Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

CISA Updates SBOM Minimum Elements, Replacing 2021 NTIA Guidance

by Kristen Smith
July 30, 2026
in Cybersecurity, DHS, News
CISA logo. CISA and partner agencies released the 2026 Minimum Elements for a Software Bill of Materials.

CISA and partner agencies released the 2026 Minimum Elements for a Software Bill of Materials, replacing guidance the NTIA published in 2021.

  • The revised baseline was co-authored with the NSA, FBI and 15 international agencies
  • It adds 10 data fields, capturing details like the SBOM’s author signature
  • The baseline applies to open-source code, AI systems and software-as-a-service

CISA Updates SBOM Minimum Elements, Replacing 2021 NTIA GuidanceThe Cybersecurity and Infrastructure Security Agency has published a revised baseline for what a software bill of materials should contain, replacing guidance the National Telecommunications and Information Administration issued in 2021. CISA released the document Wednesday.

Table of Contents

    • You might also like
    • Army PAE Fires Launches ‘Reveille Forge’ to Accelerate Capability Deployment
    • VA FISMA Audit Flags Security Gaps, Issues 19 Recommendations
    • Commerce Department Signs $874M in CHIPS Act R&D Incentives
  • What Changed in the 2026 SBOM Minimum Elements?
  • How Does the Guidance Treat AI and Cloud Software?

You might also like

Army PAE Fires Launches ‘Reveille Forge’ to Accelerate Capability Deployment

VA FISMA Audit Flags Security Gaps, Issues 19 Recommendations

Commerce Department Signs $874M in CHIPS Act R&D Incentives

The National Security Agency, the FBI and 15 international cybersecurity agencies co-authored the guidance. CISA said it incorporated more than 90 comments received during a public comment period on a draft published last year.

The elements apply to software of every kind, including open-source code, artificial intelligence systems and software-as-a-service.

Software supply chain security is one of the many priorities shaping the Department of Homeland Security’s mission. The Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 10 will bring together agency leaders and industry executives to examine the cybersecurity and technology challenges facing the homeland security enterprise. Register now!

What Changed in the 2026 SBOM Minimum Elements?

The update adds 10 data fields. Four capture information about the SBOM document itself: an author signature, the tool used to generate the SBOM, the data format and the phase of the software lifecycle at which the SBOM was produced. Three more identify the component being documented through a cryptographic hash value, the algorithm behind that hash and the license the component carries.

Several existing elements were renamed. Supplier name becomes component producer, which the authors said resolves the ambiguity that had built up around software distributors. Author of SBOM data becomes SBOM author, and version of the component becomes component version.

Two changes expand the scope of what an SBOM must cover. The former depth element, which required only top-level dependencies, has become coverage and now requires all components, including transitive dependencies, with no limit on how deep the inventory must reach. Known unknowns becomes explicitly identifying unknown information, and now asks authors to distinguish between data they lack and data they are withholding.

The access control element is gone, folded into distribution and delivery. Software identification tags dropped off the list of accepted data formats, leaving two formats the guidance describes as widely used: System Package Data Exchange, or SPDX, and CycloneDX.

How Does the Guidance Treat AI and Cloud Software?

The minimum elements apply to AI systems and software-as-a-service, but the document adds no fields specific to either. For AI, it points to separate guidance CISA issued in May with the G7 Cybersecurity Working Group, titled Software Bill of Materials for AI – Minimum Elements. Canada, France, Germany, Italy, Japan, the United Kingdom and the European Union took part in that effort, which offered recommendations tailored to AI supply chains.

The authors flagged four areas for further work: cloud software, AI software, validating SBOM accuracy and correlating SBOM data with security advisories such as Vulnerability Exploitability eXchange and the Common Security Advisory Framework.

Chris Butera, CISA’s acting executive assistant director for cybersecurity, said the revision reflects how far supply chain security practices have advanced.

“As we continue to see SBOMs adopted more widely, we want the SBOM minimum elements to paint a modern, comprehensive supply chain security picture,” he added.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

DOW Awards $76.6B in Contracts to GDEB, HII for Submarine Construction Work

Next Post

Labor Department, HII Expand Maritime Workforce Development Partnership

Recommended For You

Gov’t, Industry Reps Discuss Emerging GPS Threats at Satellite 2019

by Brenda Marie Rivers
May 20, 2019
Gov't, Industry Reps Discuss Emerging GPS Threats at Satellite 2019

Government and private sector leaders cited hacking and spoofing as potential threats to the nation’s GPS systems during the 2019 Satellite conference in Washington, D.C., C4ISRnet reported Saturday....

Read moreDetails

Accenture Wins DoD’s 2020 Employer Support Freedom Award; Jimmy Etheredge, Vince Vlasho Quoted

by Sarah Sybert
October 9, 2020
The U..S. Department of Defense presentation of the Accenture 2020 Employer Support Freedom Award. L-R Dave Bockel, Major General (Ret.), Georgia Employer Support of the Guard and Reserve (ESGR) State Co-Chair; Kevin Wince, Georgia ESGR State Chair; Jimmy Etheredge, Accenture North America CEO; Greg Anderson, global HR COO: former executive sponsor of Military ERG.

The Department of Defense (DoD) has awarded Accenture its prestigious 2020 Employer Support Freedom Award for the company’s support of its National Guard and Reserve member employees. “We...

Read moreDetails

Edge Autonomy Capitalizes on Northern Alabama Tech Sector With New Location; John Purvis Quoted

by Charles Lyons-Burt
July 25, 2023
John Purvis

Unmanned technology purveyor Edge Autonomy has opened its fourth location, as of this month, in Huntsville, Alabama. With the establishment of the new facility, the company is looking...

Read moreDetails

Avaya’s “Life and Work Beyond 2020” Survey Reveals Organizations Play Key Role in Individuals’ Well-Being

by William McCormick
April 12, 2021
Avaya’s “Life and Work Beyond 2020” Survey Reveals Organizations Play Key Role in Individuals’ Well-Being

Avaya (NYSE: AVYA), a global leader in solutions to enhance and simplify communications and collaboration, today released the results of a new survey, “Life and Work Beyond 2020: The...

Read moreDetails

Army, HackerOne to Launch Bug Bounty Challenge

by Ramona Adams
July 22, 2026
Army, HackerOne to Launch Bug Bounty Challenge

The U.S. Army has partnered with HackerOne to create a bug bounty challenge that will engage eligible hackers in efforts to uncover security vulnerabilities in the military branch's systems. HackerOne said...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!