The Cybersecurity and Infrastructure Security Agency, working with other U.S. agencies and international partners, has issued updated guidance defining what a Software Bill of Materials should contain in 2026, widening its scope to cover open-source software, AI software, and software-as-a-service. The revision follows a public comment period that drew more than 90 submissions and is intended to help organizations make more informed risk decisions and automate supply chain management.
“This advancement in SBOM minimum elements reflects the advancements we have made as a community in supply chain security. As we continue to see SBOMs adopted more widely, we want the SBOM minimum elements to paint a modern, comprehensive supply chain security picture,” said Chris Butera, CISA’s acting executive assistant director for cybersecurity. “The comments CISA received significantly contributed to this timely revision, and we thank the SBOM community for their engagement.”
The document builds on the National Telecommunications and Information Administration’s 2021 Minimum Elements for SBOM, reflecting lessons from broader deployment of SBOM tools over the past several years. Among the additions are fields for Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context. Several existing elements were renamed for clarity, including changing Author of SBOM Data to SBOM Author, Supplier Name to Component Producer, and Version of the Component to Component Version. A summary of changes is provided in an appendix.
An SBOM is a formal inventory of the components within a software package and the relationships among them. Advocates say SBOMs help producers, purchasers, and operators understand software supply chains, identify vulnerable dependencies, and respond more quickly to emerging threats—an area of heightened attention since high-profile supply chain compromises and vulnerabilities earlier in the decade.
CISA said the updated minimum elements are designed to be used in machine-readable workflows and to support scalable supply chain security practices across both government and industry. The new guidance is available on CISA’s website.





