Skip to main content

Supplier SBOM Requirements

These are requirements on our suppliers. Without them, no tool — OCSA included — can produce a defensible verdict, because the missing data cannot be reconstructed downstream.

Put them in the supplier quality agreement. They are listed here in a form you can paste.

#RequirementRationale
S-1SPDX 2.2 or 2.3 JSONFormat baseline
S-2licenseConcluded populated, not NOASSERTIONThe only field that carries a legal conclusion
S-3purl in externalRefs for every packageStable identity across releases; enables enrichment
S-4STATIC_LINK / DYNAMIC_LINK relationshipsThe LGPL verdict depends entirely on linkage
S-5hasExtractedLicensingInfos for every LicenseRef-Otherwise custom licenses are unreadable
S-6filesAnalyzed: true with licenseInfoFromFilesCatches per-file license divergence
S-7creationInfo.creators and createdNTIA minimum elements
S-8One SBOM per distributed unit (executable / ECU image), not per repositoryCopyleft is assessed per shipped artefact

:::danger S-8 is the one most often missed Suppliers naturally produce one SBOM per repository, because that is what their tooling emits. But copyleft attaches to the shipped work. A repository-level SBOM has no notion of what ended up in which binary, so propagation and compatibility cannot be assessed correctly. Insist on one SBOM per executable or ECU image. :::

Element-by-element reference​

SPDX elementRequiredUsed for
spdxVersion, name, creationInfoYesDocument identity, NTIA-6/7
packages[]YesComponent inventory
packages[].licenseConcludedPreferredPrimary license source
packages[].licenseDeclaredFallbackSecondary license source
packages[].licenseInfoFromFilesFallbackTertiary source
packages[].externalRefs (purl)Strongly preferredNTIA-4, stable cross-release identity
packages[].checksumsPreferredAUD-1
packages[].copyrightTextPreferredAUD-3, LIC-008, NOTICE file
packages[].downloadLocationPreferredAUD-2
packages[].supplierPreferredNTIA-1, supplier inquiry
relationships[]YesDependency graph, NTIA-5
relationships[].relationshipTypeStrongly preferredAUD-5, propagation verdict
hasExtractedLicensingInfos[]Yes when LicenseRef- is usedLIC-004
documentDescribesPreferredRoot / distributed unit identification

What happens when they are not met​

OCSA does not refuse to analyse an incomplete SBOM — it analyses it and tells you the evidence is weak. Concretely:

MissingConsequence
licenseConcludedFalls back to declared, then to from-files; licenseSource records which was used
purlIdentity falls back to lowercased name; renamed components look like add + remove
LinkageAssumed static — over-reports copyleft reach, every finding says so
hasExtractedLicensingInfosThe custom license is unreadable; LIC-003 fires as a release blocker
filesAnalyzed / licenseInfoFromFilesPer-file divergence is invisible; declared license is taken at face value

Every one of these degrades confidence rather than producing a wrong number, which is the point: a compliance tool should fail loudly towards more caution, never towards less.

Closing the loop​

The inquiry command drafts the letter: numbered items, each with a blank for the supplier's response. Use it at intake, before the milestone review — not after.