Jan 8, 2026·CycloneDX · Specification errataActiveMedium impact
CycloneDX 1.6.1 errata clarifies VEX status semantics
1.6.1 errata clarifies how to express 'not_affected' justifications and how VEX statements should reference SBOM components by bom-ref or PURL.
What changed
- Justification vocabulary tightened to reduce ambiguous 'not_affected' rows.
- Examples added for medical-device style submissions.
Action for manufacturers
Update your VEX generator to emit explicit justifications and stable bom-refs; FDA reviewers increasingly cite missing justifications as deficiencies.