logo

What is the xBOM?

ID: d05ec0b3-ac7b-5120-9b04-f35583555b45

STIX ID: report--d05ec0b3-ac7b-5120-9b04-f35583555b45

Feed Name: ReversingLabs Blog

Date Published: 2025-04-25

Date Updated: 2026-04-29

Author: [email protected] (Carolynn van Arsdale)

...
...

This document explains the evolution from traditional SBOMs to CycloneDX’s xBOM standard (v1.6), which extends visibility across software, SaaS, cryptography, ML models, hardware, and operational contexts to strengthen software supply chain security. It highlights ReversingLabs Spectra Assure’s support for xBOM—specifically SaaSBOM, ML-BOM, and CBOM—providing inventories of SaaS integrations, machine learning models, and cryptographic assets to improve risk management and regulatory compliance (e.g., NIST AI RMF, EU AI Act). The piece emphasizes that while xBOMs enhance transparency, additional capabilities are required to detect malware, tampering, and other threats within software pipelines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.