DigiCert
State of Software Supply Chain Security Research Report
Pages
17
Time to read
20 mins
Publication
Language
English
Pages
17
Time to read
20 mins
Publication
Language
English
This research report presents findings from a survey conducted by Virtual Intelligence Briefing (ViB) among IT and security professionals responsible for software supply chain security. The report reveals that many organizations overestimate the maturity of their supply chain security programs, with confidence levels not aligning with actual automation and compliance readiness. Key challenges identified include a lack of internal expertise, budget constraints, and minimal automation in security checks. The report details demographic insights from 222 respondents, highlighting their roles and the sectors they represent. A significant finding is the maturity paradox, where nearly half of the organizations rate their programs as established or optimizing, yet only a small percentage fully automate critical processes like code signing. The report also discusses the challenges related to Software Bill of Materials (SBOM) implementation, including accuracy concerns and integration difficulties. Recommendations for closing maturity gaps include focusing on automation, policy enforcement, and embedding security into development workflows.