A CBOM can pass schema validation and still be wrong
A published CBOM from a PQC vendor validated cleanly against the CycloneDX schema and was wrong in three separate, load-bearing ways. The schema validates shape, not meaning.
Where this came up
A Cryptography Bill of Materials exists to answer one question: what in this system is quantum-vulnerable today, and what already isn't. A reader trusts a CBOM that validates against the CycloneDX schema to at least be internally coherent, even before checking whether its inventory is complete. That trust doesn't hold. Schema validation checks that each field has a shape the schema permits — the right type, a value from an allowed enum, required keys present. It has no opinion on whether the combination of fields on one component makes sense, or on whether the document as a whole does the one job it exists to do.
Three defects the schema does not catch
An HSM typed as an algorithm. One component, a hardware security module,
carried assetType: "algorithm" and, further down, a
nistQuantumSecurityLevel field — which the CycloneDX cryptographic-asset
spec defines under algorithmProperties, not under any device or module type.
The schema's assetType enum allows the literal string "algorithm"
on any component regardless of what that component actually is, so an HSM wearing an
algorithm's type, with an algorithm-only property attached to it, passes without
complaint. Nothing in the schema cross-checks a component's declared type against which
properties it's allowed to carry.
A kernel module typed as a protocol. Same shape of problem, different
pairing: a kernel module recorded with assetType: "protocol". Both strings are
valid enum members. Whether the specific component they're attached to is actually a
protocol is a semantic judgment the schema was never asked to make.
No classical algorithms anywhere in the document. The CBOM listed only post-quantum algorithms — not one classical algorithm anywhere in the whole inventory. That inverts the entire point of a migration inventory, which exists to show what is quantum-vulnerable today, not to catalog the destination. A schema-valid CBOM that omits every classical algorithm in the system it describes is not an edge case the validator missed; it's a complete document that answers the wrong question, and the schema has no field for "is this migration inventory actually an inventory of what needs migrating."
The thesis, in one line
Schema validation checks shape. It does not check meaning. A CBOM can be fully CycloneDX-schema-valid and still misclassify what its components are, misplace their properties, and omit the one category of information the document exists to surface.
If you have a CBOM lying around, you can check it against the three defects above (and a few related ones) yourself, offline, with no vendor or product named either way: github.com/actaseal/cbom-check.