CycloneDX

Know what’s inside. See how it connects. OWASP CycloneDX brings clarity to complex systems with an open standard for transparency across software, hardware, AI, and beyond.

Discover what system transparency can do for you.

About CycloneDX

CycloneDX Bill of Materials Specification (ECMA-424)

OWASP CycloneDX is a full-stack Bill of Materials (BOM) standard that provides advanced supply chain capabilities for cyber risk reduction. CycloneDX is an Ecma International standard published as ECMA-424. The OWASP Foundation and Ecma International Technical Committee for Software & System Transparency (TC54) drive the continued advancement of the specification.

The specification supports:

  • Software Bill of Materials (SBOM)

  • Software-as-a-Service Bill of Materials (SaaSBOM)

  • Hardware Bill of Materials (HBOM)

  • Machine Learning Bill of Materials (ML-BOM)

  • Cryptography Bill of Materials (CBOM)

  • Manufacturing Bill of Materials (MBOM)

  • Operations Bill of Materials (OBOM)

  • Vulnerability Disclosure Reports (VDR)

  • Vulnerability Exploitability eXchange (VEX)

  • CycloneDX Attestations (CDXA)

The CycloneDX project provides standards in JSON, XML, and Protocol Buffers, as well as a large collection of official and community supported tools that create or interoperate with the standard.

The projects website has many documented use cases and examples that provide a springboard to SBOM adoption.

The project operates as a meritocracy whose guiding principals reinforce its risk-based approach to standards development. The project encourages community participation in the development of the standard and supporting tools.

Strategic direction of the specification is managed by the CycloneDX Core Working Group, is backed by the OWASP Foundation, and is supported by the global information security community.

Project Leaders

Steve Springett

EmailLinkedIn

Patrick Dwyer

Email

Jeffry Hesse

Email

Jan Kowalleck

EmailLinkedIn

Matt Rutkowski

Email

Project Information

Flagship Project
Classification
Standards
Language
Specification
License
Apache-2.0
Contributors
1438
GitHub Stars
4897
OWASP Logo
OWASP is a nonprofit foundation improving software security through open-source projects, global communities, and education. All resources are free and open to everyone.
OWASP, the OWASP logo, and Global AppSec are registered trademarks and AppSec Days, AppSec California, AppSec Cali, SnowFROC, OWASP Boston Application Security Conference, and LASCON are trademarks of the OWASP Foundation, Inc.
© 2026, OWASP Foundation Inc. All rights reserved.