Back Issues This Week → Calendar → Current Issue → Popular →

All issuesVolume 340, Issue 5IT NewsOperations

CISA Issues Fresh SBOM Guidance. Did They Get It Right?

Dark Reading, Friday, July 31st, 2026

CISA and 16 partner agencies expand SBOM minimum elements, but critics say the framework lacks real risk-management improvements.

Government partners from around the world released new guidelines for the minimum elements organizations should include in a software bill of materials, authored by CISA and 16 other government entities across four continents.

A couple-dozen changes to SBOM fields make them more comprehensive, but some argue the framework lacks real risk-management improvements.

The updated version supersedes the NTIA's 2021 guidelines, was first drafted in 2025, and was informed by suggestions from 90 commenters including Google, Microsoft, and AWS.

A key concern is that CISA's guidelines are not legally enforceable requirements-the responsibility lies with regulators and customers to require suppliers to follow best practices.

more →  ·  More from Operations →