If you build, buy, or ship software, the bar for software transparency has just been raised globally.
On 29 July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), together with 18 international cyber authorities, including Germany’s BSI, France’s ANSSI, Japan’s METI, India’s CERT-In, and the NSA and FBI, published the 2026 Minimum Elements for a Software Bill of Materials (SBOM). It replaces the original 2021 NTIA baseline and reflects five years of hard-won lessons about what an SBOM needs to contain to be useful.
The message is simple: an SBOM is no longer just a list of ingredients. It is a signed, versioned, machine-readable record that must stand up to a regulator, a customer, and a vulnerability disclosure all at once.
At BearingPoint, we don’t just track the 2026 SBOM Minimum Elements. We help organizations turn them into practical action: generating standards-aligned Software Bills of Materials, validating component and license data, improving software supply chain transparency, and preparing for customer, audit, and regulatory expectations.
![]()
The updated minimum elements are organized into two pillars: Data Fields, which define what belongs in the SBOM, and Practices and Processes, which define how you generate, share, and maintain it. The headline is a wave of ten brand-new data elements designed to support real, risk-informed security decisions:
Aditionally, key existing elements were sharpened: Supplier Name became Component Producer, Depth became Coverage (now including transitive dependencies with no minimum depth), and Automation Support became Machine-Processable Data, cementing SPDX and CycloneDX as the two formats that matter.
To meet the 2026 SBOM Minimum Elements, organizations need more than component names and versions.
A modern Software Bill of Materials must provide deeper coverage across transitive dependencies, built-in license information, verifiable component integrity through hashes and signatures, and machine-processable data that security, compliance, and procurement teams can analyze at scale.
Get the official document and keep the full checklist of data fields, practices, and processes at your fingertips.
Original guidance © CISA, NSA, FBI and international partners (2026 SBOM Minimum Elements, TLP:CLEAR). Provided by BearingPoint for convenience; no affiliation or endorsement implied.
This is no longer a theoretical compliance discussion. The 2026 elements land squarely on top of the regulation already reshaping the European market:
In practice, the 2026 SBOM Minimum Elements are becoming the benchmark regulators and enterprise customers will use to assess software transparency, supply chain security, and compliance readiness. Organizations that act early can turn compliance pressure into a competitive advantage.
Start with a focused SBOM quick check or a pilot scan of one product line. In just 30 minutes, we can help identify where you stand against the 2026 SBOM Minimum Elements and outline the next steps toward a standards-aligned SBOM, a clearer risk picture, and a prioritized action plan.
Talk to our FOSS compliance team today and turn the new rulebook into your advantage.
Get in touchThe 2026 SBOM Minimum Elements define the baseline data fields, practices, and processes that a Software Bill of Materials should include. They update the 2021 NTIA baseline and reflect how SBOM tooling, regulatory expectations, and software supply chain risk management have evolved.
The guidance is relevant for organizations that produce, procure, or operate software. That includes software vendors, manufacturers of products with digital elements, procurement teams, security teams, compliance teams, and organizations that need better visibility into third-party and open source components.
The 2026 update adds new elements for authenticity, traceability, machine readability, lifecycle context, component integrity, and license visibility. It also sharpens existing expectations by replacing Supplier Name with Component Producer, Depth with Coverage, and Automation Support with Machine-Processable Data.
The new fields include SBOM Author Signature, SBOM Data Format Name, SBOM Data Format Version, SBOM Generation Context, SBOM Tool Name, SBOM Tool Version, SBOM Version, Component Hash Value, Component Hash Algorithm, and Component License.
Coverage matters because an SBOM should include the components that make up the target software, including transitive dependencies. This gives organizations a more complete view of software supply chain risk and helps them assess whether a newly reported vulnerability affects their products.
Organizations should use widely adopted, interoperable, and machine-processable SBOM formats. The 2026 guidance identifies SPDX and CycloneDX as the two formats currently widely used to generate and consume SBOMs.
The EU Cyber Resilience Act requires manufacturers of products with digital elements to provide an SBOM as part of their technical documentation. The 2026 SBOM Minimum Elements give organizations a practical baseline for building the software transparency needed to support regulatory readiness and customer trust.
Each software version or update should have an associated SBOM. When a new build, release, updated component, or corrected dependency record changes the software, the SBOM should be updated so security, compliance, and procurement teams can rely on current information.
BearingPoint helps organizations assess their SBOM readiness, generate standards-aligned SBOMs, analyze component and license risk, improve software supply chain transparency, and prepare for customer and regulatory expectations around SBOM compliance.