- Home
- Leading aerospace and defense space and mission systems organization mosa.ic sca
Major U.S. A&D Space and Mission Systems Organization
Embedded Software Supply-Chain Security with MOSA.ic.SCA
Challenge
-
Repeatable SBOM + CVE evidence
-
Fit Yocto/PetaLinux CI/CD builds
-
Run on air-gapped networks
Solution
-
Build-integrated SBOM + CVE scan
-
On-prem Vigiles, CycloneDX/SPDX
-
Low-risk hosted trial first
Value
-
Compliance evidence per release
-
Target-aware, embedded-Linux depth
-
Foothold to expand across programs

Key Capabilities
GitLab CI/CD
DOORS
VectorCAST
AdaCore
SaFe Agile
Key Capabilities: MOSA.ic.SCA • Vigiles • SBOM/CVE • Yocto/PetaLinux • Air-gapped
Customer Challenge
A leading aerospace & defense (A&D) organization’s space & mission systems division needed a repeatable way to manage software-supply-chain risk in embedded systems across satellite, mission-computing, sensor, and ground-system programs. The core requirement was to generate software bills of materials (SBOMs), identify and manage known vulnerabilities (CVEs), and preserve compliance evidence to meet growing cybersecurity requirements.
Crucially, this could not be a one-time report. Engineering needed to produce SBOM and vulnerability evidence repeatedly across builds and releases, integrated with existing embedded-Linux builds, CI/CD pipelines, and an artifact repository. The immediate focus was Yocto/PetaLinux, with broader interest spanning Linux, VxWorks®, and FreeRTOS. Results had to use standard CycloneDX and SPDX SBOM formats and operate across both connected and air-gapped / disconnected networks.
Lynx Solution & Capabilities
LYNX MOSA.ic.SCA, deployed on-premises and powered by on-premises Vigiles, fit both the technical workflow and the deployment constraints. Built-in Yocto integration generates an SBOM and performs CVE analysis as part of the build itself, while Vigiles APIs and a CLI enable automated pipelines with standard CycloneDX/SPDX output. This matched the customer’s CI/CD and artifact-repository processes and its need to operate across enterprise and disconnected networks.
MOSA.ic.SCA is purpose-built for embedded Linux rather than general-purpose repository or container scanning. Its target-aware CVE analysis reflects what is deployed — kernel, U-Boot, CPU/SoC, and target package context, so teams focus on the vulnerabilities that genuinely matter for the fielded system. As an on-premises, customer-controlled solution, it satisfies multi-network and disconnected-environment requirements while complementing the broader LYNX MOSA.ic platform and integration work.
A decisive element was a low-risk path to proof: a limited, read-only hosted Vigiles trial with a preloaded PetaLinux SBOM let the evaluation team validate the end-to-end workflow on a representative build before any on-premises commitment, removing risk from the buying decision without an infrastructure lift.

Customer Value & Outcomes
The customer gained a repeatable, build-integrated way to produce SBOM and vulnerability evidence for every release, with compliance artifacts preserved across builds, replacing ad-hoc, one-time reporting. Target-aware analysis reduces noise by prioritizing the CVEs that apply to the deployed embedded target, and standard CycloneDX/SPDX output plugs directly into existing CI/CD and artifact-repository workflows.
Because the solution runs on-premises and supports disconnected operation, the same workflow works across enterprise and air-gapped networks — a hard requirement for mission-critical A&D programs. The initial adoption also establishes a foothold within a large A&D account, with clear room to expand to additional programs and business units and to adjacent Lynx capabilities such as secure Linux and MOSA.ic.AI.
Key Skills & Differentiators
-
- Build-integrated SBOM generation (CycloneDX / SPDX)
- Target-aware CVE analysis and filtering for embedded Linux (kernel, U-Boot, CPU/SoC, target packages)
- Yocto / PetaLinux integration; applicable to Buildroot and OpenWrt
- Vigiles API and CLI automation for CI/CD pipelines and artifact repositories
- On-premises, customer-controlled deployment across connected and air-gapped / disconnected networks
- Repeatable evidence and disposition tracking across builds and releases
- Multi-OS breadth of interest (Linux, VxWorks, FreeRTOS)
- Low-risk, read-only hosted trial to validate the workflow before on-premises commitment
MOSA.ic.SCA in the Embedded Build & Compliance
Build-integrated SBOM generation and target-aware CVE analysis - powered by on-premises VigilesEmbedded Build
-
Yocti/PetaLinus
- Buildroot/OpenWrt
- BSP, kernel, U-Boot
- CPU/SoC and target
- Packages
Connected
MOSA.ic.SCA
-
SBOM generation
-
Target-aware CVE
-
Vigiles API/CLI
-
CycloneDX/SPDX
Pipeline Integration
-
CI/CD pipelines
-
Artifactory
-
Issue tracker
-
Repeatable, automated
-
Per build
Connected
Compliance Outputs
-
SBOM (CycloneDX/SPDX)
-
Prioritized, relevant CVEs
-
Disposition decisions
-
Release compliance
-
Evidence
Repeatable across every build and release, ongoing SBOM and vulnerability evidence, not a one-time report
Validated first through a low risk, read-only hosted trial on a representative build, then deployed on-premises.
See How MOSA.ic.SCA Strengthens Embedded Software Assurance
Discover how MOSA.ic.SCA helps aerospace and defense teams generate repeatable SBOMs, prioritize target-relevant vulnerabilities, and maintain compliance evidence across connected and air-gapped environments.