PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Explainer3 min readReviewed September 202612 sources

SBOM validation: completeness, format conformance and quality scoring

A valid SBOM is not necessarily a useful one. Validation has four layers: format conformance, field completeness, accuracy and quality. This explainer defines each and the baselines they are measured against.

Key takeaways
  • Schema validation proves a document is well-formed, not that it is complete or correct.
  • Completeness is measured against a baseline such as NTIA 2021, CISA 2026, CERT-In's 21 fields or BSI TR-03183-2.
  • Accuracy requires comparing the SBOM with the artefact it claims to describe.
  • Quality scores summarise usefulness and are best used as trends and gates, not absolute verdicts.

Why validation matters

SBOMs arrive from many generators and suppliers, and their quality varies. CERT-In lists validating the SBOM to ensure its integrity among supplier objectives [1], and SEBI expects SBOMs for all core and critical software [2]. An SBOM that fails silently, for example by missing a lockfile ecosystem, gives false assurance. Validation has four layers.

1. Format conformance

Does the document conform to the schema of the format and version it declares? CycloneDX CLI validates against CycloneDX versions up to 1.7 and can return a non-zero exit code on errors [3]. SPDX tools-python validates SPDX 2.2 and 2.3 documents in several serialisations [4]. Conformance is necessary but weak: an empty component list can be valid.

2. Field completeness

Does each component carry the fields your baseline requires? Baselines differ:

BaselineEmphasis
NTIA 2021Seven fields: supplier, name, version, unique identifier, dependency relationship, author, timestamp [5]
CISA FSCT, 3rd edition (2024)Adds licence and copyright holder; minimum, recommended and aspirational levels [6]
CISA 2026 Minimum ElementsSeven SBOM metadata and ten component elements, including hash, hash algorithm, licence, tool and generation context [7]
CERT-In v2.021 fields including vulnerabilities, patch status, EOL, criticality and usage restrictions [1]
BSI TR-03183-2 v2.1.0CycloneDX 1.6+ or SPDX 3.0.1+, SHA-512 hashes, executable, archive and structured properties [8]

The NTIA Conformance Checker tests SPDX documents against NTIA and FSCT minimums [9]. Completeness should be measured per component, since one component missing a supplier is a different problem from all of them missing one.

3. Unknowns versus omissions

An empty field can mean "does not exist", "unknown" or "withheld". The NTIA report asks authors to state explicitly where dependency information is unknown [10]. CISA's framing document distinguishes missing from inapplicable data and says redaction should occur only when contractually required [6], and the 2026 elements require withheld data to be distinguishable from unknown data [7]. Validators should treat declared unknowns differently from silent gaps.

4. Accuracy

Does the SBOM describe the artefact it claims to? Checks include matching the declared hash against the delivered artefact, comparing component counts against an independent analysis of the same image or binary, and confirming versions against lockfiles. CISA notes that analysed SBOMs can be used to verify SBOMs from other sources [11]. Signature verification confirms the SBOM came from its stated author; CycloneDX CLI supports signing and verifying BOMs [3].

Quality scoring

Quality scores summarise usefulness. sbomqs scores SPDX and CycloneDX SBOMs from 0 to 10 across categories including identification, provenance, integrity, completeness, licensing and structure, and runs compliance profiles such as NTIA and BSI TR-03183-2 [12]. Scores are most useful as a pipeline gate (for example, reject supplier SBOMs below a threshold) and as a trend per supplier. They do not replace accuracy checks.

Where to validate

  • At generation, in CI/CD, so failures block a release.
  • At intake, before a supplier SBOM enters your inventory.
  • Periodically, because time-sensitive fields such as vulnerabilities, patch status and EOL date go stale [1].

For step-by-step commands, see how to validate an SBOM; for field detail, see the CERT-In 21 fields.

How IntelliXBOM helps

IntelliXBOM validates CycloneDX and SPDX SBOMs against configurable required-field policies, including CERT-In's list, on generation and on intake. It flags missing and stale fields, keeps validation results with each SBOM version, and includes them in timestamped compliance evidence.

Frequently asked questions

What does it mean to validate an SBOM?

It means checking that the SBOM conforms to its format's schema, contains the fields a baseline requires, and accurately describes the artefact it claims to describe. Quality scoring can then summarise how useful it is.

Is schema validation enough?

No. A document can pass schema validation with missing suppliers, hashes or dependencies. Field completeness and accuracy checks are needed as well.

Which baseline should I validate against?

Use the baseline your regulators and customers name. Indian organisations commonly use CERT-In's 21 fields, U.S.-facing suppliers the CISA 2026 elements, and EU manufacturers may look at BSI TR-03183-2.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (June 2025)SEBIwww.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
  3. CycloneDX CLICycloneDX/cyclonedx-cli (GitHub)github.com/CycloneDX/cyclonedx-cli
  4. SPDX tools-pythonSPDX (GitHub)github.com/spdx/tools-python
  5. The Minimum Elements for a Software Bill of Materials (SBOM), July 2021NTIA, U.S. Department of Commercewww.ntia.gov/report/2021/minimum-elements-software-bill-materials-sbom
  6. CISA Releases Guidance on Minimum Expectations for Software Bill of MaterialsCovington & Burling, Inside Government Contractswww.insidegovernmentcontracts.com/2024/11/cisa-releases-guidance-on-minimum-expectations-for-software-bill-of-materials/
  7. CISA Releases the 2026 SBOM Minimum ElementsFOSSAfossa.com/blog/cisa-releases-2026-minimum-sbom-elements/
  8. BSI TR-03183-2: SBOM Requirements (v2.1.0)sbomifysbomify.com/compliance/bsi-tr-03183/
  9. NTIA Conformance CheckerSPDX (GitHub)github.com/spdx/ntia-conformance-checker
  10. The Minimum Elements for a Software Bill of Materials (full report, PDF)NTIA, U.S. Department of Commercewww.ntia.gov/files/ntia/publications/sbom_minimum_elements_report.pdf
  11. Types of Software Bill of Material (SBOM) Documents (2023)CISAwww.cisa.gov/sites/default/files/2023-04/sbom-types-document-508c.pdf
  12. sbomqs, SBOM quality score and compliance checkssbomqs (GitHub)github.com/interlynk-io/sbomqs

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related SBOM guides

Across the BOM Suite

Put your SBOM under governance.Software transparency with continuous correlation and timestamped evidence.