CISA Updates Software Bill of Materials Guidance to Strengthen Supply Chain Security

The Cybersecurity and Infrastructure Security Agency (CISA), together with other U.S. government agencies and international organizations, released 2026 Minimum Elements for a Software Bill of Materials (SBOM), which incorporates feedback from more than 90 comments received during the public comment period. The minimum elements in this revision apply to SBOMs for all software, including open-source software, AI software, and software-as-a-service (SaaS).

Building on the 2021 National Telecommunications and Information Administration (NTIA) Minimum Elements for SBOM, CISA’s joint Minimum Elements for SBOM incorporates significant advancements and lessons learned from increased use of SBOM tools and practices. With these updated minimum elements, organizations are better positioned to make stronger risk-informed decisions, enhance their cybersecurity posture, and leverage scalable, machine-readable supply chain management processes.

“This advancement in SBOM minimum elements reflects the advancements we have made as a community in supply chain security. As we continue to see SBOMs adopted more widely, we want the SBOM minimum elements to paint a modern, comprehensive supply chain security picture,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “The comments CISA received significantly contributed to this timely revision, and we thank the SBOM community for their engagement.”

There are several new minimum elements, such as Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context. Several preexisting elements were updated for improved clarity, such as Author of SBOM Data changed to SBOM Author; Supplier Name changed to Component Producer; and Version of the Component, changed to Component Version. A summary of element changes is in Appendix B.

An SBOM is a formal record containing the details and supply chain relationships of the components in a software package. SBOMs provide those who produce, choose, and operate software with information that enhances their understanding of the software supply chain and strengthens risk management decisions.

The original announcement can be found here.

The Government Technology & Services Coalition's Homeland Security Today (HSToday) is the premier news and information resource for the homeland security community, dedicated to elevating the discussions and insights that can support a safe and secure nation. A non-profit magazine and media platform, HSToday provides readers with the whole story, placing facts and comments in context to inform debate and drive realistic solutions to some of the nation’s most vexing security challenges.

Related Articles

- Advertisement -

Latest Articles