Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news
No Result
View All Result
Executive Gov
No Result
View All Result
Home Cybersecurity

CISA Updates SBOM Minimum Elements, Replacing 2021 NTIA Guidance

by Kristen Smith
July 30, 2026
in Cybersecurity, DHS, News
CISA Updates SBOM Minimum Elements

CISA Updates SBOM Minimum Elements

  • The revised baseline was co-authored with the NSA, FBI and 15 international agencies
  • It adds 10 data fields, capturing details like the SBOM's author signature
  • The baseline applies to open-source code, AI systems and software-as-a-service

CISA Updates SBOM Minimum Elements, Replacing 2021 NTIA GuidanceThe Cybersecurity and Infrastructure Security Agency has published a revised baseline for what a software bill of materials should contain, replacing guidance the National Telecommunications and Information Administration issued in 2021. CISA released the document Wednesday.

Table of Contents

    • You might also like
    • Labor Department, HII Expand Maritime Workforce Development Partnership
    • DOW Awards $76.6B in Contracts to GDEB, HII for Submarine Construction Work
    • GSA, CORAS Ink OneGov Deal to Widen Federal AI Access
  • What Changed in the 2026 SBOM Minimum Elements?
  • How Does the Guidance Treat AI and Cloud Software?

You might also like

Labor Department, HII Expand Maritime Workforce Development Partnership

DOW Awards $76.6B in Contracts to GDEB, HII for Submarine Construction Work

GSA, CORAS Ink OneGov Deal to Widen Federal AI Access

The National Security Agency, the FBI and 15 international cybersecurity agencies co-authored the guidance. CISA said it incorporated more than 90 comments received during a public comment period on a draft published last year.

The elements apply to software of every kind, including open-source code, artificial intelligence systems and software-as-a-service.

Software supply chain security is one of the many priorities shaping the Department of Homeland Security's mission. The Potomac Officers Club's 2026 Homeland Security Summit on Nov. 10 will bring together agency leaders and industry executives to examine the cybersecurity and technology challenges facing the homeland security enterprise. Register now!

What Changed in the 2026 SBOM Minimum Elements?

The update adds 10 data fields. Four capture information about the SBOM document itself: an author signature, the tool used to generate the SBOM, the data format and the phase of the software lifecycle at which the SBOM was produced. Three more identify the component being documented through a cryptographic hash value, the algorithm behind that hash and the license the component carries.

Several existing elements were renamed. Supplier name becomes component producer, which the authors said resolves the ambiguity that had built up around software distributors. Author of SBOM data becomes SBOM author, and version of the component becomes component version.

Two changes expand the scope of what an SBOM must cover. The former depth element, which required only top-level dependencies, has become coverage and now requires all components, including transitive dependencies, with no limit on how deep the inventory must reach. Known unknowns becomes explicitly identifying unknown information, and now asks authors to distinguish between data they lack and data they are withholding.

The access control element is gone, folded into distribution and delivery. Software identification tags dropped off the list of accepted data formats, leaving two formats the guidance describes as widely used: System Package Data Exchange, or SPDX, and CycloneDX.

How Does the Guidance Treat AI and Cloud Software?

The minimum elements apply to AI systems and software-as-a-service, but the document adds no fields specific to either. For AI, it points to separate guidance CISA issued in May with the G7 Cybersecurity Working Group, titled Software Bill of Materials for AI – Minimum Elements. Canada, France, Germany, Italy, Japan, the United Kingdom and the European Union took part in that effort, which offered recommendations tailored to AI supply chains.

The authors flagged four areas for further work: cloud software, AI software, validating SBOM accuracy and correlating SBOM data with security advisories such as Vulnerability Exploitability eXchange and the Common Security Advisory Framework.

Chris Butera, CISA's acting executive assistant director for cybersecurity, said the revision reflects how far supply chain security practices have advanced.

“As we continue to see SBOMs adopted more widely, we want the SBOM minimum elements to paint a modern, comprehensive supply chain security picture,” he added.

Stay connected via Google News
Follow us for the latest travel updates and guides.
Add as preferred source on Google
Share5Tweet19
Previous Post

DOW Awards $76.6B in Contracts to GDEB, HII for Submarine Construction Work

Next Post

Labor Department, HII Expand Maritime Workforce Development Partnership

Recommended For You

Recent DoD IG Audit Reveals Lack of Software Rationalization in Branches

by Nichols Martin
December 20, 2018
Recent DoD IG Audit Reveals Lack of Software Rationalization in Branches

The Department of Defense's inspector general released the audit results to determine how the U.S. Navy, U.S. Marine Corps and U.S. Air Force rationalize software and manage obsolete and duplicate applications. The audit found the...

Read moreDetails

DoD Concludes ‘Hack the Proxy’ Ethical Hacking Effort

by Brenda Marie Rivers
October 31, 2019
DoD Concludes 'Hack the Proxy' Ethical Hacking Effort

The Department of Defense has conducted a bug bounty program with ethical hackers in an effort to identify vulnerabilities in the DoD Information Network, Fifth Domain reported Monday.

Read moreDetails

Los Alamos National Lab Launches Center for Quantum Computing

by Jane Edwards
February 5, 2026
Quantum computing. LANL established the Center for Quantum Computing to consolidate quantum research capabilities.

The Department of Energy’s Los Alamos National Laboratory has established a new center that aims to unify and expand its quantum research capabilities across national security, quantum computer...

Read moreDetails

Army Launches UAV Tech Contest for University Students

by Nichols Martin
September 16, 2019
Army Launches UAV Tech Contest for University Students

The U.S. Army invites university students to submit concepts on unmanned aerial vehicles for a chance to win up to $35K, Army Times reported Friday. Wichita State University organizes the C3...

Read moreDetails

Navy Refines Network Integration Engineering Facility

by Nichols Martin
June 27, 2019
Navy Refines Network Integration Engineering Facility

Naval Information Warfare Systems Command has applied new updates to its Network Integration Engineering Facility, a site working to integrate off-the-shelf products into military operations. NAVWAR said Wednesday that its...

Read moreDetails
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Sponsors

About ExecutiveGov

ExecutiveGov, published by Executive Mosaic, is a site dedicated to the news and headlines in the federal government. ExecutiveGov serves as a news source for the hot topics and issues facing federal government departments and agencies such as Gov 2.0, cybersecurity policy, health IT, green IT and national security. We also aim to spotlight various federal government employees and interview key government executives whose impact resonates beyond their agency.

CATEGORIES

  • Acquisition & Procurement
  • Announcements
  • Articles
  • Artificial Intelligence
  • Awards
  • Big Data & Analytics News
  • C4ISR
  • Civilian
  • Cloud
  • Contract Awards
  • Cybersecurity
  • Defense And Intelligence
  • Defense Security Cooperation
  • DHS
  • Digital Assets
  • Digital Modernization
  • DoD
  • Events
  • Executive Moves
  • Executive Spotlights
  • Federal Civilian
  • Financial Reports
  • Foreign Military Sales
  • General News
  • GovCon Expert
  • Government Cloud
  • Government Technology
  • GSA
  • Healthcare IT
  • Industry News
  • Intelligence
  • Legislation
  • M&A Activity
  • National Security
  • News
  • Policy Updates
  • Press Releases
  • Profiles
  • Space
  • Videos
  • Wash100
Sign Up For Our Newsletter
Subscribe to our mailing list to receives daily updates direct to your inbox!
Invalid email address
Your privacy is guranteed.
Thanks for subscribing!

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

No Result
View All Result
  • Home
  • Acquisition & Procurement
  • Agencies
    • DoD
    • Intelligence
    • DHS
    • Civilian
    • Space
  • Cybersecurity
  • Technology
  • Awards
  • News
  • About
  • Wash100
  • Contact Us
    • Advertising
    • Submit your news

Copyright 2026 Executive Mosaic. All Rights Reserved. Site Archive

Get your free GovCon news!

Get your latest GovCon news and insights. Become a VIP and subscribe to the GovConWire Daily News.

Invalid email address
We promise not to spam you. You can unsubscribe at any time.
Thanks for subscribing!