CycloneDX vs SPDX: comparing the two SBOM standards
CycloneDX and SPDX are the two SBOM formats named by CERT-In, CISA and BSI. They overlap heavily but come from different traditions. This comparison sets out the differences that matter in practice.
- Both formats are international standards: CycloneDX as ECMA-424, SPDX 2.2.1 as ISO/IEC 5962:2021.
- CycloneDX originated in security use cases and covers SBOM, CBOM, HBOM, ML-BOM, VEX and more in one specification.
- SPDX originated in licence compliance; SPDX 3.0 adds Security, Build, AI and Dataset profiles.
- Regulators accept either, so the practical answer is to accept both and normalise internally.
The short answer
Both are acceptable. CERT-In names SPDX and CycloneDX as the formats for generating and consuming SBOMs [1], the 2026 CISA Minimum Elements refer to both [2], and BSI TR-03183-2 accepts CycloneDX 1.6 or later and SPDX 3.0.1 or later [3]. The choice mostly depends on your use cases, your tools and what your customers ask for.
Comparison
| CycloneDX | SPDX | |
|---|---|---|
| Steward | OWASP, with Ecma International TC54 [4] | Linux Foundation [5] |
| International standard | ECMA-424 (v1.6 ratified June 2024) [4] | ISO/IEC 5962:2021 (SPDX 2.2.1) [5] |
| Latest version | 1.7, released 21 October 2025 [6] | 3.0 released April 2024; 3.0.1 specification published [5][7] |
| Origin | Security and supply-chain risk | Licence compliance, now broader |
| BOM types | SBOM, SaaSBOM, HBOM, CBOM, ML-BOM, OBOM, VDR, VEX, attestations [8] | Profiles: Core, Software, Security, Licensing, Dataset, AI, Build, Lite and others [7] |
| VEX | Embedded or standalone [9] | VEX assessment relationships in the Security profile [7] |
| Serialisation | JSON, XML, Protocol Buffers [8] | SPDX 2.x: tag-value, RDF, JSON, YAML, XML [10]; SPDX 3.0 uses a new model |
| Licence expressions | Uses SPDX licence identifiers | Defines the SPDX Licence List [5] |
Where CycloneDX tends to fit
CycloneDX covers several BOM types within one specification, which suits organisations building a combined inventory of software, cryptography, hardware and machine-learning models [8]. Its CBOM capability has become a reference for cryptographic inventories; see SBOM vs CBOM. VEX can be embedded in or separate from the BOM [9].
Where SPDX tends to fit
SPDX's licence model and licence list are widely used in open-source compliance, and its ISO status is often cited in procurement [5]. SPDX 3.0 restructured the specification into profiles, adding Security, AI and Dataset coverage [7]. Organisations with established licence-compliance programmes often already produce SPDX.
Versions matter more than the brand
Consumers rarely fail on "CycloneDX or SPDX"; they fail on versions. SPDX 3.0 is a significant change from 2.x, and tool support is still catching up. SPDX tools-python, for example, fully validates 2.2 and 2.3 and offers experimental write-only support for 3.0 [10]. BSI's minimum versions (CycloneDX 1.6, SPDX 3.0.1) will rule out older documents [3]. Agree versions with suppliers and customers explicitly.
Converting between them
Conversion is possible but lossy. CycloneDX CLI converts to and from SPDX JSON 2.3 and warns that converting between the formats "can result in the loss of some information" [11]. protobom provides a format-neutral representation for reading and writing both [12]. Keep the original document as received and store conversions as derived copies.
Scenario guide
| If your priority is | Consider |
|---|---|
| One model for software, crypto, hardware and ML inventories | CycloneDX, which covers these BOM types in one specification [8] |
| Open-source licence compliance with established tooling | SPDX, whose licence list is the common reference [5] |
| Supplying German or EU customers who cite BSI TR-03183-2 | Either, at CycloneDX 1.6+ or SPDX 3.0.1+ [3] |
| Supplying Indian government or SEBI-regulated customers | Either; CERT-In names both [1] |
How to choose
- Accept both from suppliers; do not reject a valid SBOM on format alone.
- Pick one internal generation format based on your tools and main use case.
- Publish in whichever format each customer or regulator requests.
- Validate fields, not just format; see SBOM validation.
How IntelliXBOM helps
IntelliXBOM generates and ingests both CycloneDX and SPDX, keeps each document as received with its version history, and validates both against the same required-field policies. Components from either format are correlated in one inventory with vulnerabilities, licences, end-of-life data and business services.
Frequently asked questions
Is CycloneDX or SPDX better?
Neither is better in general. CycloneDX covers more BOM types in one specification and has a security focus, while SPDX has deep licence-compliance roots and ISO standardisation; both are accepted by CERT-In and CISA.
Can I convert CycloneDX to SPDX?
Yes, with tools such as CycloneDX CLI or protobom. Conversion can lose information because the data models differ, so keep the original document.
Which format does CERT-In require?
CERT-In names both SPDX and CycloneDX as the standard machine-readable formats for SBOMs. It does not require one over the other.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- CISA Releases the 2026 SBOM Minimum ElementsFOSSAfossa.com/blog/cisa-releases-2026-minimum-sbom-elements/
- BSI TR-03183-2: SBOM Requirements (v2.1.0)sbomifysbomify.com/compliance/bsi-tr-03183/
- CycloneDX v1.6: Now an Ecma International Standard (ECMA-424)OWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.6-now-an-ecma-international-standard/
- SPDX OverviewSPDX, Linux Foundationspdx.dev/about/overview/
- CycloneDX v1.7 ReleasedOWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.7-released/
- The System Package Data Exchange (SPDX) Specification Version 3.0.1SPDX, Linux Foundationspdx.github.io/spdx-spec/v3.0.1/
- CycloneDX Specification OverviewOWASP CycloneDXcyclonedx.org/specification/overview/
- Vulnerability Exploitability eXchange (VEX)OWASP CycloneDXcyclonedx.org/capabilities/vex/
- SPDX tools-pythonSPDX (GitHub)github.com/spdx/tools-python
- CycloneDX CLICycloneDX/cyclonedx-cli (GitHub)github.com/CycloneDX/cyclonedx-cli
- protobom, format-neutral SBOM representationOpenSSF / protobom (GitHub)github.com/protobom/protobom
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.