US and allies rewrite the software 'ingredients list' rulebook for 2026

CISA, the NSA, the FBI and international partners have updated the minimum elements for a Software Bill of Materials, replacing 2021 guidance that industry had outgrown.

ThreatVectr Newsdesk· 4 min read
AI analyzing network data
Share

Key points

  • CISA, the NSA, the FBI and international partners published new 2026 Minimum Elements for a Software Bill of Materials, replacing 2021 guidance from the National Telecommunications and Information Administration.
  • A Software Bill of Materials, or SBOM, is an ingredients list showing every component inside a piece of software.
  • The refresh followed a public comment period in 2025 and keeps the core principles of the original document.
  • Regulators flag artificial intelligence systems and cloud-hosted software as needing extra elements beyond the baseline.
  • The guidance applies to all software, and organisations are told to start any transparency effort with these minimum elements.

American and allied cyber agencies have rewritten the rules for how software makers list what is inside their products.

The new document, 2026 Minimum Elements for a Software Bill of Materials, was released this week by CISA, the National Security Agency, the FBI and international partners. It replaces guidance first published in 2021 by the National Telecommunications and Information Administration, a US Commerce Department body.

The idea behind it is simple. A Software Bill of Materials, usually shortened to SBOM, is a list of every component that goes into a piece of software, in the same way a food label lists every ingredient in a ready meal.

That matters because most modern software is not written from scratch. Vendors stitch together open-source libraries, commercial components and their own code. When a flaw turns up in one of those ingredients, customers need to know quickly whether they are using it.

Why is the guidance being updated now?

The 2021 version was showing its age. Tools for generating SBOMs have moved on, and buyers, especially government buyers, have been pushing for more detail about what they are actually running.

CISA, per its own advisory, ran a public comment period in 2025 and folded the feedback into the refresh. The core principles from the original NTIA document are preserved. What has changed is the level of detail expected and the acknowledgement that some kinds of software need more than the baseline.

What counts as the 'minimum'?

Minimum elements describe the baseline technologies and practices that any SBOM should include, regardless of the type of software. Think of it as the shortest acceptable ingredients list.

The guidance is explicit that the minimums apply to all software. Artificial intelligence systems and software delivered as a service from the cloud may need extra elements on top, because their components and dependencies do not sit neatly inside a downloadable file.

Item Detail
Document name 2026 Minimum Elements for a Software Bill of Materials
Publishers CISA, NSA, FBI and international partners
Replaces 2021 NTIA minimum elements
Public comment period 2025
Special cases flagged AI systems, software as a service

Should ordinary buyers care?

Yes, indirectly. If you run a small business, a clinic or a school, you are not going to read an SBOM yourself. Your suppliers will. But when the next big vulnerability lands, in a component like Log4j did in 2021, the speed at which your vendor can answer 'are we affected?' depends on whether they keep an accurate SBOM.

Better ingredient lists mean faster answers. Faster answers mean shorter windows for criminals to break in.

What should organisations do next?

Start with the minimum elements. That is the direct message from the agencies: any effort to improve software transparency, whatever the software type, should begin here.

Procurement teams can ask vendors for an SBOM aligned to the 2026 guidance as a condition of purchase. Security teams can begin ingesting those files into their vulnerability management tools so that when a flaw is disclosed in a shared component, they know within minutes which products are affected, not days.

The guidance is not law. But federal purchasing power tends to pull the wider market along, and allied governments signing on to the same document makes it harder for global vendors to ignore.

© 2026 Threat Vectr