07/29/2026 | Press release | Distributed by Public on 07/29/2026 08:14
FORT MEADE, Md. - Today, the National Security Agency (NSA), and others join with Cybersecurity and Infrastructure Security Agency (CISA) to release the joint Cybersecurity Information Sheet, "2026 Minimum Elements for a Software Bill of Materials (SBOM)."
An SBOM is a nested inventory, a "list of ingredients" that makes software applications by providing organizations with detailed data about their software supply chain. This comprehensive guidance builds on the foundational principles established in the Minimum Elements for a Software Bill of Materials published by the National Telecommunications and Information Administration (NTIA) in 2021, incorporating technological advancements to enhance software security and supply chain transparency.
The CSI introduces several new elements to support more risk-informed decisions about software security, including SBOM Author Signature, SBOM Version, and Component Hash Value. Major updates to existing elements clarify the scope and specify expectations for the elements, such as SBOM Author, Component Identifiers, and Coverage. Minor updates improve information quality and align with technological developments, such as SBOM Timestamp, Component Dependency Relationship, and Distribution and Delivery. These changes in the minimum SBOM elements expected for all software ensure that SBOMs remain a robust software transparency tool for assessing and mitigating cybersecurity risks.
SBOM has emerged as a key building block in software security and software supply chain risk management. The hierarchical structure of SBOMs captures the relationships between components supporting automated analysis and sharing. This visibility enables organizations to transform data into insights, driving machine-speed actions to reduce risks to software security.
The minimum elements apply to all software types, including open-source software, AI software, and Software as a Service (SaaS). These minimum element standards for the technologies and practices that an SBOM should adhere to, enabling automated supply chain analysis, which is critical for managing the high volume of software and ensuring security at scale. The updated elements refine how organizations should generate and request SBOMs. While additional elements may be necessary for more complex software systems, all SBOMs should include the minimum elements to ensure transparency and risk management.
As new use cases emerge and technology evolves, SBOM minimum elements will continue to evolve to provide transparency into software components. Analysis of SBOMs transforms data into insights about associated risks. Organizations can then use those insights to drive security decisions about their software systems. For example, vulnerability management tools can ingest SBOMs, analyze the data, and map it to other data sources, enabling organizations to leverage data, intelligence, and actions driven by SBOMs.
Additional Resources
NSA Media Relations [email protected] 443-634-0721
About the National Security Agency
Founded in 1952, NSA is a U.S. Department of War combat support agency and element of the U.S. Intelligence Community. The Agency's mission is to provide foreign signals intelligence to policy makers and our military, and to prevent and eradicate cybersecurity threats to U.S. National Security Systems, with a focus on the Defense Industrial Base and the improvement of U.S. weapons' security. From protecting U.S. warfighters around the world to enabling and supporting operations on land, in the air, at sea, in space, and in the cyber domain, NSA is committed to building public trust through transparency and protecting civil liberties and privacy consistent with our nation's values.
###