status: label — Raised → Deliberating → Converging → Decided. Open
exploration starts as a Discussion; once it narrows
to a concrete choice it becomes an Issue, which is closed
and linked to the change that implements it. The decision rule is lazy consensus.
The thirteen aspects
From Section 3 of the scoping document, Defining CBOM Profiles. Each aspect has one canonical tracking issue — please comment on the existing thread rather than opening a parallel one.
-
What a given profile is for and where its boundaries lie — the use case it serves and what it deliberately leaves out.
-
How a profile names and versions itself so it can be referenced, compared and pinned to a specific revision.
-
The core set of cryptographic attributes a profile constrains, defined independently of any serialization format. Most other aspects build on this — settle it first.
-
How MUST / SHOULD / MAY (BCP 14) apply to profile attributes, and what "conforming" actually means for a producer and a consumer.
-
How a CBOM is checked against a profile — the validation rules and the machinery that turns a profile into a pass/fail result.
-
Normative mappings from the format-independent model onto CycloneDX and SPDX. Cross-cutting — discussed here and linked from other aspects rather than re-argued.
-
Agreeing identifiers and value vocabularies (e.g. the CycloneDX Cryptography Registry, purl) so the same thing is named the same way. Cross-cutting.
-
How a CBOM profile sits alongside and links to software and hardware BOMs rather than duplicating them.
-
How profiles extend the base model and how several profiles combine, so one CBOM can satisfy more than one profile at once.
-
Expressing migration intent and PQC-readiness (planned vs implemented state). Mainly relevant to migration-oriented profiles.
-
How a profile is proposed, versioned, revised and retired over time, and who is accountable for it.
-
Keeping profiles aligned with the regulations and guidance in the reference register — so a profile demonstrably satisfies what regulators ask for.
-
The concrete outputs that make the methodology usable: a profile template, worked examples, and tooling hooks.
Where to start
Begin with 3.3
The format-independent attribute model underpins most other aspects — settling it first avoids rework.
3.6 and 3.7 are cross-cutting
Format mapping and normalisation are discussed in their own issues and linked from others, rather than re-argued in every thread.
3.10 is migration-flavoured
Roadmap and PQC-readiness information mainly concern migration-oriented profiles; related
topics carry an orientation: label.
See the whole board
The project board shows all thirteen at once, so you can see what's stuck, converging or decided at a glance.
Status and issue numbers here mirror the repository's start-here table. If they drift, the README and the live issues are authoritative.