<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1">
<url>
<loc>https://compliancereference.com</loc>
<lastmod>2026-09-11T03:52:17.971Z</lastmod>
<changefreq>daily</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://compliancereference.com/sections/sbom-audit-evidence</loc>
<lastmod>2026-09-11T03:52:17.971Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://compliancereference.com/sections/features</loc>
<lastmod>2026-09-09T17:01:43.448Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://compliancereference.com/authors/ingrid-ashworth</loc>
<lastmod>2026-09-11T03:52:17.971Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://compliancereference.com/authors/kwame-fontaine</loc>
<lastmod>2026-09-11T03:52:17.971Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://compliancereference.com/authors/leila-lindqvist</loc>
<lastmod>2026-09-11T03:52:17.971Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.4</priority>
</url>
<url>
<loc>https://compliancereference.com/posts/eo-14028-sbom-minimum-element-requirements</loc>
<image:image>
<image:loc>https://mcxtywzsmeezbwapdahq.supabase.co/storage/v1/object/public/canvas-images/bf99d458-afee-43f2-b192-9a081215c918/canvas/4f58b114-a15b-46ad-becd-fb0c59378b21/generated/660e81c9-cb46-4a07-98de-40cc576c9aa1.jpeg</image:loc>
</image:image>
<lastmod>2026-09-11T03:52:17.971Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://compliancereference.com/posts/spdx-vs-cyclonedx-for-fedramp-auditors</loc>
<image:image>
<image:loc>https://mcxtywzsmeezbwapdahq.supabase.co/storage/v1/object/public/canvas-images/bf99d458-afee-43f2-b192-9a081215c918/canvas/4f58b114-a15b-46ad-becd-fb0c59378b21/generated/9f2e57c7-822a-4d03-a7d1-43b8b9031619.jpeg</image:loc>
</image:image>
<lastmod>2026-09-10T02:16:33.811Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://compliancereference.com/posts/software-supply-chain-risk-in-third-party-dependency-policies</loc>
<image:image>
<image:loc>https://mcxtywzsmeezbwapdahq.supabase.co/storage/v1/object/public/canvas-images/bf99d458-afee-43f2-b192-9a081215c918/canvas/4f58b114-a15b-46ad-becd-fb0c59378b21/generated/ed660357-d0cf-45d8-a1ad-1539e248dc3f.png</image:loc>
</image:image>
<lastmod>2026-09-09T17:01:43.448Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.7</priority>
</url>
</urlset>
