# External Resources (/docs/external-resources)

Documents grouped by standards, regulation, implementation guidance, complementary frameworks and community work.

## Standards [#standards]

Formal specifications that define how transparency artifacts are structured, encoded and verified.

| Resource                                                                                                                                                                                  | Description                                                                             |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------- |
| [SPDX Specification](https://spdx.github.io/spdx-spec/)                                                                                                                                   | Format and information model for software bills of materials; published as ISO/IEC 5962 |
| [CycloneDX Specification](https://cyclonedx.org/specification/overview/)                                                                                                                  | OWASP format for SBOMs, VEX, and supply chain attestations                              |
| [OpenVEX Specification](https://github.com/openvex/spec)                                                                                                                                  | Minimal JSON format for vulnerability exploitability statements                         |
| [CSAF Standard (v2.0, Errata 01)](https://docs.oasis-open.org/csaf/csaf/v2.0/errata01/csaf-v2.0-errata01.html)                                                                            | OASIS format for machine-readable security advisories, including the VEX profile        |
| [NTIA SBOM Minimum Elements](https://www.ntia.gov/page/software-bill-materials)                                                                                                           | 2021 NTIA baseline for minimum SBOM data fields, automation, and practices              |
| [2025 Minimum Elements for a Software Bill of Materials (SBOM) - Public Comment Draft](https://www.cisa.gov/resources-tools/resources/2025-minimum-elements-software-bill-materials-sbom) | Draft CISA update to the NTIA minimum elements; tracks emerging US expectations         |
| [OWASP SCVS v2](https://scvs.owasp.org/scvs/v2-software-bill-of-materials/)                                                                                                               | OWASP Software Component Verification Standard for evaluating SBOM content quality      |

## Regulatory and policy guidance [#regulatory-and-policy-guidance]

Laws, regulations, and government policy that establish SBOM and supply chain requirements.

| Resource                                                                                                                                                                                                            | Description                                                                                                           |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- |
| [EU CRA](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act)                                                                                                                                    | EU Cyber Resilience Act: cybersecurity and SBOM obligations for manufacturers of products with digital elements       |
| [NIS2 Directive](https://digital-strategy.ec.europa.eu/en/policies/nis2-directive)                                                                                                                                  | EU directive requiring supply chain risk management and incident reporting for essential and important entities       |
| [BSI TR-03183-2: Software Bill of Materials](https://www.bsi.bund.de/SharedDocs/Downloads/EN/BSI/Publications/TechGuidelines/TR03183/BSI-TR-03183-2_v2_1_0.html)                                                    | German technical guideline for SBOM content, referenced in CRA interpretation                                         |
| [Executive Order 14028: Improving the Nation's Cybersecurity](https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity)                                                                       | 2021 US executive order that introduced federal SBOM requirements and triggered NIST SSDF and related guidance        |
| [OMB M-26-05: Adopting a Risk-based Approach to Software and Hardware Security](https://www.whitehouse.gov/wp-content/uploads/2026/01/M-26-05-Adopting-a-Risk-based-Approach-to-Software-and-Hardware-Security.pdf) | Current US federal guidance for software and hardware assurance; allows agencies to require a current SBOM on request |

## Authoritative guides [#authoritative-guides]

Implementation guidance from standards bodies, coordination centers and government agencies.

| Resource                                                                                                                                                                                                                | Description                                                                                                                        |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- |
| [ENISA SBOM Analysis: Towards an Implementation Guide (v1.20, Dec 2025)](https://www.enisa.europa.eu/sites/default/files/2025-12/SBOM%20Analysis%20-%20Towards%20an%20Implementation%20Guide_v1.20-Published.pdf)       | Current ENISA implementation guide for SBOM programs                                                                               |
| [Consolidated SBOM and CSAF/VEX Operational Framework](https://www.first.org/standards/frameworks/psirts/Consolidated-SBOM-VEX-Operational-Framework.pdf)                                                               | FIRST practical guidance for how SBOM and CSAF/VEX work together operationally                                                     |
| [PSIRT Maturity Document](https://www.first.org/standards/frameworks/psirts/FIRST_PSIRT_Maturity_Document.pdf)                                                                                                          | FIRST guidance for building the response capability behind high-quality advisories and VEX                                         |
| [OpenChain SBOM Quality Management Reference Material](https://github.com/OpenChain-Project/Reference-Material/tree/master/SBOM-Quality-Management)                                                                     | OpenChain community reference material for SBOM quality management                                                                 |
| [Framing Software Component Transparency (2024)](https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024)                                                                           | CISA conceptual framework for SBOM structure, purpose, and transparency expectations                                               |
| [SBOM FAQ (2024)](https://www.cisa.gov/sites/default/files/2024-07/SBOM%20FAQ%202024.pdf)                                                                                                                               | Current CISA introduction to SBOM concepts, uses, and common questions                                                             |
| [Recommended Practices for SBOM Consumption (2024)](https://www.cisa.gov/sites/default/files/2024-08/SECURING_THE_SOFTWARE_SUPPLY_CHAIN_RECOMMENDED_PRACTICES_FOR_SOFTWARE_BILL_OF_MATERIALS_CONSUMPTION-508.pdf)       | CISA guidance for organizations that receive, assess, and act on supplier SBOMs                                                    |
| [Securing the Software Supply Chain: Recommended Practices Guide for Suppliers and Developers](https://www.cisa.gov/resources-tools/resources/securing-software-supply-chain-recommended-practices-guide-suppliers-and) | CISA guidance for software producers on secure supply chain practices and artifact delivery                                        |
| [Software Acquisition Guide for Government Enterprise Consumers](https://www.cisa.gov/resources-tools/resources/software-acquisition-guide-government-enterprise-consumers-software-assurance-cyber-supply-chain)       | CISA guidance for procurement and acquisition teams evaluating software assurance, including provenance and SBOM-related questions |
| [CERT Guide to Coordinated Vulnerability Disclosure](https://certcc.github.io/CERT-Guide-to-CVD/)                                                                                                                       | CERT/CC guide to coordinated vulnerability disclosure workflows                                                                    |
| [NIST SP 800-218: Secure Software Development Framework (SSDF)](https://csrc.nist.gov/pubs/sp/800/218/final)                                                                                                            | Foundational US secure development framework referenced by federal SBOM policy                                                     |
| [NIST SP 800-161 Rev 1: Cybersecurity Supply Chain Risk Management Practices (C-SCRM)](https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final)                                                                             | Foundational US guidance for managing supply chain cybersecurity risk                                                              |

## Complementary frameworks [#complementary-frameworks]

Vulnerability triage and build-integrity frameworks used alongside SBOM work.

| Resource                                                                                  | Description                                                                    |
| ----------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------ |
| [SSVC: Stakeholder-Specific Vulnerability Categorization](https://certcc.github.io/SSVC/) | CERT/CC framework for categorizing and prioritizing vulnerability response     |
| [SLSA: Supply-chain Levels for Software Artifacts](https://slsa.dev)                      | Supply chain integrity framework for build provenance and artifact attestation |

## Community, working groups, and research [#community-working-groups-and-research]

Organizations, working groups, and industry research that maintain or track the SBOM ecosystem.

| Resource                                                                                                                                                                                     | Description                                                                              |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- |
| [CISA SBOM Resources](https://www.cisa.gov/sbom)                                                                                                                                             | CISA landing page collecting SBOM guidance, FAQs, and reference material                 |
| [OpenSSF](https://openssf.org/)                                                                                                                                                              | Linux Foundation umbrella for open source security projects, tooling, and working groups |
| [OpenChain Project](https://openchainproject.org/)                                                                                                                                           | Community behind the OpenChain ISO standards and SBOM quality reference material         |
| [FIRST PSIRT SIG](https://www.first.org/global/sigs/psirt/)                                                                                                                                  | FIRST special interest group for product security incident response teams                |
| [ORCWG CRA Hub](https://github.com/orcwg/cra-hub)                                                                                                                                            | Open Regulatory Compliance Working Group CRA resources including community FAQ           |
| [CERT/CC](https://www.sei.cmu.edu/about/divisions/cert/)                                                                                                                                     | Coordination center behind SSVC and the CVD guide                                        |
| [Linux Foundation: State of Software Bill of Materials Report](https://www.linuxfoundation.org/hubfs/LF%20Research/State%20of%20Software%20Bill%20of%20Materials%20-%20Report.pdf?hsLang=en) | Linux Foundation Research report on SBOM adoption, maturity, and practice                |