SBOM Observer Docs logoSBOM Observer Docs

Supported Formats & Standards

Supported SBOM formats, attestation types, and standards


Ensuring that your tools and solutions work seamlessly with your existing tech stack is paramount. SBOM Observer supports a wide range of industry-standard formats and attestation types.

Supported SBOM Formats

Below is a list of supported SBOM Formats.

SBOM standardFormatsVersionMore information
CycloneDXJSON, XML1.0 - 1.6Learn more
SPDXJSON, YAML, RDF (RDF/XML), tag:value (flat text file)2.1 - 2.3Learn more

Supported Attestation Types

SBOM Observer supports the following types of attestations:

Attestation TypeDescription
SBOMSoftware Bill of Materials – A comprehensive inventory of software components.
HBOMHardware Bill of Materials – A detailed list of hardware components and their dependencies.
CBOMComing soon: Cryptography Bill of Materials – A detailed inventory of individual software components, including their dependencies and configuration details.
CSAF VEXComing soon: Common Security Advisory Framework Vulnerability Exploitability eXchange – A standardized format for sharing vulnerability information.
CycloneDX VEXA vulnerability exchange format based on the CycloneDX standard, enabling the automated sharing of vulnerability information.
OpenVEXAn open standard for vulnerability exchange that facilitates the communication of vulnerability data and remediation guidance.
SLSASupply chain Levels for Software Artifacts – A security framework outlining best practices to secure the software supply chain and verify the integrity of software artifacts. Observer supports SLSA Package Provenance