SBOM Diff & VEX Drafter
Paste your previous and current SBOMs. Get the component delta, KEV-relevant hot-spots, and a CycloneDX VEX stub ready for the not-affected dispositions reviewers expect.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
SPDX (tag-value or JSON) or CycloneDX JSON.
Same format ideally; mixed formats are fine.
What you'll see after you submit
Paste two SBOMs → component delta + VEX stub
- Supports SPDX tag-value, SPDX JSON, and CycloneDX JSON inputs (mixed is fine).
- Flags components historically associated with KEV-listed vulnerabilities so triage starts in the right place.
- Generates a CycloneDX 1.5 VEX stub with not-affected dispositions you can edit and publish alongside your release.
- Designed for release-over-release SBOM hygiene the FDA expects under §524B postmarket maintenance.
Common misconceptions
What teams usually get wrong
-
Myth: A new SBOM each release is enough.
Reality: Reviewers and customers care about deltas. Why did this component appear, why did this version bump, and what's the VEX disposition for newly surfaced CVEs?
-
Myth: VEX is a one-time document.
Reality: VEX evolves with each release. The expectation is a VEX stream - not a static file.
-
Myth: If a component isn't on KEV it doesn't matter.
Reality: KEV is a floor, not a ceiling. EPSS, vendor advisories, and your own threat-model context all feed the disposition.
References & further reading
Primary sources behind this tool
- CycloneDX VEX specification - OWASP CycloneDX
- CISA Known Exploited Vulnerabilities (KEV) - CISA
- FIRST EPSS - FIRST
- FDA Cybersecurity in Medical Devices - SBOM expectations - FDA
Recent regulatory + supply-chain activity
Tracked signals that change what reviewers expect. Items move on as new ones land.
-
Jun 9, 2026CISA KEV
CISA adds Arista Extensible Operating System (CVE-2026-7473) to KEV - Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
-
Jun 2, 2026CISA KEV
CISA adds Linux Kernel (CVE-2022-0492) to KEV - Linux Kernel Improper Authentication Vulnerability
-
Jun 2, 2026CISA KEV
CISA adds Android Framework (CVE-2025-48595) to KEV - Android Framework Integer Overflow Vulnerability
-
May 20, 2026CISA KEV
CISA adds Microsoft Windows (CVE-2008-4250) to KEV - Microsoft Windows Buffer Overflow Vulnerability
Where to take this next.
FDA-compliant SBOM services
Build the pipeline that produces a clean diff every release.
Read FDA-compliant SBOM servicesSBOM Readiness scorer
How does your SBOM + supply-chain program score overall?
Read SBOM Readiness scorerComponent Risk Scorecard
Score any individual dependency before you accept it.
Read Component Risk ScorecardMore tools
PCCP, 524B checker, threat model, wireless profiler.
Read More tools