SBCGA Implementation: Year 1 - Start With Visibility
- James W.
- 3 days ago
- 1 min read

You can't manage what you don't see.
SBCGA implementation begins with Year 1 foundation work:
Phase 1: Device Inventory
What connected devices does your building actually have?
Document: Model, manufacturer, installation date, firmware version
Tools: Physical walk-through, network scanning, BMS interrogation
Phase 2: Supportability Register
When does each device's support window close?
Create a timeline: which devices need re-contracting this year?
Set renewal alerts (contact vendors 12 months before support ends)
Phase 3: Vulnerability Tracking
Subscribe to vendor security advisories
Set up NIST CVE notifications for your devices
Create a simple register: device, CVE, patch status
This takes effort. It's not plug-and-play.
But without this foundation, you can't implement SBCGA systematically.
Years 2-4 build on this foundation. Operations, AI monitoring, supply chain verification, decommissioning protocols.
But it all starts with visibility.
Start with inventory. Know what you have. Everything else follows.
Read AC-146 for the full roadmap.

Comments