Open Source Compliance

CycloneDX SBOM Validator

Paste a CycloneDX SBOM JSON document to validate required fields, component structure, PURL format, and dependency graph integrity against the official schema.

Calculations run locally in your browser

CycloneDX SBOM Validator

The CycloneDX SBOM Validator validates SBOM documents against CycloneDX v1.4 and v1.5 JSON schema, checking required fields, PURL format, and dependency graph integrity.

โ€ข Validate a CycloneDX SBOM generated by syft or cdxgen before submission to a customer

โ€ข Debug a schema validation error in a CI/CD SBOM generation pipeline

โ€ข Check PURL format correctness for all components in an SBOM

โ€ข Verify VEX analysis states and justification codes

Continue with Utility Matrix tools for the next decision in this workflow.
Browse tools โ†’
What does this tool tell you?
The CycloneDX SBOM Validator validates SBOM documents against CycloneDX v1.4 and v1.5 JSON schema, checking required fields, PURL format, and dependency graph integrity.
What affects the result most?
Validates CycloneDX SBOM structure against v1.4 and v1.5 JSON schema. Required fields: bomFormat, specVersion, version, serialNumber, metadata.component. Component required fields: type, name โ€” bom-ref optional but recommended for dependency graph.
How should I use the result?
Treat the tool's output as a first-pass check, not a proof of correctness. A clean pass means no issues in the patterns this tool recognizes; a failure points to a specific problem you can investigate in your source. The underlying spec is the authoritative source for edge cases.
An invalid SBOM is worse than no SBOM. It creates false confidence. The Data Governance Analyzer validates your supply chain documentation โ€” catches missing components, invalid formats, and compliance gaps.
View supply chain documentation analysis โ†’