
The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), and international partners released the joint guidance 2026 Minimum Elements for a Software Bill of Materials (SBOM).
This “ingredients list” for software allows organizations to better understand the makeup of their software components and supply chains, enabling them to make more risk-informed decisions. Minimum elements are the baseline technologies and practices that an SBOM should include.
The joint guidance builds on the National Telecommunications and Information Administration’s (NTIA) Minimum Elements for SBOM published in 2021 and reflects lessons learned and advancements in SBOM tooling driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs worldwide.
It also incorporates extensive feedback from a 2025 public comment period, but includes some updates, including:
- Refined baseline SBOM data fields, including new requirements for Component Hash, License, SBOM Tool Name, and SBOM Generation Context.
- Enhanced practices for documenting and sharing software components.
- Updated guidance for all software types, including open source, artificial intelligence (AI), and software-as-service (SaaS).
- Emphasis on machine-processable SBOM formats for scalable risk management.
While the minimum elements for an SBOM apply to all software, some types may require additional elements. Additional insight is available on the updated guidance page, as well as CISA’s SBOM page.






















