A couple-dozen changes to SBOM fields will make them more comprehensive, but some argue that the framework lacks real risk-management improvements.
July 31, 2026
A gaggle of government partners from around the world has released new guidelines for the minimum elements that organizations should include in a software bill of materials (SBOM).
The document, published this week, was authored by the US Cybersecurity and Infrastructure Security Agency (CISA) and 16 other government entities spread across four continents. It supersedes the National Telecommunications and Information Administration's (NTIA) 2021 guidelines, which laid out what an SBOM had to contain as far as the US government was concerned. This updated version was first drafted in 2025, and was then informed by suggestions from 90 commenters, including major organizations like Google, Microsoft, and Amazon Web Services (AWS) to create the resulting document.
An SBOM is essentially an “ingredients list," detailing the building blocks and supply chains that make up a given piece of software. This could include proprietary or open source software components, APIs, utilities, and more. As a risk management tool, it aims to provide visibility into where vulnerabilities exist in a software stack and how to prioritize patching, among other things.









