---
title: "Beyond SBOM 2024 trends: AI, Malicious Packages, and everything in between"
description: "Discover key trends and actionable strategies in supply chain security with insights from 900+ AppSec pros in our Beyond SBOM: 2024 trends"
image: https://info.checkmarx.com/hubfs/SCS_Preview_Image.jpg
---

REPORT

# Beyond SBOM: 2024 Trends: AI, Malicious Packages, and Everything In Between

Learn how to start mitigating software supply chain risks by:

- Expanding SCA coverage
- Integrating SBOMs in SCA
- Exploring an integrated platform approach

[Read Report >](https://info.checkmarx.com/beyond-sbom-trends#form)

![SSCS LP2](https://info.checkmarx.com/hubfs/SSCS%20LP2.png)

## Trusted by the World's Leading Enterprises

- ![apple](https://info.checkmarx.com/hs-fs/hubfs/apple.png?width=213&height=52&name=apple.png)
- ![dazn](https://info.checkmarx.com/hs-fs/hubfs/dazn.png?width=213&height=52&name=dazn.png)
- ![decatlon](https://info.checkmarx.com/hs-fs/hubfs/decatlon.png?width=213&height=52&name=decatlon.png)
- ![forgerock](https://info.checkmarx.com/hs-fs/hubfs/forgerock.png?width=213&height=52&name=forgerock.png)
- ![human_managed](https://info.checkmarx.com/hs-fs/hubfs/human_managed.png?width=213&height=52&name=human_managed.png)
- ![my_heritage](https://info.checkmarx.com/hs-fs/hubfs/my_heritage.png?width=213&height=52&name=my_heritage.png)
- ![pismo](https://info.checkmarx.com/hs-fs/hubfs/pismo.png?width=213&height=52&name=pismo.png)
- ![salesforce](https://info.checkmarx.com/hs-fs/hubfs/salesforce.png?width=213&height=52&name=salesforce.png)
- ![sap](https://info.checkmarx.com/hs-fs/hubfs/sap.png?width=213&height=52&name=sap.png)
- ![siemens](https://info.checkmarx.com/hs-fs/hubfs/siemens.png?width=213&height=52&name=siemens.png)
- ![sony](https://info.checkmarx.com/hs-fs/hubfs/sony.png?width=213&height=52&name=sony.png)
- ![starlux](https://info.checkmarx.com/hs-fs/hubfs/starlux.png?width=213&height=52&name=starlux.png)
- ![visa](https://info.checkmarx.com/hs-fs/hubfs/visa.png?width=213&height=52&name=visa.png)
- ![walmart](https://info.checkmarx.com/hs-fs/hubfs/walmart.png?width=213&height=52&name=walmart.png)

Open source software (OSS) dominates the technology landscape, but software supply chain security (SSCS) measures are falling behind. While 75% of AppSec professionals are concerned about SSCS, only 7% have proper security tools in place.   

We surveyed over 900 AppSec professionals to identify actionable strategies you can implement today to improve your SSCS, beyond the software bill of materials (SBOM). 

**Explore additional key highlights, including: **

- 100% of organizations have fallen victim to SSCS attacks
- 8 out of 10 said that finding an SCSS solution is a top priority
- 56% of applications are comprised of open source software 

Download this report and learn how to create a successful SSCS program in 2024. 

## What our customers say

"We were thrilled to find Checkmarx, which helped us improve the SLA for identifying and remediating risk, reduce risk and the number of vulnerabilities, and eliminate high- and meduim-risk issues."

![Persons photo](https://info.checkmarx.com/hs-fs/hubfs/Persons%20photo.png?width=65&height=65&name=Persons%20photo.png)

Ubirajara Aguiar Jr.

Tech Lead, Red Team/DevSecOps

![pisma-logo](https://info.checkmarx.com/hubfs/pisma-logo.svg)

"Checkmarx made security team and developers life easier. "

![](https://info.checkmarx.com/hs-fs/hubfs/person-photo.png?width=51&height=50&name=person-photo.png)

Security Analyst

IT Services

![](https://info.checkmarx.com/hubfs/chain-icon.png) Source:

![Peer Insights](https://info.checkmarx.com/hs-fs/hubfs/Peer%20Insights.png?width=137&height=48&name=Peer%20Insights.png)

“Checkmarx One definitely checks all my boxes from a security standpoint and has a great interface that’s engaging and easy to use. Some of the solutions we considered were more complicated. With Checkmarx One, it’s easy to get right to the problem with little to no learning curve.”

![Persons photo2](https://info.checkmarx.com/hs-fs/hubfs/Persons%20photo2.png?width=65&height=65&name=Persons%20photo2.png)

Joel Godbout

Cybersecurity and Networking Manager

![logo-pcl](https://info.checkmarx.com/hubfs/logo-pcl.svg)

"We were thrilled to find Checkmarx, which helped us improve the SLA for identifying and remediating risk, reduce risk and the number of vulnerabilities, and eliminate high- and meduim-risk issues."

![Persons photo](https://info.checkmarx.com/hs-fs/hubfs/Persons%20photo.png?width=65&height=65&name=Persons%20photo.png)

Ubirajara Aguiar Jr.

Tech Lead, Red Team/DevSecOps

![pisma-logo](https://info.checkmarx.com/hubfs/pisma-logo.svg)

"Checkmarx’s execution is impressive; it’s brought all the products under one cloud platform"

![](https://info.checkmarx.com/hubfs/chain-icon.png) Source:

The Forrester WaveTM: Software   
Composition Analysis, Q2 2023

“By far the best AppSec tooling decision we have made!!”

Application Security Manager

Software

![](https://info.checkmarx.com/hubfs/chain-icon.png) Source:

![Peer Insights](https://info.checkmarx.com/hs-fs/hubfs/Peer%20Insights.png?width=137&height=48&name=Peer%20Insights.png)

## Market & Technology Leadership

50%

 of Fortune 100

1800+

 Customers in 70 countries

50+

 Languages & 100+ frameworks

6x

 Leader at Gartner® Magic Quadrant™ for Application Security Testing

## Industry Recognition

![footer logo 2023](https://info.checkmarx.com/hs-fs/hubfs/footer%20logo%202023.png?width=1452&height=167&name=footer%20logo%202023.png)