Skip to main content
THE LINUX FOUNDATION PROJECTS

The System Package Data Exchange™ (SPDX®)

An open standard capable of representing systems with software components in as SBOMs (Software Bill of Materials) and other AI, data and security references supporting a range of risk management use cases.

The SPDX specification is a freely available international open standard (ISO/IEC 5962:2021).

Learn More

Learn

Learn more about the structure of SPDX and how to participate.

ABOUT SPDX

Use

Explore the ways that you can engage with SPDX.

USE SPDX

Tools

SPDX workgroup tools and others you can use.

SPDX TOOLS

Areas of Interest

SPDX is organized in areas of interest or profiles focused on specific user needs.

Supported by These Foundations

Latest SPDX News

Oct 3, 2025
SPDX Responds to CISA Minimum Elements RFC

About a month ago, CISA requested industry/community comment on a proposed new minimum set of SBOM elements to replace the original NTIA list. Few people…

Sep 19, 2025
CISA Considering New Set of Minimum Elements

CISA has requested comment on a new set of minimum elements for SBOMs (on top of the original NTiA set). This short announcement describes the…

SPDX Supporters