Medium New version us

CISA and partners release 2026 Minimum Elements for Software Bill of Materials with expanded scope and new requirements

Original title: 2026 Minimum Elements for a Software Bill of Materials (SBOM)

CISA, together with other U.S. government agencies and international organizations, released the 2026 Minimum Elements for a Software Bill of Materials (SBOM), which builds on the 2021 NTIA framework and incorporates feedback from over 90 public comments. The updated minimum elements now apply to all software types, including open-source software, AI software, and SaaS, with new elements such as Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context. Organizations using these updated SBOM minimum elements can make stronger risk-informed decisions, enhance their cybersecurity posture, and implement scalable, machine-readable supply chain management processes.

What changed

  • New minimum elements added: Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context
  • Scope expanded to explicitly include open-source software, AI software, and software-as-a-service (SaaS)
  • Renamed elements for improved clarity: 'Author of SBOM Data' changed to 'SBOM Author'; 'Supplier Name' changed to 'Component Producer'; 'Version of the Component' changed to 'Component Version'
  • Updated framework builds on 2021 NTIA Minimum Elements with advancements and lessons learned from increased use of SBOM tools and practices

Who is affected

All organizations that produce, choose, or operate software, including software vendors, open-source contributors, cloud service providers offering SaaS, AI software developers, and organizations managing software supply chains across all sectors.

Action
Action required
Language
EN

Frameworks

CISA

Open the original source