The United States and 13 allied governments released an updated baseline for what information a software bill of materials, or SBOM, should contain. The refresh updates the 2021 NTIA minimum-elements guidance by adding fields such as component hash algorithm and value, component license, author signature, tool name and version, generation context, and SBOM version, while removing Access Control and SWID Tags and revising terminology and data mapping expectations.
Why it matters: This matters to software vendors, buyers, and defenders because SBOM requirements increasingly shape procurement, vulnerability response, and supply-chain risk management. Organizations that produce or buy software may need to update SBOM generation, validation, and contract requirements to match the new baseline.
Ionut Arghire
2026.07.30
100% relevant
This article establishes a distinct policy and supply-chain security development: a multination update to the baseline SBOM guidance itself, not a breach or patch tied to an existing tracked event.
← Back to all stories