Software Supply Chain

CycloneDX

CycloneDX Bill of Materials

Community Global OWASP Since 2017

A bill-of-materials standard designed for security use cases, covering software, services, hardware, machine learning models and cryptographic assets, with VEX support for stating whether a vulnerability actually affects you.

The ML-BOM and CBOM profiles are directly regulatory: one documents model and dataset provenance, the other inventories cryptography ahead of post-quantum migration mandates.

At a glance

Category
Software Supply Chain
Jurisdiction
Global
Governance
OWASP
Status
CycloneDX v1.7, published as ECMA-424 (2nd edition, 2025); SBOM, SaaSBOM, ML-BOM, CBOM and VEX
First released
2017

Links

Related frameworks

Other entries under Software Supply Chain.

See CycloneDX in context

Open the interactive Data Landscape for Regulation to compare CycloneDX against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.