Working Group — CBOM
CBOM Profiles Working Group
A neutral methodology for defining Cryptographic Bill of Materials profiles.
The CBOM Profiles Working Group develops a clear, neutral methodology for defining profiles of a Cryptographic Bill of Materials (CBOM) — independently of any single base standard. A profile is a constrained, use-case-specific specification of what a CBOM should contain, how its fields should be interpreted, and what validation rules apply.
The Working Group designs its methodology so that profiles map simply onto industry BOM standards such as SPDX and CycloneDX, rather than competing with them. The PKIC output is intended to become the reference any industry consults when creating a CBOM profile for a particular use case.
CBOM Chair
CBOM Vice ChairKey Deliverables
CBOM Profile Methodology
A documented, neutral methodology for defining CBOM profiles — allowing any industry or organization to specify a CBOM profile in a consistent, repeatable way.
Coming Soon →Standards Mapping Guidance
Documented mapping guidance describing how profiles defined with the methodology are expressed in SPDX, CycloneDX, and other relevant BOM standards — ensuring profiles are immediately actionable.
Coming Soon →Explore this Working Group
Select a section to dive deeper
More from this Working Group
Membership in the PKI Consortium working groups is open to all member types.Collaborate with industry leaders, shape standards, and drive meaningful change.
Become a Member Join Discussions