# Best Software Bill of Materials (SBOM) Software - Page 3

## How Many Software Bill of Materials (SBOM) Software Products Does G2 Track?

**Total Products under this Category:** 33

### Category Stats (Aug 2026)

- **Average Rating:** 4.49/5 (↑0.01 vs Jul 2026) The average rating of products in this category, based on all submitted ratings
- **Top Trending Product:** Finite State (+3.17%) - Among all products in this category, Finite State recorded the largest rating increase compared to last month

_Last updated: August 06, 2026_

## How Does G2 Rank Software Bill of Materials (SBOM) Software Products?

**Why You Can Trust G2's Software Rankings:**

- 30 Analysts and Data Experts
- 900+ Authentic Reviews
- 33+ Products
- Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

**Sponsored**

### Malbek

Malbek is a comprehensive contract lifecycle management (CLM) solution designed to streamline and enhance the contracting process for large enterprises and fast-growing businesses. By providing an end-to-end platform, Malbek eliminates the challenges associated with manual and disjointed contracting, allowing organizations to manage their contracts more effectively. The solution is built on a secure and scalable infrastructure, making it suitable for businesses of varying sizes and complexities. The target audience for Malbek includes legal teams, procurement departments, and business units that require efficient contract management to support their operations. With its user-friendly interface and robust features, Malbek caters to organizations looking to increase top-line revenue, improve operational efficiency, and mitigate risks associated with contract management. Specific use cases include contract creation, approval workflows, and compliance tracking, all of which are essential for maintaining control over contractual obligations and ensuring alignment with business objectives. Key features of Malbek CLM include a powerful contract repository that allows users to search and locate contracts and clauses with ease, akin to the experience of online shopping. This feature significantly reduces the time spent searching for documents, enabling users to focus on more strategic tasks. Additionally, Malbek offers modular and reusable building blocks for contract authoring, which ensures consistency and quality across all documents. Users can create and edit contracts using familiar tools such as MS Word or online editors, making the transition to Malbek seamless. Malbek also enhances the approval process with mobile capabilities and automated reminders, ensuring that contracts are tracked and approved in a timely manner. The platform imposes a superior layer of process governance, reinforcing control across the enterprise and reducing the likelihood of errors or compliance issues. By incorporating pre-approved language and terms, Malbek provides visibility into potentially risky clauses, allowing organizations to proactively manage risk and maintain compliance. Furthermore, Malbek empowers business users to create tailored solutions without the need for coding or IT intervention, redefining simplification in contract management. With out-of-the-box integrations to popular business applications such as Salesforce, Workday, Slack, and Office 365, Malbek facilitates improved collaboration among teams. This seamless flow of contract data between systems contributes to dramatically reduced contract cycle times, ultimately enhancing the overall efficiency of the contracting process.

[Visit website](https://www.g2.com/external_clickthroughs/record?secure%5Bad_program%5D=ppc&secure%5Bad_slot%5D=category_product_list_llm&secure%5Bcategory_id%5D=1008169&secure%5Bchosen_at%5D=2026-08-08T13%3A40%3A29Z&secure%5Bdisplayable_resource_id%5D=4&secure%5Bdisplayable_resource_type%5D=Category&secure%5Bmedium%5D=sponsored&secure%5Bplacement_reason%5D=retargeted_product&secure%5Bplacement_resource_ids%5D%5B%5D=128660&secure%5Bprioritized%5D=false&secure%5Bproduct_id%5D=128660&secure%5Bresource_id%5D=1008169&secure%5Bresource_type%5D=Category&secure%5Bsource_type%5D=category_page&secure%5Bsource_url%5D=https%3A%2F%2Fwww.g2.com%2Fcategories%2Fsoftware-bill-of-materials-sbom%3Fpage%3D3&secure%5Btoken%5D=4fd7525d6cc2a0d61a15706b338d885e34061a30c58613a6fa7ef1fa2fad4016&secure%5Burl%5D=https%3A%2F%2Fhubs.li%2FQ04p_stC0&secure%5Burl_type%5D=custom_url)

### [Sonatype SBOM Manager](https://www.g2.com/products/sonatype-sbom-manager/reviews)

Sonatype SBOM Manager helps organizations generate, centralize, and manage Software Bills of Materials (SBOMs) across their software portfolio so teams can meet compliance requirements and respond faster to supply chain risk. SBOMs are increasingly required for procurement, audits, and security programs - but collecting them from many teams and vendors, keeping them current, and turning them into actionable risk insights is hard. SBOM Manager brings SBOM creation and management together in a single place so security, compliance, and procurement teams can standardize how SBOMs are produced, stored, shared, and reviewed. Key capabilities: - Generate SBOMs for applications in widely used formats (CycloneDX and SPDX) - Import and manage SBOMs received from third-party software suppliers - Centralize SBOMs across teams and products for consistent governance and audit readiness - Support risk and compliance workflows by making SBOM data easy to access, distribute, and operationalize SBOM Manager pairs Sonatype’s component intelligence with dedicated SBOM management so organizations can strengthen their software supply chain security posture, stay ahead of evolving requirements, and reduce the effort of proving compliance.

#### Who Is the Company Behind Sonatype SBOM Manager?

- **Seller:** [Sonatype](https://www.g2.com/sellers/sonatype)
- **Year Founded:** 2008
- **HQ Location:** Fulton, US
- **Twitter:** @sonatype  
10,589 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=dd965bcc74ef94929b9eb731aaa8ab372133c521cbfc49096fe776e20652458f&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F210324%2F&secure%5Burl_type%5D=linkedin_company_website)  
553 employees on LinkedIn®

### [Veracode Application Security Platform](https://www.g2.com/products/veracode-application-security-platform/reviews)

Veracode helps companies that innovate through software deliver secure code on time. Unlike on-premise solutions that are hard to scale and focused on finding rather than fixing, Veracode comprises a unique combination of SaaS technology and on-demand expertise that enables DevSecOps through integration with your pipeline,empower developers to fix security defects, and scales your program through best practices to achieve your desired outcomes. Veracode covers your all your AppSec needs in one solution through a combination of five analysis types available for 24 programming languages, 77 frameworks, and application types as varied as microservices, mainframe and mobile apps.

**Average Rating:** 3.8/5.0

**Total Reviews:** 25

#### Who Is the Company Behind Veracode Application Security Platform?

- **Seller:** [VERACODE](https://www.g2.com/sellers/veracode)
- **Year Founded:** 2006
- **HQ Location:** Burlington, MA
- **Twitter:** @Veracode  
21,950 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=d799a3c2e821841d648bc54266ea8fb1c07039938aa9c79b60d2cf275f0dcf34&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2F27845%2F&secure%5Burl_type%5D=linkedin_company_website)  
500 employees on LinkedIn®

#### Who Uses This Product?

- **Top Industries:** Information Technology and Services
- **Company Size:** 69% Large, 31% Medium

#### What Do G2 Reviewers Say About Veracode Application Security Platform?

_AI-generated summary from verified user reviews_

##### Pros

- Users appreciate the **comprehensive security analysis** offered by Veracode, effectively addressing vulnerabilities and streamlining development.
- Users value Veracode for its **effective vulnerability detection** , ensuring high-security standards and seamless integration into development processes.
- Users appreciate the **automated scanning** feature of Veracode, which effectively identifies vulnerabilities and enhances security standards.
- Users value the **effective detection capabilities** of Veracode, enabling thorough security checks and vulnerability identification.
- Users value the **ease of use** of Veracode, benefiting from seamless integration and comprehensive security analysis.

##### Cons

- Users find the platform to be **expensive** , with rising costs and unjustifiable investment in customer success packages.
- Users face a **lack of information** regarding features and services, leading to confusion and unmet expectations.
- Users express concerns about **licensing issues** , citing high costs, complex models, and unmet feature expectations.
- Users report **poor customer support** , experiencing pressure from sales and challenges with feature delivery and documentation.
- Users express concerns over **pricing issues** , citing increased costs, complex licensing, and pressure from sales executives.

#### What Are Recent G2 Reviews of Veracode Application Security Platform?

**["Streamlined Security, Effortless Integration"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)**

**Rating:** 5.0/5.0 stars

_— Bhanu Prakash M._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-11757799)

**["Clear, Unified View of Application Capabilities"](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)**

**Rating:** 4.5/5.0 stars

_— Christopher S._

[Read full review](https://www.g2.com/survey_responses/veracode-application-security-platform-review-12910910)

#### What Are G2 Users Discussing About Veracode Application Security Platform?

- [What is difference between veracode and SonarQube?](https://www.g2.com/discussions/what-is-difference-between-veracode-and-sonarqube)
- [What is veracode software composition analysis?](https://www.g2.com/discussions/what-is-veracode-software-composition-analysis)
- [What is veracode used for?](https://www.g2.com/discussions/what-is-veracode-used-for)
- [What is the veracode application security platform?](https://www.g2.com/discussions/what-is-the-veracode-application-security-platform)

### [Vigiles](https://www.g2.com/products/vigiles/reviews)

Vigiles is a best-in-class vulnerability monitoring and remediation tool that combines a curated CVE database, continuous security feed based on your SBOM, powerful filtering, and easy triage tools so you don’t get blindsided by vulnerabilities.

**Average Rating:** 4.2/5.0

**Total Reviews:** 6

#### Who Is the Company Behind Vigiles?

- **Seller:** [Timesys](https://www.g2.com/sellers/timesys)
- **Year Founded:** 1996
- **HQ Location:** Pittsburgh, US
- **Twitter:** @Timesys  
540 Twitter followers
- **LinkedIn® Page:** [www.linkedin.com](https://www.g2.com/external_clickthroughs/record?secure%5Bsource_type%5D=product_profile&secure%5Btoken%5D=5e55208e74e888cc5733ffc011cda8f939829410d9548b06dd128583ee8ba8d4&secure%5Burl%5D=https%3A%2F%2Fwww.linkedin.com%2Fcompany%2Ftimesys-corporation%2F&secure%5Burl_type%5D=linkedin_company_website)  
52 employees on LinkedIn®

#### Who Uses This Product?

- **Company Size:** 83% Small, 17% Large

#### What Are Recent G2 Reviews of Vigiles?

**["Vigiles review"](https://www.g2.com/survey_responses/vigiles-review-8911852)**

**Rating:** 4.0/5.0 stars

_— Tushar T._

[Read full review](https://www.g2.com/survey_responses/vigiles-review-8911852)

**["A Revolutionary Security Solution for Peace of Mind"](https://www.g2.com/survey_responses/vigiles-review-8284121)**

**Rating:** 4.0/5.0 stars

_— Prashant S._

[Read full review](https://www.g2.com/survey_responses/vigiles-review-8284121)

- [&lsaquo; Prev‹ Prev](/categories/software-bill-of-materials-sbom?order=popular&page=2#product-list)
- [1](/categories/software-bill-of-materials-sbom?order=popular#product-list)
- [2](/categories/software-bill-of-materials-sbom?order=popular&page=2#product-list)
- 3
- Next &rsaquo;Next ›

Spotlight Categories

[SEO Tools](https://www.g2.com/categories/seo-tools)

[Multi-Country Payroll Software](https://www.g2.com/categories/multi-country-payroll)

[Employer of Record (EOR) Software](https://www.g2.com/categories/employer-of-record-eor)

[Video Editing Software](https://www.g2.com/categories/video-editing)

[Digital Adoption Platforms](https://www.g2.com/categories/digital-adoption-platform)

Similar Categories

- [Static Code Analysis](/categories/static-code-analysis)
- [Container Security](/categories/container-security-tools)
- [Dynamic Application Security Testing (DAST)](/categories/dynamic-application-security-testing-dast)
- [Interactive Application Security Testing (IAST)](/categories/interactive-application-security-testing-iast)

- [Log Analysis](/categories/log-analysis)
- [Penetration Testing](/categories/penetration-testing-tools)
- [Secure Code Review](/categories/secure-code-review)
- [Software Composition Analysis](/categories/software-composition-analysis)

- [Static Application Security Testing (SAST)](/categories/static-application-security-testing-sast)
- [Vulnerability Scanner](/categories/vulnerability-scanner)
- [Web Application Firewall (WAF)](/categories/web-application-firewall-waf)

[Browse Software Bill of Materials (SBOM) Themes](/categories/software-bill-of-materials-sbom/themes)

 ![Adam Crivello](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Adam Crivello")
AC

Researched and written by [Adam Crivello](https://research.g2.com/insights/author/adam-crivello)

Updated October 3, 2024

Software bill of materials (SBOM) solutions generate, ingest, manage, and monitor a machine-readable inventory of the components within software supply chains. The components covered include libraries, packages, modules, associated licenses, and more. Companies and developers use SBOM software to deliver and annotate comprehensive SBOMs for their software’s third party and open source components .

These solutions allow users to comply with government mandates that require the provision of a minimum SBOM. Maintaining and monitoring SBOMs also helps companies perform continuous risk assessments, though vulnerability remediation is not the primary focus of such tools. [software composition analysis (SCA) tools](https://www.g2.com/categories/software-composition-analysis) scan software supply chains’ components and dependencies at the code level to identify and remediate security vulnerabilities, whereas SBOM software automates the standardized presentation of those elements for transparency, observability, and compliance.

To qualify for inclusion in the Software Bill of Materials (SBOM) category, a product must:

- Automatically ingest and generate SBOMs in standard formats like CycloneDX and SPDX
- Continuously monitor and update SBOMs based on component versions, associated licenses, dependencies, and more
- Alert users of non-compliant elements in their software supply chain
- Allow users to annotate SBOMs
- Facilitate compliance with government regulations

Show More