How namespace registration works

One table, forty-five rows

The CycloneDX property-taxonomy registry is one markdown table in a public repository, forty-five rows long at the time of writing, released under CC0 so anyone can reuse it without asking. Each row records a top-level namespace, who administers it, and either a link to the namespace’s taxonomy or the placeholder RESERVED.

Three of the rows are structural rather than vendors. cdx belongs to the CycloneDX working group and unofficial names must stay out of it, internal exists for properties that never leave the organisation, and urn is blocked to avoid colliding with Uniform Resource Names.

The neighbours

Twenty-eight rows point at live taxonomies. Amazon documents its Inspector properties there, GitLab and Siemens publish theirs, NVIDIA’s covers its Trustworthy-AI work. OWASP’s Dependency-Track and Lockheed Martin’s Hoppr share the table with scanners like Snyk, Sonatype and Veracode.

The closest precedent for what we filed is BSI’s row. Germany’s Federal Office for Information Security registered bsi and points it at a taxonomy expressing TR-03183, its cyber-resilience guideline, as properties on the standard model – an external document rendered as a namespace, which is the pattern the CBOM Profile follows.

What RESERVED means

Fourteen rows read RESERVED instead of a link. The registry’s own process note is plain that this is the entry state, new namespaces are registered as RESERVED first, and the link is added once the taxonomy documentation is public.

The state is neither limbo nor squatting. IBM, Red Hat, JFrog and ServiceNow hold RESERVED rows today, and the note also permits revocation where the promised documentation never appears.

Where issue #189 stands

Ours is issue #189 on the registry’s tracker, titled “Register top-level namespace: appliedquantum”. It was opened on August 14, 2026 and remains open as we write, with the row still to be added. From here, two steps remain in the process. The row is added as RESERVED, and the taxonomy link at github.com/appliedquantum/cyclonedx-property-taxonomy then replaces the placeholder.

When the row appears, the status wording on this site changes the same day, because the registry is the source of truth about the registry, and our documents follow it rather than the reverse.

A SHOULD, not a MUST

Nothing in the CycloneDX schema requires any of this. A property with an unregistered namespace is schema-valid, consumers ignore names they don’t read, and the internal namespace exists for names that aren’t anybody else’s business. The registry’s own recommendation tops out at SHOULD. Anyone creating custom properties outside internal should register a top-level namespace, and nothing stronger appears anywhere in the process.

Why file, then, when nothing forces you? Nobody checks an unregistered name for collisions, including the vendor who coined it, and one public table is where duplicates get caught before they ship. The taxonomy link is how tooling and reviewers find what a property means without asking. And the row is a dated, CC0 record of who claimed the name and when, citable by anyone.

IANA’s media-type vendor tree has worked the same way since 1996. Vendors put vnd. names in a public table, registration is encouraged rather than policed, unregistered names still function, and the table is what arbitrates when two products want one string.

What the record is for

For this profile the row is half of a discipline the exit policy completes. Names are claimed in a public registry on the way in, and fields are handed to the core through a published mapping on the way out, so nothing about the appliedquantum namespace ever depends on asking us what we meant. The release candidate is open for comment through October 31, 2026, and the row, when it lands, will be visible in the registry’s published table before we say a word about it.