US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
AI analyzing network data
Share

Key points

  • CISA, the NSA, the FBI and international partners published new 2026 Minimum Elements for a Software Bill of Materials, replacing 2021 guidance from the National Telecommunications and Information Administration.
  • A Software Bill of Materials, or SBOM, is an ingredients list showing every component inside a piece of software.
  • The refresh followed a public comment period in 2025 and keeps the core principles of the original document.
  • Regulators flag artificial intelligence systems and cloud-hosted software as needing extra elements beyond the baseline.
  • The guidance applies to all software, and organisations are told to start any transparency effort with these minimum elements.

American and allied cyber agencies have rewritten the rules for how software makers list what is inside their products.

The new document, 2026 Minimum Elements for a Software Bill of Materials, was released this week by CISA, the National Security Agency, the FBI and allied governments. It replaces guidance first published in 2021 by the National Telecommunications and Information Administration, a US Commerce Department body.

A Software Bill of Materials, usually shortened to SBOM, is a list of every component that goes into a piece of software, the way a food label lists every ingredient in a ready meal. That matters because most modern software isn't written from scratch. Vendors stitch together open-source libraries and commercial components alongside their own code. When a flaw turns up in one of those ingredients, customers need to know quickly whether they're using it.

Why is the guidance being updated now?

The 2021 version was showing its age. Tools for generating SBOMs have moved on, and buyers, especially government buyers, have been pushing for more detail about what they're actually running.

CISA ran a public comment period in 2025 and folded that feedback into the refresh. The core principles from the original NTIA document are preserved. What's changed is the level of detail expected and the acknowledgement that some kinds of software need more than the baseline. We've been tracking SBOM developments since 28 May 2026, including Lookout's tool that builds detailed ingredient lists for enterprise apps to expose hidden vulnerable components.

What counts as the 'minimum'?

Minimum elements describe the baseline technologies and practices that any SBOM should include, regardless of software type. Think of it as the shortest acceptable ingredients list.

The guidance is explicit that the minimums apply to all software. Artificial intelligence systems and software delivered as a service from the cloud may need extra elements on top, because their dependencies don't sit neatly inside a downloadable file.

Item Detail
Document name 2026 Minimum Elements for a Software Bill of Materials
Publishers CISA, NSA, FBI and international partners
Replaces 2021 NTIA minimum elements
Public comment period 2025
Special cases flagged AI systems, software as a service

Should ordinary buyers care?

Yes, indirectly. If you run a small business or a school, you're not going to read an SBOM yourself. Your suppliers will. But when the next big vulnerability lands in a shared component, the speed at which your vendor can answer "are we affected?" depends on whether they keep an accurate SBOM. Better ingredient lists mean faster answers, and faster answers mean shorter windows for criminals to break in.

What should organisations do next?

Start with the minimum elements. That's the direct message from the agencies: any effort to improve software transparency, whatever the software type, begins here.

Procurement teams can ask vendors for an SBOM aligned to the 2026 guidance as a condition of purchase. Security teams can then ingest those files into their vulnerability management tools so that when a flaw is disclosed in a shared component, they know within minutes which products are affected, not days.

The guidance isn't law. Federal purchasing power tends to pull the wider market along, though, and allied governments signing on to the same document makes it harder for global vendors to ignore. The pattern here is worth watching: this is the second joint CISA-NSA release in two weeks, following the bug-hunting playbook published on 15 July. The two agencies are moving fast on supply-chain standards, and vendors who treat these documents as optional are betting that federal procurement teams won't notice.

© 2026 Threat Vectr