Current versions and standardization

SPDX’s stable specification resolves to 3.0.1. The project’s January 2026 SPDX 3.1 announcement is a release candidate for review. SPDX 2.3 remains relevant when testing existing integrations. ISO/IEC 5962:2021 represents the earlier SPDX standardization; do not present that year’s ISO edition as certification of every 3.x feature.

Source: SPDX · Stable specification 3.0.1.

Source: SPDX · Specifications and ISO status.

Source: SPDX · 3.1 release candidate announcement.

CycloneDX’s published overview lists 1.7. Ecma’s ECMA-424 second edition, December 2025, defines 1.7. CycloneDX 2.0 has been announced as upcoming; this guide does not treat that announcement as the released interoperability target.

Source: CycloneDX · Specification overview.

Source: Ecma International · ECMA-424.

Source: CycloneDX · News and release announcements.

Compare the data models

DimensionSPDX 3.0.1CycloneDX 1.7
GovernanceLinux Foundation SPDX communityOWASP CycloneDX project; Ecma standardization
ModelElements and typed relationships organized into profilesBOM object model with components, services and references
Software compositionPackages, files, snippets and relationshipsComponents and dependency graph
LicensingSimple and expanded licensing profiles; declared and concluded informationLicense information, expressions and evidence in the BOM
SecuritySecurity profile represents vulnerabilities and contextual assessmentsVulnerability data and analysis, including VEX
Broader use casesBuild, AI and dataset profilesHardware, cryptographic assets, services, ML and attestations
Representations3.x model supports JSON-LD; distinguish 2.x serialization supportJSON, XML and Protobuf documented by the project

Source: SPDX · Specification scope.

Source: CycloneDX · Specification overview · Specification overview.

Licensing, build evidence and security need separate tests

SPDX distinguishes declared license information from the author’s concluded license assessment. Its Build profile describes a build’s inputs, outputs and related agents or tools. A tool supporting a software inventory does not thereby demonstrate every licensing or build-profile capability.

Source: SPDX · Licensing profile.

Source: SPDX · Build profile.

CycloneDX can carry services, cryptographic information and attestations. Confirm whether your tool produces these fields, ingests them, displays them, exposes them through an API and preserves them on export. A format’s expressive capacity and a platform’s implemented behavior are different things.

For either format, test vulnerability and VEX interpretation with a specific product release. A field surviving import is insufficient if the receiving tool ignores its meaning or associates it with the wrong component.

Ask what “supports the format” means

Claim to testEvidence to request
GenerationProduce the agreed version from your representative artifact.
IngestionLoad your supplier fixtures, including optional fields and unusual identities.
ValidationIdentify the failing path and rule in a deliberately invalid document.
ConversionCompare fields and relationship meaning before and after a round trip.
ExportReturn original and normalized data without support intervention.
ExtensionsDocument retained, interpreted, dropped and unsupported fields.
Version migrationShow coexistence and rollback for old and new schema versions.

Maintain an interoperability corpus. Include multiple namespaces, shared dependencies, incomplete relationships, non-public components, unknown versions, and an updated revision of the same inventory. Record losses as structured findings. Do not assume conversions are lossless because the resulting JSON parses.

A decision framework

  1. Start with the consumer: regulator, customer, internal platform or partner. Record their accepted versions.
  2. List the data that cannot be lost: graph, licensing, evidence, vulnerability status or build context.
  3. Generate both candidate outputs from one reference release if your tools permit it.
  4. Ingest, validate, query and export through the entire intended workflow.
  5. Select a primary exchange format; retain originals and document conversion limits.

Primary sources