CISA and Partners Unveil Updated Software Bill of Materials Resource That Improves Transparency, Security and Risk-Informed Decision Making
WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA), together with other U.S. government agencies and international organizations, released 2026 Minimum Elements for a Software Bill of Materials (SBOM), which incorporates feedback from more than 90 comments received during the public comment period. The minimum elements in this revision apply to SBOMs for all software, including open-source software, AI software, and software-as-a-service (SaaS).
Building on the 2021 National Telecommunications and Information Administration (NTIA) Minimum Elements for SBOM, CISA’s joint Minimum Elements for SBOM incorporates significant advancements and lessons learned from increased use of SBOM tools and practices. With these updated minimum elements, organizations are better positioned to make stronger risk-informed decisions, enhance their cybersecurity posture, and leverage scalable, machine-readable supply chain management processes.
“This advancement in SBOM minimum elements reflects the advancements we have made as a community in supply chain security. As we continue to see SBOMs adopted more widely, we want the SBOM minimum elements to paint a modern, comprehensive supply chain security picture,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “The comments CISA received significantly contributed to this timely revision, and we thank the SBOM community for their engagement.”
There are several new minimum elements, such as Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context. Several preexisting elements were updated for improved clarity, such as Author of SBOM Data changed to SBOM Author; Supplier Name changed to Component Producer; and Version of the Component, changed to Component Version. A summary of element changes is in Appendix B.
An SBOM is a formal record containing the details and supply chain relationships of the components in a software package. SBOMs provide those who produce, choose, and operate software with information that enhances their understanding of the software supply chain and strengthens risk management decisions.
For more information and resources, visit Software Bill of Materials (SBOM) on CISA.gov.
###
About CISA
As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.
Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.
Fuente:
Leer la noticia original