Software Supply Chain
CycloneDX
CycloneDX Bill of Materials
A bill-of-materials standard designed for security use cases, covering software, services, hardware, machine learning models and cryptographic assets, with VEX support for stating whether a vulnerability actually affects you.
The ML-BOM and CBOM profiles are directly regulatory: one documents model and dataset provenance, the other inventories cryptography ahead of post-quantum migration mandates.
At a glance
- Category
- Software Supply Chain
- Jurisdiction
- Global
- Governance
- OWASP
- Status
- CycloneDX v1.7, published as ECMA-424 (2nd edition, 2025); SBOM, SaaSBOM, ML-BOM, CBOM and VEX
- First released
- 2017
Links
Related frameworks
Other entries under Software Supply Chain.
- SPDX: System Package Data Exchange
- SLSA: Supply-chain Levels for Software Artifacts
- Sigstore
- in-toto: in-toto Attestation Framework
See CycloneDX in context
Open the interactive Data Landscape for Regulation to compare CycloneDX against every other framework, or grab the raw JSON. Certification schemes and editions move — follow the source links before relying on this page.