How AI is applied across API Evangelist and APIs.io. Read my AI disclosure →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC

NTIA Conformance Checker

Radar: Initial Apache-2.0

Checks an SPDX SBOM against the NTIA minimum elements and CISA guidance — whether it satisfies the baseline regulators actually ask for.

SPDX

Specifications it implements

What this tool does to each specification, in the role vocabulary. Follow a standard through to standards.apievangelist.com for what it actually specifies.

StandardRoleWhat that means
SPDX validates
Using this from an agent
Interfaces
clilibrary
Install
pypi ntia-conformance-checker
Consumes
spdx
Emits
json, text
Runtime
Runs offline Deterministic Read-only No credentials

Where it applies

Jobs this tool actually does, and the surface each one is exercised on.

Prove an SBOM meets a named compliance baseline, not just that it parses.
ci-pipelinecoding-agent

A well-formed SBOM and a compliant one are different things. This is the check that distinguishes them, and it is the one procurement will run.

Website
https://spdx.github.io/ntia-conformance-checker/
Repository
https://github.com/spdx/ntia-conformance-checker
License
Apache-2.0 — reported by the GitHub API, verified 2026-08-11
Stars
89 · last commit 2026-08-11
Reading this as an agent? Don't scrape the page — this entry is published as structured data at /tools.json, against the tool.schema.json schema, using the roles.json vocabulary. Start at /llms.txt.
arrow_back All tools by adoption