PUBLISHED DATE: 31 July 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the co-authoring organisations, has updated the Minimum Elements for a Software Bill of Materials (SBOM) to reflect current SBOM needs.
Why SBOM: Enhancing transparency and security
SBOMs are a critical step toward achieving software component transparency, illuminating the software supply chain, and better positioning organisations to make risk-informed decisions regarding the components that make up their software systems. Components can include traditional software, firmware, AI systems, and SaaS. An SBOM serves as an ingredients list for software, providing organizations with data about the makeup of their software. Organisations can transform that data into insights that can drive machine-speed actions to reduce risks to the security of their software systems.
Why minimum elements: Driving security at scale
The volume of software used by modern organisations is too high for manual processes to effectively assess and mitigate risks. Given the role of software in enabling essential functions and critical infrastructure, software that no one tracks and manages poses a significant cybersecurity threat, including to critical infrastructure and government systems.
Shared expectations for SBOMs help organisations apply SBOM data to software and supply chain security practices and facilitate information sharing. Organisations across the software ecosystem and practitioners around the world have recognised the valuable role of SBOMs in increasing software and supply chain transparency and have contributed to the growth of SBOM adoption and advancement of SBOM technological implementation.
As SBOM adoption continues to spread globally across industries and sectors, the importance of harmonising expectations for SBOM will only increase.
2026 Minimum Elements for a Software Bill of Materials (SBOM) [PDF, 1.2 MB]
This guidance was co-authored by:
- U.S. National Security Agency (NSA)
- U.S. Federal Bureau of Investigation (FBI)
- Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC)
- Canadian Centre for Cyber Security (Cyber Centre)
- Czech National Cyber and Information Security Agency (NÚKIB)
- French Cybersecurity Agency (ANSSI)
- Germany Federal Office for Information Security (BSI)
- Indian Computer Emergency Response Team (CERT-In)
- Italy National Cybersecurity Agency (ACN)
- Japan Ministry of Economy, Trade and Industry (METI)
- Japan National Cybersecurity Office (NCO)
- Republic of Korea National Intelligence Service/National Cyber Security Center (NIS/NCSC)
- Korea Internet and Security Agency (KISA)
- Netherlands National Cyber Security Centre (NCSC-NL)
- New Zealand National Cyber Security Centre (NCSC-NZ)
- Poland’s Research and Academic Computer Network (NASK)
- Slovakia National Security Authority (NBU).
More information
For questions related to this guidance, email info@ncsc.govt.nz