Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

CISA Updates SBOM Minimum Elements, Replacing 2021 NTIA Guidance

by Kristen Smith
July 30, 2026
in Cybersecurity, DHS, News
CISA logo. CISA and partner agencies released the 2026 Minimum Elements for a Software Bill of Materials.

CISA and partner agencies released the 2026 Minimum Elements for a Software Bill of Materials, replacing guidance the NTIA published in 2021.

  • The revised baseline was co-authored with the NSA, FBI and 15 international agencies
  • It adds 10 data fields, capturing details like the SBOM’s author signature
  • The baseline applies to open-source code, AI systems and software-as-a-service

CISA Updates SBOM Minimum Elements, Replacing 2021 NTIA GuidanceThe Cybersecurity and Infrastructure Security Agency has published a revised baseline for what a software bill of materials should contain, replacing guidance the National Telecommunications and Information Administration issued in 2021. CISA released the document Wednesday.

Table of Contents

    • You might also like
    • FEMA Appoints Steven McAndrews as CIO
    • Raytheon Lands $23B Navy Tomahawk Missile Contract
    • DHA Seeks Industry Input on Modernizing Joint Medical Planning Tools
  • What Changed in the 2026 SBOM Minimum Elements?
  • How Does the Guidance Treat AI and Cloud Software?

You might also like

FEMA Appoints Steven McAndrews as CIO

Raytheon Lands $23B Navy Tomahawk Missile Contract

DHA Seeks Industry Input on Modernizing Joint Medical Planning Tools

The National Security Agency, the FBI and 15 international cybersecurity agencies co-authored the guidance. CISA said it incorporated more than 90 comments received during a public comment period on a draft published last year.

The elements apply to software of every kind, including open-source code, artificial intelligence systems and software-as-a-service.

Software supply chain security is one of the many priorities shaping the Department of Homeland Security’s mission. The Potomac Officers Club’s 2026 Homeland Security Summit on Nov. 10 will bring together agency leaders and industry executives to examine the cybersecurity and technology challenges facing the homeland security enterprise. Register now!

What Changed in the 2026 SBOM Minimum Elements?

The update adds 10 data fields. Four capture information about the SBOM document itself: an author signature, the tool used to generate the SBOM, the data format and the phase of the software lifecycle at which the SBOM was produced. Three more identify the component being documented through a cryptographic hash value, the algorithm behind that hash and the license the component carries.

Several existing elements were renamed. Supplier name becomes component producer, which the authors said resolves the ambiguity that had built up around software distributors. Author of SBOM data becomes SBOM author, and version of the component becomes component version.

Two changes expand the scope of what an SBOM must cover. The former depth element, which required only top-level dependencies, has become coverage and now requires all components, including transitive dependencies, with no limit on how deep the inventory must reach. Known unknowns becomes explicitly identifying unknown information, and now asks authors to distinguish between data they lack and data they are withholding.

The access control element is gone, folded into distribution and delivery. Software identification tags dropped off the list of accepted data formats, leaving two formats the guidance describes as widely used: System Package Data Exchange, or SPDX, and CycloneDX.

How Does the Guidance Treat AI and Cloud Software?

The minimum elements apply to AI systems and software-as-a-service, but the document adds no fields specific to either. For AI, it points to separate guidance CISA issued in May with the G7 Cybersecurity Working Group, titled Software Bill of Materials for AI – Minimum Elements. Canada, France, Germany, Italy, Japan, the United Kingdom and the European Union took part in that effort, which offered recommendations tailored to AI supply chains.

The authors flagged four areas for further work: cloud software, AI software, validating SBOM accuracy and correlating SBOM data with security advisories such as Vulnerability Exploitability eXchange and the Common Security Advisory Framework.

Chris Butera, CISA’s acting executive assistant director for cybersecurity, said the revision reflects how far supply chain security practices have advanced.

“As we continue to see SBOMs adopted more widely, we want the SBOM minimum elements to paint a modern, comprehensive supply chain security picture,” he added.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

DOW Awards $76.6B in Contracts to GDEB, HII for Submarine Construction Work

Next Post

Labor Department, HII Expand Maritime Workforce Development Partnership

Recommended For You

CISA Updates Known Exploited Vulnerabilities Catalog With 2 New Additions

by Jane Edwards
June 7, 2024
CISA Updates Known Exploited Vulnerabilities Catalog With 2 New Additions

The Cybersecurity and Infrastructure Security Agency has added two known exploited cyber vulnerabilities posing serious risks to federal agencies to its catalog. Federal civilian executive branch agencies are ordered to address...

Read moreDetails

CISA Calls on Network Defenders to Take Action Against Adobe ColdFusion Vulnerability Risks

by Jerry Petersen
May 20, 2024
Person using a PC_272x270

The Cybersecurity and Infrastructure Security Agency has issued an advisory concerning the exploitation of a vulnerability within select versions of the Adobe ColdFusion web application development platform that...

Read moreDetails

CBP Implements Mobile Passport Control Tool at Sacramento Intl Airport; Brian Humphrey Comments

by Jay Clemens
July 22, 2026
CBP Implements Mobile Passport Control Tool at Sacramento Intl Airport; Brian Humphrey Comments

The U.S. Customs and Border Protection has implemented the Mobile Passport Control application in California's Sacramento International Airport as part of efforts to speed up processing at major...

Read moreDetails

Amyx Appoints John Selman as COO; William Schaefer Quoted

by William McCormick
April 19, 2021
John Selman

Amyx announced on Monday that its appointment of John Selman as chief operating officer. In this role, Selman will continue to support Amyx’s recent growth by overseeing the...

Read moreDetails

DARPA to Develop Self-Healing Computers

by Miles Jamison
January 21, 2025
DARPA to Develop Self-Healing Computers

The Defense Advanced Research Projects Agency plans to develop self-healing computers that are capable of safeguarding themselves from cyberattacks.The agency said Friday these capabilities are possible by addressing gaps...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • C5ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • Department of War
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Intelligence Community
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Technology
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • Department of War
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!