PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Comparison3 min readReviewed September 202611 sources

SPDX 3.0 AI profile vs CycloneDX ML-BOM

Both major BOM standards can describe AI models and datasets, but they model them differently. CycloneDX puts a model card on a component; SPDX 3.0 adds AI and Dataset profiles with their own classes.

Key takeaways
  • CycloneDX added ML-BOM in v1.5 (June 2023); the current release is v1.7 (October 2025).
  • SPDX 3.0 (April 2024) introduced AI and Dataset profiles with AIPackage and DatasetPackage classes.
  • CycloneDX groups model information in a modelCard object; SPDX uses flat properties on AI and dataset packages.
  • SPDX 3 validation uses JSON Schema plus SHACL; CycloneDX uses JSON or XML schema.

Background

CycloneDX is an OWASP standard, also published by Ecma as ECMA-424. Version 1.5, released on 26 June 2023, introduced machine-learning BOM support [1]. Version 1.7 was released on 21 October 2025 and was expected to be ratified as ECMA-424 2nd edition [2].

SPDX is a Linux Foundation standard. SPDX 3.0, released on 16 April 2024, restructured the specification into profiles, including profiles for AI model training and characterisation and for dataset provenance [3]. For the general format comparison, see CycloneDX vs SPDX.

How each models a machine-learning model

CycloneDX represents a model as a component of type machine-learning-model with a modelCard. The card has three parts [4]:

  • modelParameters: approach, task, architecture family and name, datasets, inputs and outputs;
  • quantitativeAnalysis: performance metrics and graphics;
  • considerations: users, use cases, technical limitations, performance trade-offs, ethical and environmental considerations, fairness assessments.

SPDX 3.0 uses an AIPackage class, which inherits package properties such as name, version, supplier and download location, and adds AI properties including typeOfModel, domain, hyperparameter, informationAboutTraining, informationAboutApplication, metric, metricDecisionThreshold, limitation, modelExplainability, safetyRiskAssessment, standardCompliance, energyConsumption, autonomyType and useSensitivePersonalInformation [5].

How each models a dataset

CycloneDX uses a component of type data, referenced from a model card's datasets [4]. SPDX 3.0 has a DatasetPackage class with properties such as datasetType, dataCollectionProcess, dataPreprocessing, datasetSize, knownBias, hasSensitivePersonalInformation, anonymizationMethodUsed, confidentialityLevel, intendedUse and datasetUpdateMechanism [6].

Comparison

AspectCycloneDX ML-BOMSPDX 3.0 AI and Dataset profiles
First release with AI supportv1.5, June 20233.0, April 2024
Model representationComponent plus nested modelCardAIPackage class with flat properties
Dataset representationdata componentDatasetPackage class
Performance metricsquantitativeAnalysis.performanceMetricsmetric, metricDecisionThreshold
Limitations and useconsiderationslimitation, informationAboutApplication
Safety and riskEthical considerations, fairness assessmentssafetyRiskAssessment, autonomyType
Personal dataRecorded through dataset and consideration fieldsuseSensitivePersonalInformation, hasSensitivePersonalInformation
EnergyEnvironmental considerationsenergyConsumption
SerialisationJSON, XML, Protocol BuffersJSON-LD
ValidationSchema; CycloneDX CLI supports 1.0 to 1.7JSON Schema plus SHACL

Validation sources: CycloneDX CLI [7] and SPDX's JSON-LD validation guidance [8].

Tooling maturity

Open-source generators currently lean towards CycloneDX: the OWASP AIBOM Generator emits CycloneDX 1.6 [9]. On the SPDX side, spdx3-validate checks SPDX 3 documents, while the SPDX tools-python library describes its 3.0 support as experimental [10]. A Linux Foundation Research report on implementing AI BOMs with SPDX 3.0 notes that adoption is still at an early stage [11].

Which to choose

  • Choose CycloneDX if your software SBOMs are already CycloneDX, if you want model-card content in a nested object, or if you need broad open-source generator support today.
  • Choose SPDX 3.0 if your organisation standardises on SPDX, if you want explicit safety, autonomy and personal-data properties, or if you work in linked-data tooling.
  • Either satisfies CERT-In, which names both formats (CERT-In AIBOM requirements).

Interoperability tips

  • Agree a field mapping with suppliers before exchanging AIBOMs, especially for metrics, limitations and dataset provenance.
  • Keep the original supplier file alongside any converted copy, so nothing is lost if a conversion drops AI-specific fields.
  • Use stable identifiers for models and datasets, such as a registry URL plus revision, so the same component can be matched across formats.
  • Validate after conversion, not only before it.

How IntelliXBOM helps

IntelliXBOM generates and ingests AIBOMs in both CycloneDX and SPDX, so suppliers can deliver in either. It validates each against the same required-field policy and keeps version history and diffs across formats.

Frequently asked questions

Does SPDX support AI models?

Yes. SPDX 3.0, released in April 2024, added AI and Dataset profiles. The AIPackage class describes models with properties such as typeOfModel, metric and limitation, and DatasetPackage describes training data.

What is a CycloneDX ML-BOM?

It is CycloneDX's machine-learning bill of materials capability, introduced in v1.5. Models are components of type machine-learning-model with a modelCard covering parameters, quantitative analysis and considerations.

Can I convert between SPDX AI and CycloneDX ML-BOM?

Core identity fields map well, but the AI structures differ: CycloneDX nests a model card, while SPDX uses flat properties. Test any conversion on AI-specific fields before relying on it.

Sources

  1. Introducing OWASP CycloneDX v1.5 (26 June 2023)OWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.5-released/
  2. CycloneDX v1.7 release announcement (21 October 2025)OWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.7-released/
  3. SPDX 3.0 release announcement (16 April 2024)Linux Foundationwww.linuxfoundation.org/press/spdx-3-revolutionizes-software-management-in-systems-with-enhanced-functionality-and-streamlined-use-cases
  4. CycloneDX v1.6 JSON ReferenceOWASP CycloneDXcyclonedx.org/docs/1.6/json/
  5. SPDX 3.0.1 specification: AI profile, AIPackage classSPDX / Linux Foundationspdx.github.io/spdx-spec/v3.0.1/model/AI/Classes/AIPackage/
  6. SPDX 3.0.1 specification: Dataset profile, DatasetPackage classSPDX / Linux Foundationspdx.github.io/spdx-spec/v3.0.1/model/Dataset/Classes/DatasetPackage/
  7. CycloneDX CLICycloneDX (GitHub)github.com/CycloneDX/cyclonedx-cli
  8. Validating SPDX 3 JSON-LD documentsSPDX spdx-3-model (GitHub)github.com/spdx/spdx-3-model/blob/develop/serialization/jsonld/validation.md
  9. OWASP AIBOM GeneratorOWASP Gen AI Security Project (GitHub)github.com/GenAI-Security-Project/aibom-generator
  10. SPDX tools-pythonSPDX (GitHub)github.com/spdx/tools-python
  11. Implementing AI Bill of Materials (AI BOM) with SPDX 3.0Linux Foundation Researchwww.linuxfoundation.org/hubfs/LF%20Research/lfr_spdx_aibom_102524a.pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related AIBOM guides

Across the BOM Suite

Put your AIBOM under governance.AI supply-chain transparency with continuous correlation and timestamped evidence.