SBOM Diff & VEX Drafter
Paste your previous and current SBOMs. Get the component delta, KEV-relevant hot-spots, and a CycloneDX VEX stub ready for the not-affected dispositions reviewers expect.
Reviewed by
Christian Espinosa
Founder & CEO, Blue Goat Cyber
SPDX (tag-value or JSON) or CycloneDX JSON.
Same format ideally; mixed formats are fine.
What you'll see after you submit
Paste two SBOMs → component delta + VEX stub
- Supports SPDX tag-value, SPDX JSON, and CycloneDX JSON inputs (mixed is fine).
- Flags components historically associated with KEV-listed vulnerabilities so triage starts in the right place.
- Generates a CycloneDX 1.5 VEX stub with not-affected dispositions you can edit and publish alongside your release.
- Designed for release-over-release SBOM hygiene the FDA expects under §524B postmarket maintenance.
Common misconceptions
What teams usually get wrong
-
Myth: A new SBOM each release is enough.
Reality: Reviewers and customers care about deltas. Why did this component appear, why did this version bump, and what's the VEX disposition for newly surfaced CVEs?
-
Myth: VEX is a one-time document.
Reality: VEX evolves with each release. The expectation is a VEX stream - not a static file.
-
Myth: If a component isn't on KEV it doesn't matter.
Reality: KEV is a floor, not a ceiling. EPSS, vendor advisories, and your own threat-model context all feed the disposition.
References & further reading
Primary sources behind this tool
- CycloneDX VEX specification - OWASP CycloneDX
- CISA Known Exploited Vulnerabilities (KEV) - CISA
- FIRST EPSS - FIRST
- FDA Cybersecurity in Medical Devices - SBOM expectations - FDA
Recent regulatory + supply-chain activity
Tracked signals that change what reviewers expect. Items move on as new ones land.
-
Apr 22, 2026CISA KEV
CISA adds use-after-free in Linux kernel netfilter to KEV (CVE-2026-0511)
-
Apr 15, 2026CISA KEV
BLE pairing bypass in widely embedded Bluetooth stack added to KEV
-
Jan 8, 2026CycloneDX
CycloneDX 1.6.1 errata - clarifies VEX status semantics for medical devices
-
Nov 12, 2025OpenSSF
SLSA v1.1 published - tightened build-provenance language for regulated industries
Where to take this next.
FDA-compliant SBOM services
Build the pipeline that produces a clean diff every release.
Learn moreSBOM Readiness scorer
How does your SBOM + supply-chain program score overall?
Learn moreComponent Risk Scorecard
Score any individual dependency before you accept it.
Learn moreMore tools
PCCP, 524B checker, threat model, wireless profiler.
Learn more