Continuous SBOM risk management helps organisations address vulnerabilities, open-source licence risks and EOL/EOS exposure across complex enterprise software environments
MARLOW, England – 15 September 2026 – Developing World Systems Limited (DWS), a global software services company and part of AGEST Group, today announced the international launch of SBOM Archi, AGEST, Inc.’s proprietary software supply chain risk management platform. Developed in Japan by AGEST, SBOM Archi helps organisations gain greater visibility into their software components and continuously manage security, compliance and lifecycle risks.
The latest SBOM Archi Version 2.2 introduces new capabilities designed to support organisations preparing for requirements under the European Union’s Cyber Resilience Act (CRA), including integration with the European Vulnerability Database (EUVD), audit logging, CRA reporting-status management and support for CVSS Version 4.0.
Founded in 1998 and headquartered in Marlow, England, DWS provides enterprise software development, testing and software supply chain security solutions for organisations operating complex and business-critical systems, including enterprise ERP environments. Its services focus on software quality, security, reliability and controlled modernisation.
The launch comes as software supply chain security moves higher on the enterprise risk agenda and new regulatory requirements place greater emphasis on software transparency and vulnerability management.
Reporting obligations under the European Union’s Cyber Resilience Act (CRA) are being phased in from September 2026, increasing the importance of structured vulnerability management and security reporting for organisations operating in or preparing to enter the European market.
For enterprises operating complex and business-critical software environments, these developments increase the importance of understanding not only which components are present within software, but also the risks associated with those components throughout their lifecycle.
“Software supply chain visibility is becoming an important part of both cybersecurity and operational resilience,” said Satoshi Furui, CEO of DWS. “For organisations managing complex or business-critical environments, creating an SBOM is only the starting point. The real value comes from being able to understand the risks within that information, prioritise what requires action and maintain that visibility as software and vulnerabilities change.”
Managing Three Areas of Software Supply Chain Risk
SBOM Archi provides an integrated environment for organisations to identify, assess and manage three critical areas of software supply chain exposure:
Vulnerability Risk: Identify known security vulnerabilities affecting software components and reassess risk as new information becomes available.
Licence Risk: Identify open-source licences and support the management of potential compliance concerns.
EOL/EOS Risk: Identify components approaching or reaching End-of-Life or End-of-Support, helping organisations address potential security, maintainability and business continuity issues.
This approach enables organisations to move beyond maintaining an SBOM as a static software inventory and use component information as part of an ongoing operational risk-management process.
From SBOM Generation to Operational Risk Management
SBOM Archi supports the full SBOM lifecycle through a Generate, Analyse and Remediate model.
Organisations can generate and manage SBOM data, assess software components against vulnerability and lifecycle information, prioritise identified risks and maintain a record of response activities within an integrated environment.
The platform integrates vulnerability intelligence from major sources including the National Vulnerability Database (NVD), Open Source Vulnerabilities (OSV), GitHub Security Advisories (GHSA) and Japan Vulnerability Notes (JVN).
Vulnerabilities can be evaluated using CVSS severity scores and EPSS exploitation probability, providing additional context to help security teams prioritise remediation activities.
SBOM Archi supports widely adopted SPDX 2.2-2.3 and CycloneDX 1.4-1.6 formats, as well as online, on-premise and offline or air-gapped SBOM generation workflows.
Supporting Cyber Resilience Act Readiness
The latest SBOM Archi Version 2.2 introduces capabilities specifically designed to support organisations preparing for requirements under the European Union’s Cyber Resilience Act.
European Vulnerability Database Integration
SBOM Archi now supports the European Vulnerability Database (EUVD), the EU’s official vulnerability database developed and operated by ENISA.
The platform supports vulnerability matching using EUVD IDs and introduces a dedicated CRA Mode. When CRA Mode is enabled for a project or target, a dedicated EUVD tab becomes available, helping organisations incorporate European vulnerability information into their vulnerability-management processes.
Audit Logging
Version 2.2 also introduces audit logging designed to maintain records relevant to CRA-related processes.
This includes records of SBOM updates and decision-making processes associated with vulnerability response. Save operations performed within SBOM Archi are captured within the audit log, helping organisations maintain a clearer record of their software supply chain risk-management activities.
CRA Reporting-Status Management
SBOM Archi now enables organisations to manage CRA-specific reporting statuses independently from the technical status used within VEX (Vulnerability Exploitability eXchange).
Users can record whether an issue does not require reporting, has not yet been reported or has already been reported under CRA requirements. Reporting destinations, such as ENISA, and associated ticket IDs can also be recorded manually.
Support for CVSS Version 4.0
The latest release also adds support for CVSS Version 4.0, the latest version of the internationally recognised Common Vulnerability Scoring System used to assess the severity of software vulnerabilities.
In addition, Version 2.2 includes 12 further functional enhancements, improvements and defect fixes.
Together, these capabilities can help organisations establish clearer processes around software component visibility, vulnerability management, auditability and regulatory reporting as CRA requirements are phased into application.
SBOM Archi is intended to support regulatory readiness rather than replace an organisation’s compliance programme. Customers remain responsible for determining the requirements that apply to their products and for completing required regulatory assessments, documentation and attestations.
Built for Complex Enterprise Environments
DWS supports organisations operating enterprise and mission-critical software environments where reliability, security and continuity directly affect business operations.
The addition of SBOM Archi extends DWS’s existing software development, testing and software supply chain security capabilities with enhanced software component visibility and risk-management capabilities.
For organisations managing ERP platforms, legacy environments, proprietary applications or increasingly complex third-party software dependencies, SBOM Archi provides a centralised way to understand software composition and the risks associated with it.
Limited-Time Full Access Offer
To support the international introduction of SBOM Archi, DWS is offering a limited-time free-access programme through 30 November 2026.
Organisations that register during the promotional period will receive full access to all SBOM Archi features at no cost, from the date of registration through 30 November 2026.
This includes access to the platform’s core SBOM management capabilities, vulnerability, licence and EOL/EOS risk management, as well as the latest capabilities introduced in SBOM Archi Version 2.2, including EUVD integration, audit logging, CRA reporting-status management and support for CVSS Version 4.0.
The programme gives organisations an opportunity to evaluate SBOM Archi within their own software environments and experience the platform’s full capabilities before making a longer-term commitment.
Organisations interested in taking advantage of the offer can contact DWS to register or arrange a demonstration.
Availability
SBOM Archi is available internationally through DWS beginning 15 September 2026.
Organisations can contact DWS to discuss their software supply chain requirements, CRA preparation, the limited-time free-access programme or to arrange a demonstration of SBOM Archi.
About SBOM Archi
SBOM Archi is a software supply chain risk management platform developed by AGEST, Inc.
Engineered in Japan, it enables organisations to continuously identify, assess and manage vulnerabilities, licence risks and EOL/EOS exposure across complex software environments.
SBOM Archi combines SBOM management, vulnerability intelligence, risk assessment and operational risk management to help organisations transform software component information into actionable risk intelligence.
AGEST plans to continue enhancing SBOM Archi by incorporating customer feedback and expanding its functionality to support stronger software supply chain risk management and more resilient security environments.