SBOM Validator (BSI TR-03183-2 and CISA 2026 Minimum Elements)
Upload or paste a CycloneDX or SPDX JSON SBOM and check it against BSI TR-03183-2 v2.1.0, the German federal guideline that concretises the CRA SBOM requirement. The validator verifies the minimum specification version of CycloneDX 1.6 or SPDX 3.0.1. It checks every required data field for the SBOM and for each component, including creator, timestamp, dependencies, licences, and hashes. Validation runs entirely in your browser. The same document is also assessed against the 2026 Minimum Elements for a Software Bill of Materials, version 2.1. CISA published this specification with seventeen partner agencies, including seven EU national cybersecurity authorities. That document replaced the 2021 NTIA minimum elements and expanded the field count from seven to seventeen. It is not EU law and creates no CRA obligation, but it is increasingly what procurement asks for. The two verdicts are reported separately and never blended because the frameworks disagree on key requirements. TR-03183-2 sets minimum format versions that the 2026 elements do not. In addition, the 2026 elements require transitive dependency coverage that CRA Annex I Part II(1) does not.
Last updated 29 August 2026
Key takeaways
- BSI TR-03183-2 version 2.1.0 sets CycloneDX 1.6 or SPDX 3.0.1 as the minimum SBOM format versions.
- CRA Annex I Part II(1) requires a software bill of materials in a machine-readable format, covering at the very least the top-level dependencies.
- BSI TR-03183-2 requires component entries to include creator, name, version, dependencies, licences, and SHA-512 hashes.
- The 2026 Minimum Elements for a Software Bill of Materials, version 2.1 expands required data fields from seven to seventeen.
Validate your SBOM against BSI TR-03183-2 and the 2026 Minimum Elements
Upload or paste a CycloneDX or SPDX JSON document. Validation runs entirely in your browser. Your SBOM is never uploaded or stored.
Frequently asked
What does BSI TR-03183-2 require from an SBOM?
Is an SBOM mandatory under the CRA?
My SBOM is CycloneDX 1.4 or SPDX 2.3. Is that a problem?
Does this tool upload my SBOM anywhere?
Can vulnerability information be included in the SBOM?
What changed in the 2026 SBOM Minimum Elements compared with the 2021 NTIA version?
Do the 2026 Minimum Elements apply to me as an EU manufacturer?
Why does my SBOM pass one framework and fail the other?
Other free CRA tools
Ready to automate your CVD programme?
CVD Portal integrates all these tools and handles your Article 13 and 14 obligations automatically.
Start your free portal →