DevOps / SRE / Platform · 31.07.2026, 11:18 UTC
CISA’s 2026 SBOM Guidance Adds Hash Requirements and AI Coverage
| Schweregrad | info |
|---|---|
| Kategorie | DevOps / SRE / Platform |
| Quelle | DevOps.com ↗ |
| Veröffentlicht | 31.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
CISA just gave software supply chain security a long-overdue refresh. Working with the NSA, the FBI, and a roster of international partners, the agency released the 2026 Minimum Elements for a Software Bill of Materials, updating and replacing the baseline that the National Telecommunications and Information Administration published back in 2021. Five years is a long time in software security terms, and the update shows. The timing isn’t random. The revision incorporates feedback from more than 90 comments submitted during a public comment period, and CISA circulated a draft in 2025 specifically to update elements like SBOM author, software producer, and component version for better clarity. This wasn’t a quiet policy tweak. It was a deliberate, multi-year rework built on real feedback from people who actually generate and consume SBOMs for a living. What’s New The headline change is scope. The minimum elements now apply to SBOMs across all software types, including open-source software, AI software, and software-as-a-service. That’s a meaningful expansion from 2021, when the guidance was written before AI systems and SaaS delivery models were the default rather than the exception. The second big change is data quality. According to one industry summary of the release, the guidance adds new required minimum data fields, including component hash algorithm, component license, SBOM tool name, and SBOM generation context. It also renames several existing elements for consistency, with “Supplier Name” becoming “Component Producer”. The hash requirement deserves its own …