Blog/ai security
ai security

2026 Minimum Elements for a Software Bill of Materials (SBOM)

July 29, 2026·Source: CISA
0 comments

TL;DR

CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document. An SBOM serves as an “ingredients list” for software and is a key building block of software security and supply chain risk management. Organizations can use SBOM data to better understand the makeup of their software components and supply chains and make more risk-informed decisions. Minimum elements for an SBOM describe the baseline technologies and practices that an SBOM should include.  While the minimum elements for an SBOM apply to all software, some software types—such as artificial intelligence and software as a service in cloud environments—may require additional elements. Any effort to improve software transparency, regardless of the software type, should begin with the application of minimum elements.

What Happened

2026 Minimum Elements for a Software Bill of Materials (SBOM), reported by CISA.

CISA, the National Security Agency, the Federal Bureau of Investigation, and international partners released joint guidance, 2026 Minimum Elements for a Software Bill of Materials (SBOM), that updates and replaces the minimum elements for an SBOM published by the National Telecommunications and Information Administration (NTIA) in 2021. The new guidance incorporates stakeholder feedback from a 2025 public comment period and reflects current SBOM tools and needs while preserving the core principles of the original NTIA document. An SBOM serves as an “ingredients list” for software and is a key building block of software security and supply chain risk management. Organizations can use SBOM data to better understand the makeup of their software components and supply chains and make more risk-informed decisions. Minimum elements for an SBOM describe the baseline technologies and practices that an SBOM should include.  While the minimum elements for an SBOM apply to all software, some software types—such as artificial intelligence and software as a service in cloud environments—may require additional elements. Any effort to improve software transparency, regardless of the software type, should begin with the application of minimum elements.

For the full technical details, see the original report.

Why It Matters for Businesses

This development could affect organizations that rely on the impacted technologies or services. Unpatched systems, misconfigured infrastructure, or lack of monitoring can leave businesses exposed to exploitation, data breaches, and regulatory penalties.

How to Check Your Exposure

Run a free scan on NEL Professional's Cyber Risk Scanner to check whether your domain is affected. The scan covers SSL/TLS, security headers, DNS configuration, email authentication, and more across 16 modules.

Check Your Domain Security

Mitigation Steps

  • Patch immediately, Apply vendor patches or updates as soon as they are available.
  • Review configurations, Check firewall rules, access controls, and security headers.
  • Monitor logs, Watch for indicators of compromise (IOCs) related to this threat.
  • Update security policies, Ensure incident response plans cover this type of threat.
  • Run a security scan, Use automated tools to verify your exposure.

Need Expert Help?

If your organization needs help assessing or remediating this issue, hire a verified cybersecurity specialist through NEL Professionals.

Need More Scan Credits?

Get up to 100 scans or unlimited lifetime access starting at $15.

View Plans →

Comments (0)

No comments yet. Be the first to comment!

← Back to Blog