If you build, buy, or ship software, the bar for software transparency has just been raised globally.

On 29 July 2026, the U.S. Cybersecurity and Infrastructure Security Agency (CISA), together with 18 international cyber authorities, including Germany’s BSI, France’s ANSSI, Japan’s METI, India’s CERT-In, and the NSA and FBI, published the 2026 Minimum Elements for a Software Bill of Materials (SBOM). It replaces the original 2021 NTIA baseline and reflects five years of hard-won lessons about what an SBOM needs to contain to be useful.

The message is simple: an SBOM is no longer just a list of ingredients. It is a signed, versioned, machine-readable record that must stand up to a regulator, a customer, and a vulnerability disclosure all at once.

At BearingPoint, we don’t just track the 2026 SBOM Minimum Elements. We help organizations turn them into practical action: generating standards-aligned Software Bills of Materials, validating component and license data, improving software supply chain transparency, and preparing for customer, audit, and regulatory expectations.

What changed in the 2026 SBOM Minimum Elements?

The updated minimum elements are organized into two pillars: Data Fields, which define what belongs in the SBOM, and Practices and Processes, which define how you generate, share, and maintain it. The headline is a wave of ten brand-new data elements designed to support real, risk-informed security decisions:

  • Component License, the license(s) each component ships under (ideally as SPDX identifiers), so license risk is finally part of the SBOM itself.
  • Component Hash Value & Hash Algorithm, cryptographic fingerprints that let you verify component integrity.
  • SBOM Author Signature, a digital signature proving the SBOM is authentic and untampered.
  • SBOM Data Format Name & Version, explicit declaration of the format used (SPDX or CycloneDX).
  • SBOM Generation Context, indicating whether the SBOM was built before build, at build, or after build. Context changes everything.
  • SBOM Tool Name, Tool Version & SBOM Version, full traceability of how and when the SBOM was produced.

Aditionally, key existing elements were sharpened: Supplier Name became Component Producer, Depth became Coverage (now including transitive dependencies with no minimum depth), and Automation Support became Machine-Processable Data, cementing SPDX and CycloneDX as the two formats that matter.

Key Takeaway: A basic dependency list is no longer enough

To meet the 2026 SBOM Minimum Elements, organizations need more than component names and versions.

A modern Software Bill of Materials must provide deeper coverage across transitive dependencies, built-in license information, verifiable component integrity through hashes and signatures, and machine-processable data that security, compliance, and procurement teams can analyze at scale.

Want the complete requirements straight from the source?

Get the official document and keep the full checklist of data fields, practices, and processes at your fingertips. 

Original guidance © CISA, NSA, FBI and international partners (2026 SBOM Minimum Elements, TLP:CLEAR). Provided by BearingPoint for convenience; no affiliation or endorsement implied.

  • Download: The 2026 Minimum Elements for a Software Bill of Materials (SBOM)
    Download: The 2026 Minimum Elements for a Software Bill of Materials (SBOM) 1.08 MB Download

Why the 2026 SBOM requirements matter for EU compliance

This is no longer a theoretical compliance discussion. The 2026 elements land squarely on top of the regulation already reshaping the European market:

  • EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to provide an SBOM as part of their technical documentation, with full enforcement arriving in 2027.
  • Germany’s BSI TR-03183-2 already spells out technical SBOM requirements.
  • NIS2 and customer-driven SBOM demand letters are already pushing transparency requirements down the supply chain.

In practice, the 2026 SBOM Minimum Elements are becoming the benchmark regulators and enterprise customers will use to assess software transparency, supply chain security, and compliance readiness. Organizations that act early can turn compliance pressure into a competitive advantage.

Check your products against the 2026 SBOM Minimum Elements

Start with a focused SBOM quick check or a pilot scan of one product line. In just 30 minutes, we can help identify where you stand against the 2026 SBOM Minimum Elements and outline the next steps toward a standards-aligned SBOM, a clearer risk picture, and a prioritized action plan.

Talk to our FOSS compliance team today and turn the new rulebook into your advantage.

Get in touch

Frequently asked questions about the 2026 SBOM Minimum Elements

Get in touch

Talk to our specialists and learn how our Open-Source Management Services can help your business.