Defining and standardizing a minimum valuable SBOM makes a lot of sense. Many vendors produce or provide SBOMs just to tick the compliance boxes, and those are completely useless for software supply chain analysis and monitoring.
CISA just refreshed the SBOM Minimum Elements:
SBOM: author, signature, format name/version, gen context, timestamp, tool name/version, version
Component: producer, name, version, IDs, hash + algo, license, dependencies
Coverage = all transitive deps.
Our 2026 Minimum Elements for a Software Bill of Materials (SBOM) helps organizations improve supply chain transparency & risk management. Check out the updated guidance to learn more about new data fields, practices & processes 🔗
go.dhs.gov/5ms