CycloneDX 2.0 Preview: Evolving BOM Architecture for Broader Applicability @OWASPGLOBAL
CycloneDX 2.0 Preview: Evolving BOM Architecture for Broader Applicability  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 2 weeks ago
The CycloneDX standard continues to evolve to meet the increasing demands of software transparency, AI accountability, and supply chain security. Version 1.7 introduces targeted improvements including improvements for cryptographic assets, and added support for patents and TLP. But 2.0 is a major architectural shift: a modular, model-driven approach designed to increase reuse, expressiveness, and long-term maintainability.

This session will walk through the new capabilities introduced in CycloneDX 1.7 and preview the roadmap to 2.0. We'll discuss practical benefits for tool developers and adopters, explain how the new model structure works, and offer guidance for preparing for the transition. Whether you're building SBOM tooling, managing compliance, or contributing to the standard, this talk will equip you with the latest and next directions for CycloneDX.

Steve Springett
ServiceNow
Creator of OWASP Dependency-Track and Chair of CycloneDX SBOM Core Working Group and Ecma TC54
Chicago
about.me/stevespringett
linkedin.com/in/stevespringett

Managed by the OWASP® Foundation
owasp.org
CycloneDX 2.0 Preview: Evolving BOM Architecture for Broader ApplicabilityGuardrails First: Building AI Agents That Won’t Leak Your Secrets - Track 2Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third PartySecure Financial Analytics with Homomorphic Encryption and GAN Driven Data Track 2Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan WorcelSelf-Healing Security Test Automation for OWASP AppSec: Adaptive Defense Against Evolving ThreatsAMMF: Attention-Driven Multi-Feature Fusion for Scalable Cross-Architecture Binary VulnerabilityHow a Clean Security Audit Became a Breach Notification Six Months Later- Track 2OWASP AIVSS Project: What it is, why we need it and how we are doing itOWASP Mobile Application Security (MAS) - Sven Schleier, Carlos HolgueraGetting an LLM to Hack Itself: On AI, Moral Dilemmas, and SecurityLost in Translation: Exploiting Unicode Normalization
OWASP Foundation |

CycloneDX 2.0 Preview: Evolving BOM Architecture for Broader Applicability

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER