generated: '2026-07-20' method: searched source: >- http://xcbl.org/about.shtml, http://xcbl.org/xcbl40/documentation/releasenotes.shtml, http://xcbl.org/faq.shtml scope: xCBL 4.0 (XML Common Business Library) published by Commerce One standards: - id: w3c-xml-schema name: W3C XML Schema (XSDL 1.0) conforms: true evidence: >- xCBL 4.0 is the first xCBL release using W3C XML Schema (XSDL) as the canonical form; the distribution ships 709 .xsd modules. Source: http://xcbl.org/xcbl40/documentation/releasenotes.shtml - id: xml-namespaces name: XML Namespaces conforms: true evidence: >- xCBL 4.0 uses multiple namespaces (one core plus eight functional areas) under the rrn:org.xcbl: scheme to allow independent versioning. - id: oasis-ubl name: OASIS Universal Business Language (UBL) conforms: partial evidence: >- Release notes describe xCBL 4.0 as "an initial alignment with the OASIS Universal Business Language (UBL) initiative"; some UBL recommendations (including multiple namespaces) were adopted, with more intended as UBL matured. Not a UBL conformance claim. - id: edi name: EDI (ANSI X12 / UN/EDIFACT semantics) conforms: partial evidence: >- "xCBL 4.0 ... provides a smooth migration path from EDI-based commerce because of its origins in EDI semantics." Source: http://xcbl.org/about.shtml Mapping resources are published under /xcbl40/otherresources.shtml. - id: rosettanet name: RosettaNet conforms: partial evidence: >- xCBL was developed from analysis of existing e-commerce standards including EDI and RosettaNet. Source: http://xcbl.org/about.shtml - id: sox name: SOX (Schema for Object-Oriented XML) conforms: superseded evidence: >- SOX was the schema language Commerce One created and used in its own products; it was the canonical form for xCBL 2.x/3.x and was superseded by XSDL in 4.0. SOX influenced W3C XML Schema and JAXB. - id: xdr name: XDR / BizTalk schemas conforms: legacy evidence: >- xCBL 2.0/3.0/3.5 were additionally published as XDR schemas, including sets designed for Microsoft BizTalk Server. Not carried forward into 4.0. - id: xml-dtd name: XML DTD conforms: legacy evidence: xCBL 2.0/3.0 were additionally published in DTD form; not carried forward into 4.0. - id: oauth2 name: OAuth 2.0 conforms: false evidence: No HTTP API surface and no OAuth documentation published; xCBL predates OAuth. - id: rfc9457 name: RFC 9457 Problem Details conforms: false evidence: >- Errors are modelled as xCBL ErrorResponse/ApplicationResponse business documents in the messagemanagement namespace, not as problem+json. See errors/commerce-one-problem-types.yml certifications: [] compliance_programs: [] notes: >- No security or privacy compliance certifications (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP) are published — Commerce One ceased operating in 2004 and xcbl.org survives only as a static archival distribution site. This artifact therefore carries no Compliance pointer.