Most security teams cannot answer a basic question fast: what does a given vendor ship us, and how exposed are we today? The real answer takes hours of manual digging through an asset list never built with vendors in mind.
Manifest Cyber is introducing Manifest Supplier Risk, a supplier-centric view of every third party in your software supply chain, grounded in the software bill of materials (SBOM) each vendor ships. Risk rolls up automatically at the supplier level. Vendor risk stops being something teams check on a schedule and becomes something they can see live.
What's New
- Supplier portfolio view. Every supplier ranked by risk score, asset count, open vulnerabilities, and last update.
- Supplier detail view. A full vendor footprint in one click, including every asset, version, risk score, component count, and vulnerability count.
- Aggregated supplier risk scoring. Asset-level risk rolls up to a single supplier score, so teams compare vendors directly instead of asset by asset.
- Prioritized supplier findings. Vulnerabilities are stack ranked by severity and product impact, so teams know what to remediate first.
- Supplier-aware vulnerability and component pages. Third-party products surface alongside first-party assets, clearly distinguished, so teams can see what they build and what they buy in the same place.
- Binary-generated SBOMs. When a supplier will not or cannot produce an SBOM, Manifest generates one from the binary and folds it into that supplier's record, covering C++, unmanaged code, and embedded systems where traditional software composition analysis (SCA) falls short.
- Supplier-associated ingestion. Upload an SBOM or binary directly in The Manifest Platform, or publish through the command line interface (CLI) with a supplier flag.
Why We Built This
Security teams buy nearly as much software as they build, but most tools weren't built with vendors in mind. A few problems keep coming up:
- No aggregated risk score at the supplier level. Just a pile of asset-by-asset findings.
- Vendor questionnaires go stale the moment a new vulnerability drops.
- Suppliers who won't hand over an SBOM disappear from the inventory entirely.
None of this is a problem you fix by adding another dashboard. It is a data model problem, and it is why third-party risk management still runs on questionnaires and point-in-time reviews. A vendor answers a hundred questions in March, and by June the answers are already out of date.
Supplier Risk models third-party software the way procurement actually experiences it, as vendors who ship products, in versions, over time. Teams associate each third-party SBOM with a supplier once a new asset is uploaded, and risk rolls up from there automatically. When a vulnerability surfaces, teams immediately see which suppliers are affected, which products carry the exposure, and what to prioritize first.
Who This Is For
- Third-party risk management (TPRM) teams can replace point-in-time questionnaires with continuous, evidence-based vendor risk.
- Governance, risk, and compliance (GRC) teams can report supplier posture using platform data instead of relying on vendor self-reporting.
- Security and supply chain analysts can answer "what do we have from this vendor" in seconds instead of hours.
- Procurement teams can assess risk before signing a contract, and hold suppliers accountable to it after.
What Comes Next
Today Supplier Risk gives you a clear view of your vendors. Next we'll expand that view to automate vendor outreach, clean up how supplier identity gets resolved across messy SBOM metadata, and give execs a one-click answer to "which vendors does this vulnerability touch."


.png)

