[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fxvo_TxcfPSZBPGK87B_2Rb4GvfBtNHnM1pP01qt6O08":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":30,"category":31,"article_tags":34},"38a5de1b-41a4-4696-a492-862617439de5","2026 Minimum Elements for a Software Bill of Materials (SBOM)","2026-minimum-elements-for-a-software-bill-of-materials-sbom-034520","CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document. An SBOM serves as an “ingredients list” for software and is a key building block of software security and supply chain risk management. Organizations can use SBOM data to better understand the makeup of their software components and supply chains and make more risk-informed decisions. Minimum elements for an SBOM describe the baseline technologies and practices that an SBOM should include. While the minimum elements for an SBOM apply to all software, some software types—such as artificial intelligence and software as a service in cloud environments—may require additional elements. Any effort to improve software transparency, regardless of the software type, should begin with the application of minimum elements.","CISA, NSA, FBI, and international partners have released updated guidance on the minimum elements required for a Software Bill of Materials (SBOM). This new guidance, titled '2026 Minimum Elements for a Software Bill of Materials (SBOM)', replaces the 2021 NTIA document and incorporates feedback from a 2025 public comment period. SBOMs are crucial for software security and supply chain risk management, acting as an 'ingredients list' to help organizations understand their software components and make risk-informed decisions.","US agencies and international partners release updated SBOM minimum elements guidance.","PUBLICATION 2026 Minimum Elements for a Software Bill of Materials (SBOM) Publish DateJuly 29, 2026 2026 Minimum Elements for a Software Bill of Materials (SBOM) Related topics: Critical Infrastructure Security and Resilience , Cybersecurity Best Practices , Information and Communications Technology Supply Chain Security CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document. An SBOM serves as an “ingredients list” for software and is a key building block of software security and supply chain risk management. Organizations can use SBOM data to better understand the makeup of their software components and supply chains and make more risk-informed decisions. Minimum elements for an SBOM describe the baseline technologies and practices that an SBOM should include. While the minimum elements for an SBOM apply to all software, some software types—such as artificial intelligence and software as a service in cloud environments—may require additional elements. Any effort to improve software transparency, regardless of the software type, should begin with the application of minimum elements. Tags Audience: Federal Government, Industry, Small and Medium Businesses, State, Local, Tribal, and Territorial Government Language: English Topics: Critical Infrastructure Security and Resilience, Cybersecurity Best Practices, Information and Communications Technology Supply Chain Security Related Resources Jun 26, 2026 External Russian Intelligence Services Continue to Target Commercial Messaging Applications May 12, 2026 External, Publication Software Bill of Materials for AI - Minimum Elements Feb 04, 2025 External, Publication Guidance and Strategies to Protect Network Edge Devices Jul 28, 2026 External CI Fortify – Advice for isolating vital systems","https:\u002F\u002Fwww.cisa.gov\u002Fresources-tools\u002Fresources\u002F2026-minimum-elements-software-bill-materials-sbom",null,"2026-07-29T12:00:00+00:00","2026-07-29T16:00:23.319249+00:00",7,[18,21,23,25,27],{"name":19,"type":20},"CISA","vendor",{"name":22,"type":20},"National Security Agency",{"name":24,"type":20},"FBI",{"name":26,"type":20},"NTIA",{"name":28,"type":29},"SBOM","technology","26b0b636-0e31-4db1-bffb-61bdf9f20a58",{"id":30,"icon":13,"name":32,"slug":33},"Supply Chain","supply-chain",[35,40,42],{"category":36},{"id":37,"icon":13,"name":38,"slug":39},"217d3263-c763-41ca-875e-06901f522fe0","NIST","nist",{"category":41},{"id":30,"icon":13,"name":32,"slug":33},{"category":43},{"id":44,"icon":13,"name":45,"slug":46},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",[]]