*:last-child]:mb-0 [&>*:last-child]:pb-0 [&>p]:font-normal text-left [&>.prm-button-bar]:justify-start [&_.portable-text-link]:font-semibold [&_.portable-text-link]:underline [&_.prm-button-bar_a]:no-underline [&_li]:text-light-gray [&_p]:text-light-gray">
Premier submitted recommendations to the Cybersecurity and Infrastructure Security Agency (CISA) on 2025 updates to the minimum elements for a software bill of materials (SBOM). Premier expressed support for the Administration's efforts to bolster the security of our software supply chains and to bring greater supply chain transparency and accountability to strengthen cybersecurity for critical infrastructure - including healthcare. In its detailed comments, Premier specifically recommends that CISA take the following actions to safeguard critical infrastructure:
-
Leverage the broad public and private sector influence of SBOM minimum elements;
-
Update certain data fields to make SBOM minimum elements more useful to stakeholders in critical infrastructure, including healthcare;
-
Incorporate Artificial Intelligence (AI) models into the "Dependency Relationship" field;
-
Require updates to SBOM minimum elements in regular and timely intervals; and
-
Consider ways to leverage the private sector contracting process to promote wider adoption of SBOM minimum elements and software supply chain visibility, security and resilience.