NTIA Conformance Checker
Checks an SPDX SBOM against the NTIA minimum elements and CISA guidance — whether it satisfies the baseline regulators actually ask for.
Specifications it implements
What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.
| Standard | Role | What that means |
|---|---|---|
| SPDX | validates |
- Interfaces
clilibrary- Install
-
pypi
ntia-conformance-checker - Consumes
- spdx
- Emits
- json, text
- Runtime
- Runs offline Deterministic Read-only No credentials
Where it applies
Jobs this tool actually does, and the surface each one is exercised on.
A well-formed SBOM and a compliant one are different things. This is the check that distinguishes them, and it is the one procurement will run.
- Website
- https://spdx.github.io/ntia-conformance-checker/
- Repository
- https://github.com/spdx/ntia-conformance-checker
- License
- Apache-2.0 — reported by the GitHub API, verified 2026-09-17
- Stars
- 91 · last commit 2026-09-07
/tools.json,
against the tool.schema.json
schema, using the roles.json
vocabulary. Start at /llms.txt.