Back to Feed
PolicyJul 30, 2026

US and Allies Update SBOM Guidance

US and 13 allies update SBOM guidance for software supply chain security.

Summary

The US and 13 allied nations have released updated guidance on the minimum elements required for a Software Bill of Materials (SBOM). This refresh, building on 2021 guidance, aims to enhance software security and supply chain risk management by reflecting advancements in SBOM tooling and addressing feedback. New elements include component hash details, license information, and signature data, while some previous elements like SWID tags have been removed or updated for clarity and broader use cases.

Full text

Government agencies in the US and 13 allied countries this week released updated guidance on the minimum elements of a software bill of materials (SBOM). Meant to reflect the changes in supply chain security and software transparency, the document builds on the SBOM Minimum Elements guidance that NTIA released in 2021 and takes into consideration comments received during the public feedback period last year. An SBOM, the authoring agencies say, should serve as a “key building block of software security and supply chain risk management,” helping organizations build accurate inventories of the software and software components within their environments. In this regard, the updated minimum elements for an SBOM (PDF) guidance provides a baseline of the technologies and practices expected to be included in an SBOM. “Organizations that produce, procure, and operate software can use SBOM data to better understand their software supply chain. Increased software supply chain visibility can drive risk management decisions, including addressing known and newly discovered vulnerabilities and risks,” the guidance reads. The updated document preserves the core principles of the 2021 SBOM Minimum Elements while reflecting current SBOM needs. It improves data quality, supports a broader range of use cases and applications, introduces new elements, removes others, and updates descriptions for improved clarity.Advertisement. Scroll to continue reading. New additions include the Component Hash Algorithm, Component Hash Value, Component License, Author Signature, Data Format Name, Data Format Version, Generation Context, Tool Name, Tool Version, and SBOM Version elements. While only two elements were removed from the updated guidance, namely Access Control and Software Identification (SWID) Tags, multiple elements were replaced, others were clarified or rewritten, and others were modified to improve data mapping, such as the component name, which now allows multiple entries. “SBOM tooling has advanced, driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs. These advancements enable organizations requesting SBOMs to demand more information about their supply chain and software components than they could have in 2021,” the guidance reads. According to the authoring agencies, while the document applies to all software, some types of software, such as AI systems and SaaS, may require additional elements. In May, government agencies from Group of Seven (G7) countries released SBOM guidance for AI. Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure Related: Are SBOMs Failing? Supply Chain Attacks Rise as Security Teams Struggle With SBOM Data Related: US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security Related: How to Conduct a Successful Audit of AI-Driven Software Development Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire US, Australia Release OT Isolation Guidance for Critical Infrastructure Spur Raises $200 Million for IP Intelligence PlatformJFrog Zero-Days Exploited in OpenAI-Hugging Face HackShinyHunters Claims Ernst & Young HackOT Security Startup Frenos Raises $1.52 MillionHush Security Raises $30 Million for AI Agent GovernanceGoogle Adopts New Threat Actor Naming SystemUnpatched Fastjson Vulnerability Exploited in Attacks Latest News Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 1 in 5 Data Center Assets Are Within Easy Reach of AttackersChrome 151 Patches 370 VulnerabilitiesCisco Secure FMC Zero-Day Exploited in the WildUS Bans Foreign-Made Humanoid Robots, Targeting China Over National SecurityMate Security Raises $35 Million for Agentic SOCThreatLocker Raises $190 Million in Series F FundingCritical VM Escape Vulnerability Patched in VMware ESXi Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveAlex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER).More People On The MoveExpert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email

Entities

SBOM (technology)NTIA (vendor)