External Resources
Curated collection of external documentation and tools
A curated collection of external resources for software transparency standards.
Standards Documentation
| Resource | Description |
|---|---|
| SPDX Specification | Official SPDX specification |
| CycloneDX Specification | Official CycloneDX specification |
| NTIA SBOM Minimum Elements | NTIA minimum elements guidance |
| OpenVEX Specification | OpenVEX format specification |
| CSAF Standard | Common Security Advisory Framework |
Regulatory Guidance
| Resource | Description |
|---|---|
| EU CRA | EU Cyber Resilience Act |
| NIS2 Directive | EU Network and Information Security |
| Executive Order 14028 | US Executive Order on Cybersecurity |
Community
| Resource | Description |
|---|---|
| SBOM Forum | CISA SBOM resources |
| OpenSSF | Open Source Security Foundation |
Authoritative Guides
| Resource | Description |
|---|---|
| - | - |