CBOM Check
Semantic checks for CycloneDX 1.6 and 1.7 Cryptography Bills of Materials.
Passing the schema does not mean a CBOM is correct.
This checks what the CBOM says: NIST levels against FIPS 203/204/205, asset modelling,
incomplete parameter-set names, missing classical algorithms, refresh against a previous version,
and agreement with an ACVP test report.
Loading Python engine (about 15 MB, cached after the first visit)…
Try a sample: · ·
Reviewing CBOMs from many vendors, or need proof that a CBOM passed and when?
ActaSeal seals the result so your auditor can verify it offline.
Talk to us →
Checks
CBOM_SCHEMA_INVALID: baseline CycloneDX 1.6 / 1.7 schema validationCBOM_ASSET_MISSING_CRYPTO_PROPERTIESCBOM_ASSETTYPE_IMPLAUSIBLE: heuristic, warning only; the modelling decision is yoursCBOM_NIST_LEVEL_ON_NON_ALGORITHM,CBOM_NIST_LEVEL_MISMATCHCBOM_PARAMETER_SET_NAME_INCOMPLETE,CBOM_NO_CLASSICAL_ALGORITHMSCBOM_SERIALNUMBER_NOT_REFRESHED,CBOM_TIMESTAMP_NOT_REFRESHEDACVP_ALGORITHM_NOT_IN_CBOM,CBOM_ALGORITHM_NOT_TESTED,ALGORITHM_NAME_MISMATCHCBOM_CERTIN_ELEMENT_MISSING: optional; CERT-In CBOM minimum elements (Technical Guidelines v2.0)
Limits
The assetType check is a heuristic; every other check is deterministic. It does not check inventory completeness, key lengths, certificate contents, or whether an ACVP report is genuine. Self-run test vectors are not CAVP validation.
Privacy
The checker is Python running in your browser (Pyodide). Your files are read locally and
never sent anywhere. The same code runs as a CLI:
python cbom_check.py cbom.json --acvp report.json --baseline old.json --strict