CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

2026 Minimum Elements for a Software Bill of Materials (SBOM)

unknown
CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM) , that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document. An SBOM serves as an “ingredients list” for software and is a key building block of software security and supply chain risk management. Organizations can use SBOM data to better understand the makeup of their software components and supply chains and make more risk-informed decisions. Minimum elements for an SBOM describe the baseline technologies and practices that an SBOM should include. While the minimum elements for an SBOM apply to all software, some software types—such as artificial intelligence and software as a service in cloud environments—may require additional elements. Any effort to improve software transparency, regardless of the software type, should begin with the application of minimum elements.

CSIRTS triage

What
New guidance for Software Bill of Materials (SBOM) has been released.
Who is affected
Organizations involved in software development and supply chain management.
Urgency
Understanding SBOM is essential for software security and risk management.
Action
Review the new SBOM guidance and implement necessary practices.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
CISA Cybersecurity Advisories (US · national-cert · site)
Severity
unknown
Published
2026-07-29
Exploitation
Not in CISA KEV at last sync

Original advisory: https://www.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom

More from CISA Cybersecurity Advisories