What CycloneDX Bill of Materials Specification Version 1.7 (OWASP Foundation + Ecma International TC54, Components, Services, Dependencies, Vulnerabilities VEX, Formulations, Declarations, JSON/XML/Protobuf) requires
CycloneDX is a lightweight, full-stack Bill of Materials (BOM) standard developed by the OWASP Foundation and standardised through Ecma International's TC54 Technical Committee. The current version is CycloneDX 1.7, released on 21 October 2025. CycloneDX supports multiple BOM types beyond traditional SBOM: Software Bill of Materials (SBOM), Hardware Bill of Materials (HBOM), AI/ML Bill of Materials (ML-BOM, for models, datasets, parameters, training context), Software-as-a-Service Bill of Materials (SaaSBOM, for services and APIs), Operations Bill of Materials (OBOM, for runtime configuration), and Cryptography Bill of Materials (CBOM, for cryptographic assets and post-quantum risk). The specification supports first-party and third-party components with component types including application, framework, library, container, platform, operating-system, device, device-driver, firmware, file, machine-learning-model, and data. The dependency graph represents direct and transitive relationships including services-to-services dependencies. Services represent external APIs with endpoint URIs, authentication requirements, and trust boundary traversals. Vulnerabilities support Vulnerability Exploitability eXchange (VEX) for stating exploitability status of known vulnerabilities (affected, not_affected with justification, fixed, under_investigation). Formulations describe manufacturing and deployment processes via formulas, workflows, tasks, and steps. Declarations capture conformance attestations to standards including the EU Cyber Resilience Act (CRA), with claims, counter-claims, evidence, and digital signatures. CycloneDX serialisation formats are JSON, XML, and Protocol Buffers with registered IANA media types. CycloneDX is one of the two SBOM formats recognised by the US NTIA Minimum Elements for SBOM under EO 14028 and OMB Memorandum M-22-18, alongside SPDX.
Pillar: Cybersecurity · Authority: OWASP Foundation; Ecma International TC54 · Version: 1.0.0 · Last updated:
Primary source: https://cyclonedx.org/specification/overview/
SHA-256 integrity: 1836febd4d4a2d945dfb376469e1c5dc78637d5f34b5402a52c69b21a00d8c85
Primary Citations — 8 traced to source
- CycloneDX Bill of Materials Specification, OWASP Foundation and Ecma International TC54, canonical specification at cyclonedx.org/specification/; current version 1.7 released 21 October 2025; the project is 'Developed By OWASP Foundation' with international standardisation through 'Ecma International TC54'.
- CycloneDX supported BOM types: SBOM Software Bill of Materials; HBOM Hardware Bill of Materials; ML-BOM Machine Learning Bill of Materials (models, datasets, training parameters); SaaSBOM Software-as-a-Service Bill of Materials; OBOM Operations Bill of Materials (runtime configuration); CBOM Cryptography Bill of Materials (algorithms, keys, post-quantum risk).
+ 6 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/cyclonedx-1-7-owasp-ecma-sbom-standard.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/cyclonedx-1-7-owasp-ecma-sbom-standard.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/cyclonedx-1-7-owasp-ecma-sbom-standard
- Back to registry: Browse all 10,085 compliance nodes