New AI Security Requirements

CISA and Global Partners Update SBOM Guidelines

Update, Software Bill of Materials, CISA, updated SBOM guidelines from CISA 2026, new minimum elements for Software Bill of Materials, CISA SBOM requirements for organizations, SBOM, Software
Facebook
X
LinkedIn
Reddit
WhatsApp

Five years after the release of the first version, CISA and international government partners have published an updated guideline defining the minimum elements of a Software Bill of Materials (SBOM).

The new “2026 Minimum Elements for a Software Bill of Materials” guideline replaces the minimum requirements introduced by the US National Telecommunications and Information Administration (NTIA) in 2021. According to CISA, the update incorporates more than 90 comments submitted during a public consultation process held the previous year.

Ad

An SBOM is designed to function as a software equivalent of an ingredient list, helping organizations create an accurate inventory of the software and components they use. According to the participating authorities, organizations can leverage this information to gain greater visibility into their software supply chains and make more informed risk management decisions, including when addressing known or newly discovered vulnerabilities.

The updated version maintains the core principles of the 2021 edition while improving data quality, expanding support for additional use cases, introducing new elements, removing others, and revising descriptions to improve clarity.

New and Removed SBOM Elements

Newly added elements include, among others, the hash algorithm and hash value of a component, its license information, an author signature, the name and version of the data format, the creation context, and the name and version of the tool used to generate the SBOM. The SBOM version itself is also now included as a required element.

Ad

Only two elements have been removed: access control and Software Identification Tags. Several other elements have been replaced, revised, or adjusted to improve data mapping. This includes the component name, which can now support multiple entries.

According to the authorities, the SBOM ecosystem has evolved significantly since 2021. Organizations can now request and process far more detailed information about their software supply chains and individual components than was possible five years ago.

Additional Requirements for AI Systems

The updated guideline applies broadly to all types of software. However, the authorities note that certain categories, including AI systems and Software-as-a-Service (SaaS), may require additional SBOM elements.

In May, government authorities from the G7 countries had already published a separate SBOM guideline specifically focused on AI systems.

(ll)

Ad

Weitere Artikel