Draft:CycloneDX
| CycloneDX | |
|---|---|
| Filename extension | .json, .xml |
| Internet media type | application/vnd.cyclonedx+json, application/vnd.cyclonedx+xml |
| Developed by | OWASP Foundation, Ecma International |
| Initial release | March 2018 |
| Latest release | 1.7 October 2025 |
| Type of format | Bill of materials |
| Extended from | JSON, XML, Protocol Buffers |
| Standard | ECMA-424 (2nd Edition) |
| Open format? | Yes |
| Free format? | Yes |
| Website | cyclonedx |
CycloneDX is an open standard for representing software bills of materials (SBOMs) and related forms of supply chain inventory. It originated in 2017 within the OWASP Foundation and was ratified as an international standard by Ecma International as ECMA-424 in 2024, with a second edition published in 2025.[1][2]
CycloneDX is one of the principal machine-readable standards identified in academic and industry literature for software supply chain transparency.[3][4][5][6] The format has been recommended in government cybersecurity guidance in the United States, Germany, the Netherlands, Singapore, and India, and has been adopted by major open source foundations including the Apache Software Foundation.[7][8][9][10][11][2]
History
[edit]CycloneDX was originally developed in 2017 to support OWASP Dependency-Track, an open source component analysis platform.[1] The initial design priorities were vulnerability identification, license compliance, and identification of outdated components. Academic surveys have noted that, unlike SPDX which evolved from license compliance use cases, CycloneDX was created specifically with software security in mind.[1][4][12]
CycloneDX joined the OWASP Foundation as a project in 2021. In May 2021, the United States Executive Order 14028 on Improving the Nation's Cybersecurity directed federal agencies to require machine-readable SBOMs from software suppliers, and subsequent guidance from the National Telecommunications and Information Administration (NTIA) identified CycloneDX as one of the acceptable SBOM formats.[12][13]
In December 2023, Ecma International established Technical Committee 54 (TC54) for Software and System Transparency to standardize CycloneDX and related specifications.[2] CycloneDX 1.6 was ratified by Ecma as ECMA-424 in 2024.[2] CycloneDX 1.7 was ratified as ECMA-424, 2nd edition, in December 2025 and entered the ISO/IEC JTC 1 fast-track standardization process.[2]
| Version | Release | Selected new capabilities |
|---|---|---|
| 1.0 | March 2018 | Initial release supporting software and hardware components |
| 1.1 | March 2019 | Component pedigree describing lineage including commits, patches, and modifications |
| 1.2 | May 2020 | Software Identification (SWID per ISO/IEC 19770-2:2015) support; services inventory |
| 1.3 | May 2021 | Composition completeness declarations |
| 1.4 | January 2022 | Vulnerability Exploitability eXchange (VEX) and Vulnerability Disclosure Report (VDR) support[14] |
| 1.5 | June 2023 | Machine Learning Bill of Materials (ML-BOM) and Manufacturing Bill of Materials (MBOM) |
| 1.6 | April 2024 | Cryptographic bill of materials (CBOM); attestation capabilities; ratified as ECMA-424 |
| 1.7 | October 2025 | Standardized cryptographic algorithm naming; improved license expressions; ratified as ECMA-424, 2nd edition[2] |
Capabilities
[edit]Academic studies of SBOM formats have characterized CycloneDX as designed primarily for automation. A 2024 taxonomy survey of SBOM generation approaches concluded that CycloneDX's format specification makes it well-suited as an automation target, while SPDX is more often used where human readability is the priority.[15] Comparative analyses in trade press have noted that CycloneDX uses a component-centric model and supports JSON, XML, and Protocol Buffers serializations.[12][13]
CycloneDX supports multiple types of bill of materials beyond software:[12][16]
- Software Bill of Materials (SBOM)
- Software-as-a-Service Bill of Materials (SaaSBOM)
- Hardware Bill of Materials (HBOM)
- Machine Learning Bill of Materials (ML-BOM)
- Cryptography Bill of Materials (CBOM)
- Operations Bill of Materials (OBOM)
- Manufacturing Bill of Materials (MBOM)
Vulnerability disclosure
[edit]CycloneDX defines two complementary structures for sharing vulnerability information: the Vulnerability Disclosure Report (VDR), an inventory of known vulnerabilities affecting components, and the Vulnerability Exploitability eXchange (VEX), which communicates whether a known vulnerability actually affects a product in its specific usage context.[14]
Cryptographic bill of materials
[edit]The Cryptographic Bill of Materials (CBOM) capability, introduced in CycloneDX 1.6, was developed by researchers and engineers at IBM Research and contributed to the specification.[17] CBOM extends the SBOM model to describe cryptographic assets and dependencies, supporting inventory and migration planning for post-quantum cryptography.[7] In June 2025, IBM donated its CBOM tooling, including CBOMkit, to the Linux Foundation.[18]
Research and tooling evaluation
[edit]CycloneDX has been the focus of multiple peer-reviewed empirical studies of SBOM tooling.
A 2023 study by researchers at KTH Royal Institute of Technology, published in IEEE Security & Privacy, examined six CycloneDX SBOM producers across 26 Java projects, finding significant variation in accuracy and completeness across tools and recommending specific clarifications to the standard to improve interoperability.[1] The same group subsequently published an expanded evaluation framework for SBOM tools in ACM Transactions on Software Engineering and Methodology in 2025.[19] In 2026, the KTH group introduced zkSBOM, a privacy-preserving SBOM sharing mechanism based on zero-knowledge sets, that allows software consumers to obtain cryptographic proof of whether a given vulnerable component is present in a supplier's SBOM without disclosing the full dependency list. The implementation supports the CycloneDX format, and the experimental evaluation generated CycloneDX SBOMs for end-to-end feasibility tests across four package ecosystems (Cargo, Go, Maven, and npm) and analyzed 43,940 real-world CycloneDX SBOMs from the Wild SBOMs dataset.[20]
A 2024 landscape study by researchers at Rochester Institute of Technology analyzed 84 open source and proprietary SBOM tools, identifying emerging use cases including vulnerability management and compliance verification.[21]
A 2024 ICSE study, "BOMs Away! Inside the Minds of Stakeholders," surveyed five categories of SBOM stakeholders and analyzed how CycloneDX and SPDX are used by tool developers, consumers, and standards contributors.[5] Earlier ICSE work by Xia et al. described CycloneDX as one of the two most adopted SBOM standards.[4]
In 2024, the Software Engineering Institute at Carnegie Mellon University conducted the SBOM Harmonization Plugfest, sponsored by the Cybersecurity and Infrastructure Security Agency. The study collected 243 SBOMs from 21 participants and analyzed sources of variation in tool outputs, noting that CycloneDX 1.6 had been ratified as an Ecma International standard for use across software, services, hardware, firmware, AI/ML, and cryptography domains.[22][23]
A 2025 comparative analysis of the SBOM tool ecosystems published as a preprint by researchers from the Lahore University of Management Sciences, Queen's University, the Indian Institute of Technology Ropar, and the University of Waterloo, examined 108 open source SBOM tools across the SPDX and CycloneDX ecosystems and compared use case coverage, project health, and community engagement.[24] A separate 2026 large-scale study analyzed the adherence gap between SBOM standards and the tools implementing them, with CycloneDX and SPDX as the two primary subjects.[25]
Adoption
[edit]In October 2023, IBM contributed two supply chain tools, SBOM Utility and License Scanner, to the CycloneDX project, in coverage by Dark Reading describing CycloneDX as one of the two primary SBOM standards.[16]
The Apache Software Foundation reported in its 2025 year-in-review that contributors to ASF projects had played an active role in shaping CycloneDX 1.7 and that the foundation had adopted CycloneDX and the related Package URL (ECMA-427) and Common Lifecycle Enumeration (ECMA-428) standards across its ecosystem; multiple major ASF projects, including Apache Hadoop, Apache Hive, and Apache HBase, publish CycloneDX SBOMs.[2][26]
Regulatory recognition
[edit]European Union (Germany)
[edit]The German Federal Office for Information Security (BSI) published Technical Guideline TR-03183 to support manufacturers in meeting the software transparency requirements of the EU Cyber Resilience Act.[27] Part 2 of the guideline, "Software Bill of Materials (SBOM)", specifies CycloneDX version 1.6 or later as one of the acceptable machine-readable SBOM formats and provides detailed JSON path mappings for required data fields.[8]
India
[edit]In July 2025, the Indian Computer Emergency Response Team (CERT-In) published Technical Guidelines covering five categories of bill of materials: SBOM, Quantum BOM (QBOM), Cryptographic BOM (CBOM), Artificial Intelligence BOM (AIBOM), and Hardware BOM (HBOM). The guidelines identify CycloneDX among the recommended formats for SBOM, CBOM/QBOM, AIBOM, and HBOM in government and public sector procurement.[11]
Netherlands
[edit]In January 2021, the Netherlands National Cyber Security Centre (NCSC-NL) published a 26-page report, prepared by Capgemini, on using SBOMs for cybersecurity. The report concluded that for automation purposes, CycloneDX is the format of choice for producing machine-readable SBOMs, citing its component identifier support (CPE, SWID, Package URL) and vulnerability schema extension.[9]
Singapore
[edit]In 2024, the Cyber Security Agency of Singapore (CSA) published an advisory on implementing SBOMs for vulnerability management, identifying CycloneDX as one of the acceptable formats for generation and signing of SBOMs in continuous integration pipelines.[10]
United States
[edit]Executive Order 14028, signed in May 2021, directed federal agencies to enhance software supply chain security, including through machine-readable SBOMs.[12] Subsequent NTIA guidance identified CycloneDX as one of the acceptable formats.[13]
In 2021, the National Telecommunications and Information Administration (NTIA) published a Survey of Existing SBOM Formats and Standards as part of its Multistakeholder Process on Software Component Transparency. The survey described CycloneDX as focused on automation and ease of adoption, with widespread use in security contexts, and noted its native support for multiple component identifiers including Package URL, CPE, and SWID.[28] In the same year, NTIA published the second edition of Framing Software Component Transparency, a foundational document defining SBOM concepts and baseline attributes that align with CycloneDX and SPDX.[29]
In September 2024, the Cybersecurity and Infrastructure Security Agency (CISA) published the third edition of Framing Software Component Transparency, updating and superseding the 2021 NTIA document. The 2024 edition expands SBOM baseline attributes, introduces minimum expected, recommended, and aspirational tiers for each attribute, and provides a mapping of these attributes to both the CycloneDX and SPDX formats.[6][30]
In December 2023, the National Cybersecurity Center of Excellence at NIST published SP 1800-38B, a practice guide on migration to post-quantum cryptography, which recommends CycloneDX for cryptographic bill of materials and states that the CycloneDX specification "provided the basis for the CBOM structure".[7]
The Food and Drug Administration has identified CycloneDX as one of the acceptable machine-readable SBOM formats in cybersecurity guidance for medical devices submitted under Section 524B of the Federal Food, Drug, and Cosmetic Act.[31]
Governance
[edit]CycloneDX is jointly stewarded by the OWASP Foundation and Ecma International TC54.[2] The CycloneDX Core Working Group manages day-to-day development of the specification, supported by feature-focused working groups. The specification is published under a royalty-free patent policy, with the reference JSON schemas distributed under the Apache License 2.0.[32]
See also
[edit]- Software bill of materials
- Software Package Data Exchange
- Cryptographic bill of materials
- Software composition analysis
- Supply chain attack
- Vulnerability management
- Post-quantum cryptography
- OWASP
References
[edit]- ^ a b c d Balliu, Musard; Baudry, Benoit; Bobadilla, Sofia; Ekstedt, Mathias; Monperrus, Martin; Ron, Javier; Sharma, Aman; Skoglund, Gabriel; Soto-Valero, César; Wittlinger, Martin (2023). "Challenges of Producing Software Bill of Materials for Java". IEEE Security & Privacy. 21 (6): 12–23. Bibcode:2023ISPri..21f..12B. doi:10.1109/MSEC.2023.3302956.
- ^ a b c d e f g h "ASF 2025 Year in Review: Building for Resilience and Growth". Apache Software Foundation. 19 December 2025. Retrieved 2026-05-17.
- ^ Greengard, Samuel (20 July 2023). "A Nested Inventory for Software Security, Supply Chain Risk Management". Communications of the ACM. Retrieved 2026-05-17.
- ^ a b c Xia, Boming; Bi, Tingting; Xing, Zhenchang; Lu, Qinghua; Zhu, Liming (2023). "An Empirical Study on Software Bill of Materials: Where We Stand and the Road Ahead". arXiv:2301.05362 [cs.SE].
- ^ a b Bi, Tingting; Xia, Boming; Xing, Zhenchang; Lu, Qinghua; Zhu, Liming (2024). "BOMs Away! Inside the Minds of Stakeholders: A Comprehensive Study of Bills of Materials for Software Systems". Proceedings of the 46th International Conference on Software Engineering (ICSE). Association for Computing Machinery.
- ^ a b Framing Software Component Transparency: Establishing a Common Software Bill of Materials (SBOM) (PDF) (Report) (3rd ed.). Cybersecurity and Infrastructure Security Agency. September 2024. Retrieved 2026-05-17.
- ^ a b c Migration to Post-Quantum Cryptography: Quantum Readiness: Cryptographic Discovery (NIST SP 1800-38B) (PDF) (Report). National Institute of Standards and Technology. December 2023. Retrieved 2026-05-17.
- ^ a b "BSI TR-03183-2: Software Bill of Materials (SBOM)". German Federal Office for Information Security. Retrieved 2026-05-17.
- ^ a b Using the Software Bill of Materials for Enhancing Cybersecurity (Report). National Cyber Security Centre (Netherlands). January 2021. Retrieved 2026-05-17.
- ^ a b Advisory on Implementation of Software Bill of Materials for Vulnerability Management (Report). Cyber Security Agency of Singapore. 2024. Retrieved 2026-05-17.
- ^ a b Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM (PDF) (Report). Indian Computer Emergency Response Team. 9 July 2025. Retrieved 2026-05-17.
- ^ a b c d e Hughes, Chris (8 August 2022). "SBOM formats SPDX and CycloneDX compared". CSO Online. Retrieved 2026-05-17.
- ^ a b c "SBOM formats compared: CycloneDX vs. SPDX vs. SWID Tags". TechTarget. Retrieved 2026-05-17.
- ^ a b "VDR, VEX, OpenVEX and CSAF". Open Source Security Foundation. 7 September 2023. Retrieved 2026-05-17.
- ^ Verma Sehgal, Vandana; Ambili, P. S. (2024). "A Taxonomy and Survey of Software Bill of Materials (SBOM) Generation Approaches". Proceedings of the International Conference on Data Science, Machine Learning and Artificial Intelligence. Springer.
- ^ a b Schwartz, Jeffrey (17 October 2023). "IBM Contributes Supply Chain Security Tools to OWASP". Dark Reading. Retrieved 2026-05-17.
- ^ Hess, Basil; Koertge, Nicklas (14 May 2024). "Standardization of Cryptography Bill of Materials in OWASP CycloneDX". ETSI/IQC Quantum Safe Cryptography Conference 2024.
- ^ "IBM is donating its CBOM toolset to the Linux Foundation". IBM Research. 24 June 2025. Retrieved 2026-05-17.
- ^ Balliu, Musard; Baudry, Benoit; et al. (2025). "More Than Meets the Eye: On Evaluating SBOM Tools In Java". ACM Transactions on Software Engineering and Methodology 3766073. doi:10.1145/3766073.
- ^ Sorger, Tom; Cornelissen, Eric; Sharma, Aman; Ron, Javier; Balliu, Musard; Monperrus, Martin (30 April 2026). "zkSBOM: Privacy-Preserving SBOM Sharing with Zero-Knowledge Sets". arXiv:2605.00076 [cs.CR].
- ^ Mirakhorli, Mehdi; Garcia, Derek; Dillon, Schuyler; Laporte, Kevin; Morrison, Matthew; Lu, Henry; Koscinski, Viktoria; Enoch, Christopher (17 February 2024). "A Landscape Study of Open Source and Proprietary Tools for Software Bill of Materials (SBOM)". arXiv:2402.11151 [cs.SE].
- ^ Software Bill of Materials (SBOM) Harmonization Plugfest 2024 (PDF) (Report). Software Engineering Institute, Carnegie Mellon University. July 2025. CMU/SEI-2025-SR-002. Retrieved 2026-05-17.
- ^ "Study Finds Key Causes of Divergence in Software Bills of Materials". Software Engineering Institute. 11 August 2025. Retrieved 2026-05-17.
- ^ Bangash, Abdul Ali; Ge, Tongxu; Zhao, Zhimin; Singh, Arshdeep; Wang, Zitao; Adams, Bram (2025). "The State of the SBOM Tool Ecosystems: A Comparative Analysis of SPDX and CycloneDX". arXiv:2512.21781 [cs.SE].
- ^ Wang, Chengjie; Wu, Jingzheng; Lyu, Hao; Ling, Xiang; Luo, Tianyue; Wu, Yanjun; Zhao, Chen (2026). "A Large Scale Empirical Analysis on the Adherence Gap between Standards and Tools in SBOM". ACM Transactions on Software Engineering and Methodology 3788692. arXiv:2601.05622. doi:10.1145/3788692.
- ^ "SBOM – Community Development". Apache Software Foundation. Retrieved 2026-05-17.
- ^ "Technical Guideline TR-03183 Cyber Resilience Requirements for Manufacturers and Products". German Federal Office for Information Security. Retrieved 2026-05-17.
- ^ Survey of Existing SBOM Formats and Standards (PDF) (Report). National Telecommunications and Information Administration. 2021. Retrieved 2026-05-17.
- ^ Framing Software Component Transparency: Establishing a Common Software Bill of Materials (SBOM) (PDF) (Report) (2nd ed.). National Telecommunications and Information Administration. 21 October 2021. Retrieved 2026-05-17.
- ^ Muncaster, Phil (October 2024). "CISA Urges Improvements in US Software Supply Chain Transparency". Infosecurity Magazine. Retrieved 2026-05-17.
- ^ "FDA Medical Device SBOM Requirements". sbomify. 9 January 2026. Retrieved 2026-05-17.
- ^ "CycloneDX Specification". CycloneDX. Retrieved 2026-05-17 – via GitHub.
External links
[edit]| Part of a series on |
| Software development |
|---|
Category:Computer file formats Category:Computer security standards Category:Data serialization formats Category:Ecma standards Category:Free software Category:Open formats Category:Post-quantum cryptography Category:Software development process Category:Supply chain management