CISA and Partners Unveil Updated Software Bill of Materials Resource That Improves Transparency, Security and Risk-Informed Decision Making
CISA and partners released updated 2026 Minimum Elements for a Software Bill of Materials (SBOM), expanding guidance to cover all software types and incorporating feedback from over 90 public comments.
The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with U.S. and international partners, published the 2026 Minimum Elements for a Software Bill of Materials (SBOM), updating the 2021 NTIA framework. The revision applies to all software, including open-source, AI, and SaaS, and reflects lessons learned from broader SBOM adoption. Organizations can now make more informed risk decisions and improve cybersecurity through scalable, machine-readable supply chain processes. CISA Acting Executive Assistant Director for Cybersecurity Chris Butera highlighted the community’s role in shaping the updated guidance.
The updated SBOM minimum elements introduce new requirements such as Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context. Existing elements were refined for clarity, including renaming ‘Author of SBOM Data’ to ‘SBOM Author’ and ‘Supplier Name’ to ‘Component Producer.’ These changes aim to provide a clearer, more comprehensive view of software supply chain security. A summary of all updates is available in Appendix B of the document.
An SBOM is a formal record detailing the components and supply chain relationships within a software package. It enables producers, users, and operators to assess risks and make informed decisions about software adoption and management. The updated guidance strengthens these capabilities by standardizing key data points across all software types. CISA emphasizes SBOMs as a critical tool for enhancing transparency and security in software supply chains.
CISA serves as the nation’s cyber defense agency and leads efforts to reduce risks to critical infrastructure. The updated SBOM guidance aligns with this mission by improving supply chain visibility and risk management. Additional resources and information are available on CISA.gov, including the full SBOM documentation and implementation guidance.