* Product documentation identifying elements contained in the product (elements may include software, firmware, or hardware elements, as applicable).
* Product documentation identifying components contained in the product (components may include software, firmware, or hardware components, as applicable).
* Component inventory, bill of materials, or equivalent software identification information, including version and patch-level information where available.
* Access to the product, or to relevant components such as binaries, packages, images, firmware, containers, or file systems, sufficient to perform vulnerability scanning where technically feasible.
* Vulnerability scanning tools and associated vulnerability databases suitable for identifying candidate vulnerabilities in the product.