On July 29, 2026, CISA, NSA, FBI, and international partners published new SBOM Minimum Elements, replacing the 2021 NTIA baseline. The update adds component hashes, licenses, format name and version, and an author signature. It identifies SPDX and CycloneDX as machine-processable formats.
An SBOM is an inventory, not a security verdict. Generate one for each release in CI and request one from vendors. On a CVE arrival, correlate package identifiers and hashes with the SBOM, then use VEX or CSAF status data to determine whether the component is affected.
The EU Cyber Resilience Act requires manufacturers to document at least top-level dependencies in a machine-readable format; its main obligations apply on December 11, 2027. ENISA says the CRA is accelerating adoption. Start now: automate generation, validate signatures, request supplier output, and assign an owner. SBOMs make dependency risk searchable; they do not remove it. Start small now.
Related What I Do
Related What I Do
These What I Do pages are matched from the subject matter of this article, creating a cleaner path from educational content to implementation work.
Continue reading
Related articles
Based on shared categories first, then the strongest overlap in tags.