Skip to content

References & Resources

This page contains a curated list of external resources to help you on your SBOM journey.

SPDX (Software Package Data Exchange)

The official website for the SPDX standard. Visit website

CycloneDX

The official website for the CycloneDX standard. Visit website

NTIA: Software Bill of Materials

The website of the US National Telecommunications and Information Administration (NTIA) on SBOMs. Visit website

CISA: Software Bill of Materials

The website of the US Cybersecurity and Infrastructure Security Agency (CISA) on SBOMs. Visit website

FIRST: SBOM and CSAF/VEX Operational Framework

A comprehensive guide by FIRST on implementing SBOM and CSAF/VEX practices, covering the relationship between static SBOMs and dynamic vulnerability data. Download PDF

CISA: SBOM Sharing Primer

CISA’s guide on SBOM sharing roles (Producer, Distributor, Consumer), sharing mechanisms, and best practices for SBOM distribution. Download PDF

CISA: Types of SBOMs

Defines the six types of SBOMs (Design, Source, Build, Analyzed, Deployed, Runtime) and their appropriate use across the software lifecycle. Download PDF

CSAF: Common Security Advisory Framework

The OASIS standard for machine-readable security advisories, including VEX profiles for communicating vulnerability exploitability status. View specification

OWASP SCVS

The OWASP Software Component Verification Standard (SCVS) is a community-driven effort to establish a framework for verifying the security of software components. Visit website

SLSA

Supply-chain Levels for Software Artifacts (SLSA) is a security framework, a check-list of standards and controls to prevent tampering, improve integrity, and secure packages and infrastructure. Visit website

OpenChain Project

The OpenChain Project identifies key requirements of a quality open source compliance program to build trust in the open source supply chain. Visit website