Two open formats dominate in practice. CycloneDX originates from the OWASP community and is standardized internationally through the Ecma committee TC54: version 1.6 was published in June 2024 as ECMA-424 (1st edition), and version 1.7, released in October 2025, was published in December 2025 as ECMA-424 (2nd edition) – with extended modeling for, among other things, cryptographic artifacts and ML models. SPDX is developed under the umbrella of the Linux Foundation; ISO/IEC 5962:2021 standardizes version 2.2.1, while the current specification 3.0.1 (December 2024) is going through the ISO process as ISO/IEC DIS 5962. SPDX has its roots in license compliance, whereas CycloneDX is more strongly geared toward security use cases – both satisfy the CRA requirement of a "commonly used and machine-readable format".
SBOM Management for the Software Supply Chain
How to generate, distribute and operationalize software bills of materials (SBOMs) in a standards-compliant way – from format selection and build integration to continuous vulnerability correlation.
A Software Bill of Materials (SBOM) is a machine-readable inventory of all components of a piece of software – analogous to the bill of materials in manufacturing. At the latest since incidents like Log4Shell, it has become clear that organizations without component transparency cannot answer whether and where they are affected by a new vulnerability. With the Cyber Resilience Act, the SBOM becomes a legal requirement in the EU for products with digital elements for the first time; in parallel, CISA and international partners redefined the minimum contents of an SBOM in July 2026. SBOM management involves more than generating a file once: it is an ongoing process of generation, distribution, enrichment and analysis across the entire product lifecycle.
From format standard to legal obligation
Tap a milestone to reveal the details.
CycloneDX 1.6 becomes ECMA-424
The specification originating from the OWASP community is standardized internationally through Ecma committee TC54: version 1.6 is published as ECMA-424 (1st edition); version 1.7, released in October 2025, follows in December 2025 as the 2nd edition.
Cyber Resilience Act enters into force
Regulation (EU) 2024/2847 takes effect. Annex I Part II requires a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies.
BSI TR-03183 Part 2, version 2.1.0
The BSI substantiates the CRA requirements with formal and subject-matter specifications per data field — including mapping recommendations to SPDX and CycloneDX and the treatment of virtual and referenced components.
2026 Minimum Elements for a SBOM
CISA, NSA, FBI and international partner agencies supersede the 2021 NTIA version. New additions include component hashes, license information, the generation tool and the generation context.
CRA main obligations apply
The main obligations of the Cyber Resilience Act apply; reporting obligations start as early as 11 September 2026. The SBOM is part of the technical documentation and must be provided to market surveillance authorities upon request.
The Essentials at a Glance
Six topic blocks — tap to expand.
SBOM management in four views
From format selection to regulatory obligations — pick a tab for details.
- CycloneDX originates from the OWASP community and is standardized through Ecma committee TC54 — version 1.7 was published in December 2025 as ECMA-424 (2nd edition), with extended modeling for cryptographic artifacts and ML models, among other things.
- SPDX is developed under the umbrella of the Linux Foundation; ISO/IEC 5962:2021 standardizes version 2.2.1, while the current specification 3.0.1 is going through the ISO process as ISO/IEC DIS 5962.
- SPDX has its roots in license compliance, whereas CycloneDX is more strongly geared toward security use cases — both satisfy the CRA requirement of a commonly used and machine-readable format.
- In 2021, the NTIA first defined minimum constituents in three categories: data fields, automation support and accompanying processes.
- The 2026 Minimum Elements from CISA, NSA, FBI and international partner agencies add component hashes, license information, the name of the generation tool and the generation context, among others.
- The minimum contents are explicitly a floor — depending on the use case, additional information is advisable.
- Continuous correlation with vulnerability data from sources such as NVD, OSV or GitHub Advisories enables an immediate answer, when a new CVE emerges, as to which products contain affected components.
- Since a vulnerable component does not automatically mean a vulnerable product, VEX complements the SBOM with machine-readable vendor statements about actual exploitability — CISA published minimum requirements for this in April 2023.
- CSAF 2.0 (an OASIS standard since November 2022, with its own VEX profile) and CycloneDX with embedded VEX serve as exchange formats; used correctly, the combination significantly reduces false positives.
- CRA Annex I Part II requires a software bill of materials in a commonly used, machine-readable format that covers at least the top-level dependencies.
- The SBOM is part of the technical documentation and must be provided to market surveillance authorities upon request; there is no obligation to publish it.
- Main obligations apply from 11 December 2027, reporting obligations already from 11 September 2026; BSI TR-03183 Part 2 (version 2.1.0, August 2025) substantiates the requirements per data field.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
ECMA-424: CycloneDX Bill of Materials Specification, 2nd Edition
International standard for CycloneDX v1.7 (adopted December 2025); the 1st edition of June 2024 standardized version 1.6.
ISO/IEC 5962:2021 – SPDX Specification V2.2.1
ISO standardization of the SPDX format in version 2.2.1; the current SPDX specification 3.0.1 is going through the ISO process as ISO/IEC DIS 5962.
2026 Minimum Elements for a Software Bill of Materials (SBOM)
Supersedes the 2021 NTIA Minimum Elements; adds, among others, component hashes, licenses, generation tool and generation context as minimum fields.
Verordnung (EU) 2024/2847 (Cyber Resilience Act)
Annex I Part II requires an SBOM in a commonly used, machine-readable format covering at least the top-level dependencies; main obligations from 11 Dec 2027.
BSI TR-03183 Teil 2: Software Bill of Materials (SBOM), Version 2.1.0
Formal and subject-matter SBOM specifications as an entry aid to the CRA, including field mapping to SPDX and CycloneDX (as of August 2025).
Dependency-Track Documentation
Documents the platform's core capabilities: consumption/production of CycloneDX SBOM and VEX, vulnerability sources, policy engine and API-first design.
Related Services
Implementing the CRA's SBOM obligations in a structured way?
We support you with format selection, build integration and setting up ongoing SBOM operations – from gap analysis to toolchain. Contact us for a no-obligation initial consultation.