SBOM Quality Checks
A verdict is only as good as the SBOM behind it. Before any risk is computed, OCSA runs 12 checks — the 7 NTIA minimum elements plus 5 additional audit elements — and reports a single quality percentage.
The demo 4.2.0 SBOM scores 50 % (6 of 12), which is representative: real supplier SBOMs routinely fail the purl, checksum and linkage checks.
NTIA minimum elements
| ID | Check | Passes when |
|---|---|---|
NTIA-1 | Supplier name | No component is missing a supplier, or has NOASSERTION |
NTIA-2 | Component name | Every component has a name |
NTIA-3 | Version identifier | No component is missing a version |
NTIA-4 | Unique identifier (purl) | Every component has a package URL |
NTIA-5 | Dependency relationship | At least one relationship is recorded |
NTIA-6 | SBOM author | creationInfo.creators is non-empty |
NTIA-7 | Timestamp | creationInfo.created is present |
Additional audit elements
| ID | Check | Passes when | Why it matters |
|---|---|---|---|
AUD-1 | Checksums | Every component has a checksum | Proves you analysed the artefact you shipped |
AUD-2 | Download location | Every component has a resolved download location | Needed for source retrieval and offers |
AUD-3 | Copyright text | Every component has copyright text (not NOASSERTION) | Feeds the NOTICE file and LIC-008 |
AUD-4 | Files analysed | No component is marked filesAnalyzed: false | Without it, per-file license divergence is invisible |
AUD-5 | Linkage declared | At least one explicit STATIC_LINK / DYNAMIC_LINK relation exists | Critical for LGPL assessment |
AUD-5 deserves emphasis. The LGPL verdict depends entirely on linkage. If the SBOM declares
only DEPENDS_ON, OCSA assumes static linkage — the safe direction, but it over-reports. Every
such finding says "linkage not declared", so a supplier can fix the SBOM and the finding goes
away.
How the score is computed
score = round((passed / 12) * 100)
It is a simple ratio of passed checks, not a weighted model. A single missing element is enough to fail a check — which is deliberate: these are minimum elements, not nice-to-haves.
What to do with a low score
A low quality score is not itself a compliance risk — it is a data risk. It means some verdicts rest on weaker evidence. The right response is to send the supplier requirements back to the supplier and re-run, not to argue about the findings.
Use --min-quality in the release gate to
reject an SBOM at intake when it is too incomplete to assess:
node tools/cli.mjs gate sbom.json --min-quality 70
Where it appears
- The SBOM quality panel in the dashboard lists all 12 checks with pass/fail and a count of affected components.
- The KPI strip shows the percentage.
- The per-ECU compliance report records it, so the review board can see that a verdict was reached on incomplete data.