- What: US and allies update SBOM guidance
- Impact: Government agencies and organizations involved in software supply chain security
Application Security US and Allies Update SBOM Guidance Five years after the initial release, the refresh introduces new elements, removes others, and updates terminology. By Ionut Arghire | July 30, 2026 (4:21 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Government agencies in the US and 13 allied countries this week released updated guidance on the minimum elements of a software bill of materials (SBOM). Meant to reflect the changes in supply chain security and software transparency, the document builds on the SBOM Minimum Elements guidance that NTIA released in 2021 and takes into consideration comments received during the public feedback period last year. An SBOM, the authoring agencies say, should serve as a “key building block of software security and supply chain risk management,” helping organizations build accurate inventories of the software and software components within their environments. In this regard, the updated minimum elements for an SBOM (PDF) guidance provides a baseline of the technologies and practices expected to be included in an SBOM. “Organizations that produce, procure, and operate software can use SBOM data to better understand their software supply chain. Increased software supply chain visibility can drive risk management decisions, including addressing known and newly discovered vulnerabilities and risks,” the guidance reads. The updated document preserves the core principles of the 2021 SBOM Minimum Elements while reflecting current SBOM needs. It improves data quality, supports a broader range of use cases and applications, introduces new elements, removes others, and updates descriptions for improved clarity. Advertisement. Scroll to continue reading. New additions include the Component Hash Algorithm, Component Hash Value, Component License, Author Signature, Data Format Name, Data Format Version, Generation Context, Tool Name, Tool Version, and SBOM Version elements. While only two elements were removed from the updated guidance, namely Access Control and Software Identification (SWID) Tags, multiple elements were replaced, others were clarified or rewritten, and others were modified to improve data mapping, such as the component name, which now allows multiple entries. “SBOM tooling has advanced, driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs. These advancements enable organizations requesting SBOMs to demand more information about their supply chain and software components than they could have in 2021,” the guidance reads. According to the authoring agencies, while the document applies to all software, some types of software, such as AI systems and SaaS, may require additional elements. In May, government agencies from Group of Seven (G7) countries released SBOM guidance for AI. Related: US, Australia Release OT Isolation Guidance for Critical Infrastructure Related: Are SBOMs Failing? Supply Chain Attacks Rise as Security Teams Struggle With SBOM Data Related: US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security Related: How to Conduct a Successful Audit of AI-Driven Software Development Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Spur Raises $200 Million for IP Intelligence Platform JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack ShinyHunters Claims Ernst & Young Hack OT Security Startup Frenos Raises $1.52 Million Hush Security Raises $30 Million for AI Agent Governance Google Adopts New Threat Actor Naming System Unpatched Fastjson Vulnerability Exploited in Attacks Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day Latest News Chrome 151 Patches 370 Vulnerabilities Cisco Secure FMC Zero-Day Exploited in the Wild US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security Mate Security Raises $35 Million for Agentic SOC ThreatLocker Raises $190 Million in Series F Funding Critical VM Escape Vulnerability Patched in VMware ESXi US, Australia Release OT Isolation Guidance for Critical Infrastructure OpenAI’s Rogue AI Ventured Beyond Hugging Face Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energy Security, and Emergency Response (CESER). Sumo Logic has appointed Chris Malone as CEO and Conor Burns as CFO. Nozomi Networks has appointed co-founder Andrea Carcano as CEO. More People On The Move Expert Insights Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Flipboard Reddit Whatsapp Whatsapp Email