What happened
On July 29, 2026, CISA and 17 co-authoring national cybersecurity agencies published the '2026 Minimum Elements for a Software Bill of Materials (SBOM)', the first full revision of the SBOM baseline since the original 2021 NTIA document (with an intermediate August 2025 draft). The revision incorporates feedback from 90+ public comments and explicitly extends scope to SBOMs for AI software systems and SaaS/cloud software, adding new elements (SBOM Author Signature, SBOM Tool Name/Version, SBOM Generation Context, Component Hash Algorithm, Component License) and updating others (Supplier Name→Component Producer, Depth→Coverage, Known Unknowns→Explicitly Identifying Unknown Information). A dedicated discussion section addresses 'SBOM for AI Software Systems'.
Why it matters
This is a normative, multi-government joint guidance document (18 co-authoring agencies across US, Australia, Canada, EU member states, Japan, Korea, India, etc.) that establishes the baseline transparency/supply-chain standard software producers, procurers, and operators are expected to meet — now explicitly scoped to include AI models/software components. Because SBOM minimum elements are frequently referenced by procurement frameworks and regulations, this update effectively raises the floor for AI supply-chain transparency across the ecosystem that adopts NTIA/CISA SBOM baselines.
Action needed
Organizations that produce, procure, or operate software (including AI software) should update SBOM generation/request practices to satisfy the 2026 minimum elements (in CycloneDX 1.6 or SPDX 2.3/3.0), including the new AI-specific SBOM elements and author-signature/tooling metadata fields.