & SBOM essentials path delivers

What you start with

A mapped software trust surface, with SBOM Essentials as your primary acquisition target through TrustOps.

What TrustOps returns

Business Passport, Software Supply Chain Passport, Cyber Resilience Passport, Product Passport, and a live resolver-verifiable software trust profile.

What you can show publicly

A Resolver profile documenting your software provenance, supply chain integrity, and cyber resilience posture — shareable in procurement, security review, and tenders.

What your counterparty can verify

Software supply chain integrity, cyber resilience posture, product provenance, and liability attribution — through Resolver, without requesting documentation.

Related onboarding paths

Ready to establish software evidence posture?

Acquire your SBOM Essentials through TrustOps. Your software trust credentials are provisioned once and remain verifiable through Resolver for any buyer or security team.