|
| 1 | +--- |
| 2 | +# Page settings |
| 3 | +layout: document |
| 4 | +keywords: application security, software security, software bill of material, SBOM, BOM, open source, supply chain, specification, spdx, license, package url, purl, cpe |
| 5 | +comments: false |
| 6 | +banner: false |
| 7 | + |
| 8 | +# News article settings |
| 9 | +organization: CycloneDX |
| 10 | +type: Press Release |
| 11 | + |
| 12 | +title: "CycloneDX v1.6: Now an Ecma International Standard" |
| 13 | +window_title: "CycloneDX v1.6: Now an Ecma International Standard" |
| 14 | +description: "CycloneDX v1.6: Now an Ecma International Standard" |
| 15 | +location: WILMINGTON, DE |
| 16 | +subtitle: CycloneDX v1.6 has been officially ratified as an Ecma International standard, following a decisive vote at the Ecma General Assembly on 26 June. |
| 17 | +excerpt: This milestone sets the stage for CycloneDX Bill of materials being available as a global xBOM (Bill of Materials) standard for use across multiple domains. CycloneDX is proud to be an OWASP Flagship standards project, and in a community development model with Ecma International’s TC54, underscoring its importance and impact in the industry. |
| 18 | +image: https://cyclonedx.org/theme/assets/images/hero-subheader.png |
| 19 | + |
| 20 | +# Micro navigation |
| 21 | +micro_nav: false |
| 22 | + |
| 23 | +# Page navigation |
| 24 | +breadcrumbs: |
| 25 | + - title: CYCLONEDX |
| 26 | + - title: ABOUT |
| 27 | + - title: NEWSROOM |
| 28 | + |
| 29 | +--- |
| 30 | + |
| 31 | +# CycloneDX v1.6: Now an Ecma International Standard |
| 32 | +**01 July 2024** |
| 33 | + |
| 34 | +OWASP is excited to announce that CycloneDX v1.6 has been officially ratified as an Ecma International standard, |
| 35 | +CycloneDX Bill of materials specification, following a decisive vote at the Ecma General Assembly on 26 June. |
| 36 | +This milestone sets the stage for CycloneDX Bill of materials being available as a global xBOM (Bill of Materials) |
| 37 | +standard for use across multiple domains. CycloneDX is proud to be an OWASP Flagship standards project, and in a |
| 38 | +community development model with Ecma International’s TC54, underscoring its importance and impact in the industry. |
| 39 | + |
| 40 | +#### **A Comprehensive Standard for the Software Supply Chain** |
| 41 | +CycloneDX v1.6 stands out as the global xBOM standard that holistically supports a wide range of assets, including |
| 42 | +software, services, hardware, firmware, AI/ML, and cryptography. This broad coverage is crucial in today’s complex |
| 43 | +and interconnected technology landscape, enabling organizations to achieve comprehensive visibility and management |
| 44 | +across their entire supply chain. |
| 45 | + |
| 46 | +* **Software**: Ensures detailed transparency and management of software components, vital for addressing security vulnerabilities and ensuring compliance. |
| 47 | +* **Services**: Covers third-party services, providing insights into potential risks and dependencies that could impact operational integrity. |
| 48 | +* **Hardware and Firmware**: Facilitates robust management and security of physical components and embedded systems, crucial for sectors like IoT and critical infrastructure. |
| 49 | +* **AI/ML**: Addresses the growing need to manage and secure machine learning models and data, essential for maintaining trust and performance in AI-driven applications. |
| 50 | +* **Cryptography**: Ensures secure handling and implementation of cryptographic assets, including Post-Quantum Cryptography (PQC) readiness as outlined in [NIST SP 1800-38B](https://csrc.nist.gov/pubs/sp/1800/38/iprd-(1)). This is a fundamental aspect of protecting data integrity and confidentiality from evolving threats. |
| 51 | + |
| 52 | +#### **Ideal for Holistic Supply Chain and Advanced Cybersecurity Use Cases** |
| 53 | + |
| 54 | +CycloneDX v1.6 is specifically designed to meet the demands of holistic supply chain management and advanced |
| 55 | +cybersecurity use cases. By providing a detailed and comprehensive view of the entire supply chain, CycloneDX |
| 56 | +enables organizations to identify and mitigate risks effectively, ensuring resilience and security. |
| 57 | + |
| 58 | + |
| 59 | +#### **Unmatched License Support** |
| 60 | + |
| 61 | +One of the standout features of CycloneDX v1.6 is its advanced license support, which holistically helps to |
| 62 | +facilitate open-source license compliance and supports commercial license management and procurement scenarios. |
| 63 | +This capability is critical for organizations navigating the complexities of software licensing, ensuring compliance |
| 64 | +and optimizing procurement processes. |
| 65 | + |
| 66 | + |
| 67 | +#### **Wide Industry Support** |
| 68 | + |
| 69 | +CycloneDX has garnered wide industry support, with over 220 tools now supporting the standard. This extensive |
| 70 | +ecosystem demonstrates the trust and adoption by the industry, making CycloneDX a reliable and effective choice |
| 71 | +for organizations looking to enhance their supply chain security and management. |
| 72 | + |
| 73 | +#### **Quotes** |
| 74 | + |
| 75 | +<blockquote class="press-release"> |
| 76 | +<p>The ratification of CycloneDX Bill of materials specification as an Ecma International standard is a testament to |
| 77 | +the effectiveness of the community model established by Technical Committee 54 (TC54). This model is a benchmark |
| 78 | +for future technical committees and the CycloneDX Bill of materials specification is just the beginning, with |
| 79 | +several other supply chain standards expected to emerge from TC54.</p> |
| 80 | +<cite>Samina Husain, Secretary General of Ecma International</cite> |
| 81 | +</blockquote> |
| 82 | + |
| 83 | +<blockquote class="press-release"> |
| 84 | +<p>CycloneDX Bill of materials specification recognition as an international standard is a testament to its robustness |
| 85 | +and wide industry adoption. It exemplifies the kind of innovative solutions the OWASP Foundation is proud to support.</p> |
| 86 | +<cite>Andrew van der Stock, Executive Director of the OWASP Foundation</cite> |
| 87 | +</blockquote> |
| 88 | + |
| 89 | +<blockquote class="press-release"> |
| 90 | +<p>The standardization of CycloneDX by Ecma International is a major milestone for the global technology community. |
| 91 | +This achievement highlights our commitment to creating secure, transparent, and manageable supply chains.</p> |
| 92 | +<cite>Steve Springett, Chair of the Ecma TC54 and Director of Product Security at ServiceNow</cite> |
| 93 | +</blockquote> |
| 94 | + |
| 95 | +#### **About Ecma Technical Committee (TC54)** |
| 96 | + |
| 97 | +The Ecma Technical Committee 54 (TC54) is responsible for drafting the CycloneDX Bill of materials specification and |
| 98 | +other related initiatives. Operating under a community development model, the committee is dedicated to standardizing |
| 99 | +core data formats, APIs, and algorithms that advance software and system transparency. |
| 100 | + |
| 101 | +Among TC54's ongoing projects is the standardization of Package URL (purl), a specification for identifying and locating |
| 102 | +software packages. This is crucial for managing dependencies and vulnerabilities across diverse software ecosystems. |
| 103 | +Another key initiative is the Transparency Exchange API, designed for the efficient sharing of supply chain artifacts |
| 104 | +and intelligence, further enhancing the security and transparency of supply chains. |
| 105 | + |
| 106 | +For more information about TC54 and its initiatives, please visit [https://tc54.org](https://tc54.org). |
| 107 | + |
| 108 | +##### **About Ecma International** |
| 109 | + |
| 110 | +Ecma International is a not-for-profit industry association of technology developers, vendors, and users founded |
| 111 | +in 1961 and dedicated to the standardization of Information and Communication Technology (ICT) and Consumer |
| 112 | +Electronics (CE). For over 60 years Ecma has actively contributed to worldwide standardization in information |
| 113 | +technology and telecommunications. More than 400 Ecma Standards and 100 Technical Reports of high quality have |
| 114 | +been published, more than two-thirds of which have also been adopted as International Standards and/or Technical |
| 115 | +Reports. |
| 116 | + |
| 117 | +To learn more or to become a member, visit [https://ecma-international.org](https://ecma-international.org). |
| 118 | + |
| 119 | +##### **About the OWASP Foundation** |
| 120 | +The OWASP Foundation is a nonprofit organization that works to improve the security of software. Through community-led |
| 121 | +open source software projects, over 260 local chapters worldwide, tens of thousands of members, and leading educational |
| 122 | +and training conferences, the OWASP Foundation is the source for developers and technologists to secure the web. For |
| 123 | +nearly two decades corporations, foundations, developers, and volunteers have supported the OWASP Foundation and its |
| 124 | +work. To learn more or to become a member, visit [https://owasp.org](https://owasp.org). |
| 125 | + |
| 126 | +For more information about CycloneDX v1.6 and its benefits, please visit [https://cyclonedx.org](https://cyclonedx.org). |
0 commit comments