Current versions and standardization
SPDX’s stable specification resolves to 3.0.1. The project’s January 2026 SPDX 3.1 announcement is a release candidate for review. SPDX 2.3 remains relevant when testing existing integrations. ISO/IEC 5962:2021 represents the earlier SPDX standardization; do not present that year’s ISO edition as certification of every 3.x feature.
Source: SPDX · Stable specification 3.0.1.
Source: SPDX · Specifications and ISO status.
Source: SPDX · 3.1 release candidate announcement.
CycloneDX’s published overview lists 1.7. Ecma’s ECMA-424 second edition, December 2025, defines 1.7. CycloneDX 2.0 has been announced as upcoming; this guide does not treat that announcement as the released interoperability target.
Source: CycloneDX · Specification overview.
Source: Ecma International · ECMA-424.
Compare the data models
| Dimension | SPDX 3.0.1 | CycloneDX 1.7 |
|---|---|---|
| Governance | Linux Foundation SPDX community | OWASP CycloneDX project; Ecma standardization |
| Model | Elements and typed relationships organized into profiles | BOM object model with components, services and references |
| Software composition | Packages, files, snippets and relationships | Components and dependency graph |
| Licensing | Simple and expanded licensing profiles; declared and concluded information | License information, expressions and evidence in the BOM |
| Security | Security profile represents vulnerabilities and contextual assessments | Vulnerability data and analysis, including VEX |
| Broader use cases | Build, AI and dataset profiles | Hardware, cryptographic assets, services, ML and attestations |
| Representations | 3.x model supports JSON-LD; distinguish 2.x serialization support | JSON, XML and Protobuf documented by the project |
Source: SPDX · Specification scope.
Source: CycloneDX · Specification overview · Specification overview.
Licensing, build evidence and security need separate tests
SPDX distinguishes declared license information from the author’s concluded license assessment. Its Build profile describes a build’s inputs, outputs and related agents or tools. A tool supporting a software inventory does not thereby demonstrate every licensing or build-profile capability.
Source: SPDX · Licensing profile.
Source: SPDX · Build profile.
CycloneDX can carry services, cryptographic information and attestations. Confirm whether your tool produces these fields, ingests them, displays them, exposes them through an API and preserves them on export. A format’s expressive capacity and a platform’s implemented behavior are different things.
For either format, test vulnerability and VEX interpretation with a specific product release. A field surviving import is insufficient if the receiving tool ignores its meaning or associates it with the wrong component.
Ask what “supports the format” means
| Claim to test | Evidence to request |
|---|---|
| Generation | Produce the agreed version from your representative artifact. |
| Ingestion | Load your supplier fixtures, including optional fields and unusual identities. |
| Validation | Identify the failing path and rule in a deliberately invalid document. |
| Conversion | Compare fields and relationship meaning before and after a round trip. |
| Export | Return original and normalized data without support intervention. |
| Extensions | Document retained, interpreted, dropped and unsupported fields. |
| Version migration | Show coexistence and rollback for old and new schema versions. |
Maintain an interoperability corpus. Include multiple namespaces, shared dependencies, incomplete relationships, non-public components, unknown versions, and an updated revision of the same inventory. Record losses as structured findings. Do not assume conversions are lossless because the resulting JSON parses.
A decision framework
- Start with the consumer: regulator, customer, internal platform or partner. Record their accepted versions.
- List the data that cannot be lost: graph, licensing, evidence, vulnerability status or build context.
- Generate both candidate outputs from one reference release if your tools permit it.
- Ingest, validate, query and export through the entire intended workflow.
- Select a primary exchange format; retain originals and document conversion limits.
Primary sources
- SPDX · Stable specification 3.0.1Published specification
- SPDX · Specification scopePublished specification
- SPDX · Licensing profilePublished specification
- SPDX · Build profilePublished specification
- SPDX · Specifications and ISO statusStandards organization
- SPDX · 3.1 release candidate announcementRelease candidate
- CycloneDX · Specification overviewPublished specification
- Ecma International · ECMA-424Standard
- CycloneDX · 1.7 JSON referenceSchema reference
- Ecma International · ECMA-427 Package-URLStandard
- CycloneDX · News and release announcementsStandards project news