ssdfregulatorNewsThe Broadside2 min read

CISA Issues First SBOM Baseline Update Since 2021

The multi-agency update reflects five years of tooling maturity and stakeholder input but leaves open whether existing SBOMs must be rebuilt to the new floor.


TL;DR

CISA, the NSA, the FBI, and international partners released the 2026 Minimum Elements for a Software Bill of Materials, replacing the 2021 NTIA baseline that governed SBOM expectations for five years. The update incorporates feedback from a 2025 public comment period and reflects current SBOM tooling while preserving the original document's core principles. AI systems and SaaS products, the guidance notes, may require elements beyond the minimum. For software producers and federal suppliers, this is the new reference point for what a conforming SBOM contains. The guidance is silent on whether existing SBOMs must be retroactively updated.

CISA Issues First SBOM Baseline Update Since 2021
Editorial illustration · drawn by The Broadside

CISA, the NSA, the FBI, and international partners released the 2026 Minimum Elements for a Software Bill of Materials, replacing the NTIA's 2021 SBOM baseline in the first comprehensive update since the original publication. The guidance incorporates feedback from a public comment period that ran from August 22 through October 3, 2025, as announced in the Federal Register last summer.

The multi-agency release (CISA plus NSA, FBI, and international partners) signals that SBOM policy has outgrown its origins as a single-agency initiative.

The guidance preserves the core structure of the original NTIA document. Data fields, automation support, and practices and processes remain the organizing framework. But the new version reflects how the tooling ecosystem has changed since 2021. The 2025 draft described the need for "machine-processable formats that support scalable implementation and integration into broader cybersecurity practices," and that emphasis carries into the final document. The 2026 guidance also explicitly acknowledges that artificial intelligence systems and software-as-a-service products deployed in cloud environments may need elements beyond the baseline minimum.

What the guidance doesn't provide is equally notable. It doesn't itemize which specific elements changed from the 2021 baseline, so practitioners will need to perform their own delta analysis. It doesn't address whether existing SBOMs must be retroactively updated to meet the new minimums or whether the requirements apply only to software released after publication. For organizations that built SBOM programs around the 2021 NTIA baseline, the absence of transition language means the operational impact depends entirely on how individual agencies fold the new guidance into their procurement requirements.

For Monday, start with the guidance itself. Compare it against your organization's current SBOM output and identify gaps. The document is clear on one point: "any effort to improve software transparency, regardless of the software type, should begin with the application of minimum elements." The harder question (whether existing SBOMs need rebuilding) won't be answered by CISA. It'll be answered by contracting officers.


Published ·Deep Fathom