Regulatory Digital Product Passports as a Catalyst for U. S. Supply Chain Visibility
Figure 2-2: SPDX 3.1 SupplyChain Profile Sub-Graph( Information View)
Figure 2-2 shows the machine-readable SPDX 3.1 SupplyChain-profile sub-graph corresponding to the ACME CAM-5200 product model. In this representation, hardware products, software artifacts, bundles, supply chain events, assertions, and external references are serialized using SPDX 3.1 concepts and vocabulary. The model captures events such as component receipt, assembly, functional testing, packaging, and shipment, while linking those events to associated compliance assertions and supporting references.
In SPDX 3.1 terms, assertions and external references serve different purposes. Assertions express claims about a product, component, or lifecycle event, while external references identify supporting standards, certifications, documents, or evidence artifacts associated with those claims. Lifecycle events establish provenance and custody relationships that may support or contextualize an assertion but remain analytically distinct from the assertion itself.
For example, assertions attached to the SPDX model may include RoHS compliance, REACH compliance, cybersecurity baseline compliance, or country-of-origin claims, while external references may point to ISO 14067 carbon footprint documentation or IEC 62443-4-2 security requirements. Because the SPDX 3.1 SupplyChain profile preserves relationships among packages, events, assertions, and references as a graph rather than isolated records, organizations can aggregate these sub-graphs across suppliers and products to support supplierrisk analysis, due diligence, cyber supply chain assessments, sustainability reporting, circularity analysis, and resilience planning.
The distinction between the two figures is important. Figure 1 represents the operational supply chain ecosystem itself, while Figure 2 represents the portable, machine-readable information artifact that describes a portion of that ecosystem using standardized SPDX 3.1 semantics. When many such SPDX sub-graphs are normalized and aggregated, they can be stitched into strategic aggregated supply chain graphs capable of supporting enterprise-scale analytics and decisionmaking.
SPDX 3.1 supply chain modeling is action-centric rather than BOM-centric alone. Manufacturing, transport, assembly, testing, packaging, and shipment activities are represented as graph-
EDM Association – Journal of Innovation 29