Government agencies in the US and 13 allied countries have released updated guidance on the minimum elements required for a Software Bill of Materials (SBOM). This document builds upon the SBOM Minimum Elements guidance initially released by the NTIA in 2021 and incorporates feedback received during a public consultation period last year.
The updated guidance aims to reflect changes in supply chain security and software transparency. SBOMs are intended to serve as a foundational component for software security and supply chain risk management, enabling organizations to create accurate inventories of software and its components within their environments. Increased visibility into the software supply chain can inform risk management decisions, including addressing known and newly discovered vulnerabilities.
The updated document maintains the core principles of the 2021 guidance while addressing current SBOM requirements. It introduces new elements such as Component Hash Algorithm, Component Hash Value, Component License, Author Signature, Data Format Name, Data Format Version, Generation Context, Tool Name, Tool Version, and SBOM Version. Two elements, Access Control and Software Identification (SWID) Tags, were removed, while others were replaced, clarified, or modified to improve data mapping and quality.
The agencies note that SBOM tooling has advanced significantly, driven by a growing number of organizations generating, sharing, consuming, and analyzing SBOMs. These advancements allow organizations requesting SBOMs to demand more detailed information about their supply chain and software components than was possible in 2021. While the document applies broadly to all software, specific types like AI systems and SaaS may require additional elements.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Government agencies from the US and 13 allied countries have released updated guidance for Software Bill of Materials (SBOM) minimum elements. This update reflects advancements in supply chain security and software transparency, providing a baseline for technologies and practices in SBOMs.