SPDX
An open SBOM and license-data format published as ISO/IEC 5962:2021.
Definition
SPDX (Software Package Data Exchange) is an open specification, maintained by the Linux Foundation and standardized as ISO/IEC 5962:2021, for communicating software bill-of-materials information including components, licenses, copyrights, and security references. SPDX 3.0 (2024) extends the format with profiles for security, AI/ML, and dataset provenance. It is one of the two SBOM formats explicitly accepted by FDA (the other is CycloneDX).What this means in practice
SPDX is most common in build pipelines that already use it for license compliance (e.g., automotive, aerospace, large enterprise software). For MedTech teams choosing fresh, CycloneDX is often easier to pair with VEX, but SPDX is fully acceptable to FDA and a better fit when license attribution is also a deliverable.- •Treating SPDX as solely a license-compliance artifact and omitting security-relevant metadata.
- •Producing SPDX 1.x or 2.x output when modern tooling expects SPDX 2.3 or 3.0.
- •Hand-editing SPDX files instead of generating them from the build - drift is inevitable.
Frequently asked questions
Cross-references
Used by
Things that build on this term.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsA lightweight, OWASP-maintained SBOM format designed for application security and supply-chain use cases.
The federal statute that gives FDA explicit premarket authority over cybersecurity for cyber devices.
A machine-readable inventory of all software components, including open-source and third-party libraries, used to build a medical device.
A machine-readable statement that explains whether a known vulnerability is actually exploitable in a specific product.
More in Cybersecurity
· Same categoryAAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
AAMI Technical Information Report on post-market security risk management for medical device manufacturers, the operational companion to TIR57.
Unauthorized remote control of an implanted neurostimulator (e.g., DBS) to alter stimulation parameters and harm a patient.
Primary references
3 sources- 1
SPDX SpecificationsVerifiedLinux Foundationspdx.dev
- 2
ISO/IEC 5962:2021 (SPDX)VerifiedISO/IECiso.org
- 3
FDA Cybersecurity Guidance (Sept 2023)VerifiedFDAfda.gov
Inline markers like [1] jump to the matching reference above.