THE 2026 Minimum Elements for a Software Bill of Materials (SBOM) is a joint guidance document released by CISA, NSA, and FBI, updating prior SBOM standards from 2021. It aims to enhance software transparency, serving as an 'ingredients list' for software components to help organizations manage supply chain risks.
The guidance incorporates feedback from a 2025 public comment period and outlines essential elements that all software SBOMs should contain, noting that specific software types like AI and cloud services may need additional requirements. The document emphasizes the importance of using SBOMs to foster informed decision-making regarding software security.