Specification Overview

Explore how CycloneDX elevates supply chain transparency. Discover how its modular, extensible design delivers actionable insights.

The CycloneDX specification is a highly modular and extensible framework designed to represent a broad range of supply chain information with precision and flexibility. At its core, CycloneDX employs a robust object model capable of capturing components, services, dependencies, and relationships across various inventory types, including software, hardware, cryptographic assets, and operational configurations. This object model is structured to support detailed metadata, lifecycle stages, and extensible attributes, enabling organizations to adapt the specification to their unique needs without sacrificing interoperability.

Specification Details

TitleCycloneDX
Current Version1.7
DocumentationJSON XML Protobuf
Release Date2025-10-21
Media Types
vnd.cyclonedx+json
vnd.cyclonedx+xml
x.vnd.cyclonedx+protobuf
Developed By
OWASP Foundation
Ecma International
Standards
Published On2024-07-11
Technical Committee