The idea of knowing what is in our software went from a radical idea to the popular buzzword of “SBOM”. But where is Software Bill of Materials going, and how will it interact with other movements in security, particularly around government policy and regulation? This talk will review where SBOM came from, and how it became a global community, then explicitly aggressive current gaps, and how the community is working to address them. But SBOM alone will, of course, not solve all our problems. Before SBOM, we need more Coordinated Vulnerability Disclosure (CVD). Once we have SBOM, we need good quality vulnerability data, including the new CVE standards, and better software identifiers. And to prevent being overwhelmed, we need the Vulnerability Exploitability eXchange (VEX) and machine readable advisories, for both proprietary and open source software. See the whole map for better planning around the future of software security and response.