How to Create a CycloneDX SBOM

Sep 8, 2023

This video walks you through how to generate a CycloneDX Software Bill of Materials (SBOM) using Mend.io.
You’ll see how quick and simple it is to produce a high-quality SBOM that supports software supply chain security, compliance, and transparency requirements.

What is a CycloneDX SBOM?

CycloneDX is a lightweight and industry-recognized SBOM standard designed for use in software supply chain risk management. An SBOM provides a detailed inventory of all open source components, dependencies, and licenses used in an application. CycloneDX is especially valuable because it’s widely supported and purpose-built to enable security, compliance, and operational use cases.

Generating an SBOM in CycloneDX format using Mend.io allows you to meet regulatory demands like U.S. Executive Order 14028 and support internal governance, all without adding friction to your development process.

How to Generate a CycloneDX SBOM with Mend.io

In this demo, you’ll learn how Mend.io makes it easy to generate a CycloneDX SBOM from your scanned projects. The video walks through each step: selecting your project, accessing the SBOM export feature, and downloading the output in CycloneDX format.

The resulting SBOM includes critical metadata about components, versions, licenses, and known vulnerabilities—giving you full visibility into your software composition. Whether you're building for a government customer, addressing compliance requirements, or simply improving transparency, this walkthrough shows how Mend.io helps you generate reliable, standards-based SBOMs in just a few clicks.