CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Issues Updated Guidance on Minimum Elements of an SBOM

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6290

As cited

Copy frozen at (site build).

regulatory

CISA Issues Updated Guidance on Minimum Elements of an SBOM

CISA, FBI, NSA, and 15 international partners released updated guidance on Software Bill of Materials (SBOM) minimum elements, replacing 2021 guidance to reflect advances in SBOM tools and stakeholder feedback. The update adds ten data fields and clarifies eight components to help organizations better track software supply chain risks and identify vulnerable components before patches become available.

Why it matters: Organizations producing, procuring, or operating software can use the updated guidance to strengthen visibility into third-party components and dependencies, enabling faster response to supply chain vulnerabilities and reducing exposure to cybercriminal exploitation.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary