Validate the SPDX SBOM against NTIA, CISA, and other minimum element requirements.
This tool determines whether a SPDX software bill of materials (SBOM) document contains informational items as required by a certain specification.
It supports SPDX specification versions 2.2, 2.3, and 3.0.
Note that while the SPDX 3.0 specification allows for multiple SBOMs within a single SPDX document, this tool currently limits support to one SBOM per document.
A web-based version of the tool is available (no installation needed) at: https://tools.spdx.org/app/ntia_checker/
Currently, the supported specifications are:
- 2021 NTIA SBOM Minimum Elements
- 2024 CISA Framing Software Component Transparency (FSCT3) (minimum expected)
- 2025 BSI TR-03183-2 v2.1.0 content requirements
The minimum elements include:
- Supplier Name
- Component Name
- Version of the Component
- Other Unique Identifiers
- Dependency Relationship
- Author of SBOM Data
- Timestamp
As defined by the NTIA, the minimum elements are "the essential pieces that support basic SBOM functionality and will serve as the foundation for an evolving approach to software transparency."
In addition to information similar to NTIA minimum elements, FSCT3 requires these Baseline Attributes as part of its "minimum expected":
- License
- Copyright Holder (inside Copyright Notice)
BSI TR-03183-2 introduces stricter requirements for component files and relationships, including:
- SHA-512 Hashes for deployable components
- Structured component properties (e.g., container, firmware)
- Strict concluded licensing targets
- Explicit dependency completeness definitions
Mappings:
- The mapping of the NTIA elements required data fields to the SPDX 2.3 specification can be found here.
- The mapping of FSCT3 Baseline Attributes to ISO/IEC 5962:2021 (SPDX 2.2.1) and SPDX 3.0 can be found at Section 2.5 of the FSCT3 document.
- More comparison of SBOM requirements and their mapping to SPDX can be found in this slide from Takashi Ninjouji of OpenChain Japan SBOM Sub-WG, presented at SPDX General Meeting 2024-12-05.
Note
To ensure strict compatibility with the official SPDX 3.0.1 specification, this checker adapts two of the examples provided in the BSI TR-03183-2 v2.1.0 document:
- Deployable URIs:
binaryArtifactis evaluated strictly as anExternalRefTypeinside anexternalRefarray (rather than a direct property ofsoftware_File). - Source Code URIs: Artifacts must be defined using concrete subclasses (e.g.,
software_File,software_Package,software_Snippet) instead of the abstractsoftware_SoftwareArtifactclass.
For full technical details regarding these design decisions, please refer to PR #428.
This tool requires Python 3.10 or newer. Its dependencies may require a more recent version of Python.
Installation Method #1:
Install from the Python Package Index (PyPI) with pip.
pip install ntia-conformance-checkerInstallation Method #2: Install from local source. Clone the repo and install dependencies using the following commands:
git clone https://github.com/spdx/ntia-conformance-checker.git
cd ntia-conformance-checker
pip install .It is recommended to use a virtual environment, especially
if you work with multiple Python versions.
virtualenv is a tool for creating isolated Python environments;
it lets you keep a project's dependencies in a single environment
or create separate environments for testing with different Python versions.
usage: sbomcheck [OPTIONS] PATH
positional arguments:
PATH Filepath for SBOM input
options:
-h, --help show this help message and exit
-s, --sbom-spec {spdx2,spdx3}
SBOM specification of the input file; see below for details [default: spdx2]
-c, --comply {bsi,fsct3-min,ntia}
Compliance standards to check against; see below for details [default: ntia]
-k, --skip-validation
Skip validation
-r, --output TYPE Report output type; see below for details [default: print]
-o, --output-file PATH
Filepath for report output; if omitted, prints to console
-v, --verbose Increase log verbosity to info
-vv, --debug Increase log verbosity to debug
-q, --quiet Quiet logs: show errors only
-V, --version Display version of sbomcheck
choices:
SBOM specifications (for --sbom-spec):
spdx2 Software Package Data Exchange (SPDX) 2.x
spdx3 System Package Data Exchange (SPDX) 3.x
Compliance standards (for --comply):
bsi BSI TR-03183-2 v2.1.0 content requirements
fsct3-min 2024 CISA Framing Software Component Transparency (minimum expected)
ntia 2021 NTIA SBOM Minimum Elements
Report output types (for --output):
html Report in HTML format
json Report in JSON format
none No report
print Report in regular text format
Examples:
sbomcheck sbom.spdx
sbomcheck -s spdx3 -c fsct3-min -v sbom.json
sbomcheck sbom.yaml --output json --output-file report.json
The user can then analyze a particular file:
sbomcheck sbom.jsonTo generate the output in machine-readable JSON, run:
sbomcheck sbom.spdx --output jsonTo analyze an SPDX 3 JSON file, run:
sbomcheck sbom.json --sbom-spec spdx3Use -h for help:
sbomcheck -hntia-conformance-checker can also be imported as a library. For example:
from ntia_conformance_checker import SbomChecker
sbom_checker = SbomChecker("SBOM_filepath")
print(sbom_checker.compliant)See the API documentation at: https://spdx.github.io/ntia-conformance-checker/
Additional properties and methods can be found in BaseChecker class
at base_checker.py.
Specific properties and methods for a particular specification can be found
at the checker for that specification. For example, NTIAChecker class
at ntia_checker.py.
With the SPDX Online Tool, you can check the SBOM conformance without the need to install the Python package.
Go to this page: https://tools.spdx.org/app/ntia_checker/.
The HTML output is organized into four distinct div blocks, each with a specific CSS class for easy styling and targeting:
- Errors (parsing, etc.):
<div class="conformance-err"> - Conformance results:
<div class="conformance-res"> - Components missing required information:
<div class="conformance-mis"> - Detailed validation information:
<div class="conformance-val"> - Graph structural issues:
<div class="conformance-graph">
- The project is the result of an initial Google Summer of Code (GSoC) contribution in 2022 by @linynjosh.
- SPDX 3 support and improved FSCT3 checker, available in v4.0.0, are GSoC 2025 contribution by @bact.
- BSI TR-03183-2 conformance checker and structural graph validation architecture are GSoC 2026 contribution by @InduwaraGunasena.
- The project is maintained by a community of SPDX adopters and enthusiasts.
- See SPDX's participation in Google Summer of Code (GSoC): https://github.com/spdx/GSoC.
- spdx-tools used for parsing the SPDX 2 SBOM.
- spdx-python-model used for parsing the SPDX 3 SBOM.
- Submit issues, questions or feedback at https://github.com/spdx/ntia-conformance-checker/issues
- Join the discussion on https://lists.spdx.org/g/spdx-tech and https://spdx.dev/participate/tech/
Contributions are very welcome! See CONTRIBUTING.md for instructions on how to contribute to the codebase.
Check out the frequently asked questions document.