Don’t have structured component tracking.
Can’t trace vulnerabilities across their own codebase.
Aren’t compliant with upcoming industry regulations.
Lack investment in software supply chain hygiene.
Incomplete or vague component listings.
Missing version numbers or suppliers.
No dependency relationships.
Use of non-standard formats or manually written documents
Poor build and release discipline.
Weak DevSecOps integration.
Immature vulnerability tracking processes.
How fast does the supplier respond?
Do they proactively notify you about the impacted component?
Do they offer mitigations, patches, or updated builds?
Can they show impact based on the SBOM they previously delivered?