CISA and International Partners Expand SBOM Requirements for Software Vendors
The Cybersecurity and Infrastructure Security Agency (CISA), working with the National Security Agency, the Federal Bureau of Investigation and 15 international cyber agencies, issued the “2026 Minimum Elements for a Software Bill of Materials” on July 29. The new guidance supersedes the 2021 minimum‑elements standard issued by the National Telecommunications and Information Administration, adding detailed requirements such as full component inventories, transitive dependencies, hash algorithms, licenses, author signatures and tool versions while removing access‑control and software‑identification tags.
The expanded baseline applies to all large organizations, including health‑system security teams, and shifts the negotiating position with software vendors. Recipients can now demand comprehensive data that enables precise vulnerability assessments, and the guidance notes that certain software types, such as AI systems and SaaS offerings, may need additional elements.
CISA says the changes reflect advances in SBOM tooling over the past five years and incorporate feedback from more than 90 public consultations, aiming to improve software‑supply‑chain transparency worldwide.
Entities: Cybersecurity and Infrastructure Security Agency (CISA) · Federal Bureau of Investigation (FBI) · Health systems · International cyber agencies · National Security Agency (NSA)