SBOM
CycloneDX vs SPDX
CycloneDX and SPDX are the two SBOM formats almost every tool supports. Both describe the components in a piece of software and how they relate. They differ in where they came from, what else they carry, and which standards body stands behind them.
Updated
The short answer
Use the format your customers, regulators or tools ask for. If nobody asks, CycloneDX is the more common choice for security work because it carries VEX natively, and SPDX is the more common choice where license compliance leads. Most generators, CRACI included, can produce both.
Side by side
| Capability | CycloneDX | SPDX |
|---|---|---|
| Maintained by | OWASP Foundation and Ecma International | Linux Foundation |
| Standard | ECMA-424 | ISO/IEC 5962:2021 |
| Current version | 1.7, October 2025 | 3.0, April 2024 |
| Where it started | Security and supply chain risk | License compliance |
| Bill types | SBOM, SaaSBOM, HBOM and more | Profiles for security, build, datasets and AI |
| Vulnerability data | VEX built in | Security profile in 3.0 |
| Encodings | JSON, XML, Protocol Buffers | Several, including JSON |
CycloneDX
CycloneDX is developed by the OWASP Foundation and standardized by Ecma International as ECMA-424. Version 1.7 was released in October 2025. It started from security and supply chain risk and covers more than software: SBOMs, SaaSBOMs for services and HBOMs for hardware. It supports VEX, so the same format can say whether a vulnerability affects a product. It is serialized as JSON, XML or Protocol Buffers.
SPDX
SPDX is an open source project hosted by the Linux Foundation and recognized as the international standard ISO/IEC 5962:2021. It started from license compliance, and its license identifiers are used far beyond SBOMs. SPDX 3.0, released in April 2024, added profiles for security, build, datasets and AI.
Watch: SBOM basics
From our talk at KCD Helsinki: what an SBOM records, how SPDX and CycloneDX differ in practice, and what OpenVEX adds.
SBOM basics: SPDX, CycloneDX and OpenVEX
Petteri Pulkkinen and Erika Marttinen at Kubernetes Community Days Helsinki 2026, 16:50 to 22:05 of SBOMbastic: Getting Ready for Upcoming EU Cybersecurity Regulation in Software Supply Chains.
What regulators accept
The EU Cyber Resilience Act asks for an SBOM in "a commonly used and machine-readable format" and does not name one. Germany's BSI TR-03183-2, version 2.1.0, is more specific: CycloneDX 1.6 or higher, or SPDX 3.0.1 or higher, in JSON or XML. See CRA SBOM requirements.
The format matters less than the content
Both formats can hold an incomplete SBOM. What decides whether an SBOM is useful is whether it lists everything that went into the product, including transitive dependencies. CRACI records the SBOM while your GitHub Actions build runs, states its completeness per job and per cache, and exports it in CycloneDX or SPDX. See build-time SBOM generation.
CycloneDX vs SPDX: frequently asked questions
Is CycloneDX or SPDX better?
Neither is better in general. CycloneDX grew out of security use and carries VEX natively; SPDX grew out of license compliance and is an ISO standard. Most tools can produce both. Choose the one your customers, regulators or tools ask for.
Which SBOM format does the EU Cyber Resilience Act require?
The CRA asks for a commonly used, machine-readable format and does not name one. Germany's BSI TR-03183-2 accepts CycloneDX 1.6 or higher and SPDX 3.0.1 or higher, in JSON or XML.
Can I convert between CycloneDX and SPDX?
Tools exist to convert in both directions, but the formats do not map one to one, so a conversion can lose detail. If you can, generate the format you need directly.
Does CRACI export CycloneDX or SPDX?
Both. CRACI records the SBOM while your GitHub Actions build runs and exports it in CycloneDX or SPDX, including transitive dependencies and each component's declared license.
Get both formats from one build
Run one GitHub Actions job on CRACI and export its recorded SBOM in CycloneDX or SPDX.
Book a demo