U.S. and international cybersecurity agencies have released updated joint guidance defining the minimum elements required for a software bill of materials (SBOM), a critical inventory tool designed to help organizations identify and manage vulnerabilities hidden within their software supply chains. The Cybersecurity and Infrastructure Security Agency (CISA) and partner agencies published the guidance on July 29, 2026, replacing the previous baseline established by the National Telecommunications and Information Administration (NTIA) in 2021, according to aha.org. An SBOM functions as a formal list of all components contained in a software product, providing transparency that allows organizations to quickly determine if they are affected by newly discovered vulnerabilities in third-party libraries or dependencies.
What Are the Minimum Elements for a Software Bill of Materials?
The new guidance establishes a standardized baseline for what an SBOM must contain, updating the 2021 NTIA recommendations to reflect evolving software complexity and threat landscapes. While the specific technical data fields are detailed in the full joint publication, the core purpose remains consistent: to ensure that every software product—whether proprietary, open source, or commercial off-the-shelf—carries a verifiable ingredient list. This update is particularly significant for sectors relying on complex, long-lifecycle software systems, such as healthcare, energy, and critical manufacturing. The guidance acknowledges that modern software types, including artificial intelligence models and software-as-a-service (SaaS) deployed in cloud environments, may require additional elements beyond the standard minimum to address their unique supply chain risks, according to aha.org.
How Does This Impact Medical Device Manufacturers and Hospitals?
The healthcare sector faces a direct regulatory mandate tied to SBOM adoption. Section 524B of the Federal Food, Drug, and Cosmetic Act requires medical device manufacturers to provide an SBOM for new device applications submitted to the Food and Drug Administration (FDA) after October 1, 2023. This statutory requirement underscores the life-safety implications of software transparency in clinical environments. Scott Gee, deputy national advisor for cybersecurity and risk at the American Hospital Association (AHA), illustrated the risk using a medical imaging device: the device itself may not appear on a vulnerability alert list, but a deeply embedded, unpatched software component could harbor a technical vulnerability that leads to device compromise and, consequently, the infiltration of the hospital network it connects to, according to aha.org. This "nested dependency" problem is precisely what the updated minimum elements aim to help organizations uncover.
What Is the New International Guidance for AI-Specific SBOMs?
Running parallel to the general SBOM update, a coalition of G7 cybersecurity agencies published dedicated guidance for Artificial Intelligence systems on May 12, 2026. Authored by the G7 Cybersecurity Working Group, the document titled "Software Bill of Materials (SBOM) for Artificial Intelligence - Minimum Elements" introduces a framework of seven "clusters" of potential elements tailored to AI supply chains, according to infosecurity-magazine.com. These clusters cover areas such as training data provenance, model architecture, third-party model dependencies, and licensing, alongside a Metadata cluster describing the SBOM for AI itself. The guidance emphasizes that all clusters are equally important except for Metadata, and critically notes that these elements are not mandatory and remain open to further refinement.
What Are the Limitations and Expert Concerns Regarding AI SBOM Clusters?
While the seven-cluster framework represents a structural advance for AI transparency, experts have flagged practical implementation challenges. Allan Friedman, who led CISA’s SBOM efforts from August 2021 to July 2025, stated he "liked a lot" of the clusters but cautioned that many are "hard to measure or even hard to define in a specific, cross-organization fashion," according to infosecurity-magazine.com. The guidance itself explicitly states that an SBOM for AI by itself is "not sufficient" for increasing cybersecurity along the supply chain. To achieve substantial protection, the SBOM for AI must be integrated with cybersecurity tooling—including vulnerability scanning and management tools, security advisories, and bulletins—and support the development of adaptable, evolutionary tooling mechanisms. The document concludes that only when deployed alongside the right cybersecurity tools will an SBOM for AI strengthen the security of the AI supply chain.
Which Agencies Are Leading This International Effort?
The joint guidance on general SBOM minimum elements and the dedicated AI SBOM framework both stem from broad international collaboration. The AI-specific document was jointly published by Germany’s Federal Office for Information Security (BSI), Italy’s National Cybersecurity Agency (ACN), France’s National Cybersecurity Agency (ANSSI), Canada’s Communications Security Establishment (CSE), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the U.K.’s National Cyber Security Centre (NCSC), and Japan’s National Cybersecurity Office (NCO), in collaboration with the EU Commission, according to infosecurity-magazine.com. This alignment signals a concerted push by major economies to standardize software transparency requirements across borders, reducing friction for global vendors and improving collective defense against supply chain attacks.
Why It Matters for Security Teams and Procurement Officers
For security practitioners, the updated minimum elements provide a clearer benchmark for evaluating vendor SBOMs and automating vulnerability correlation. Procurement officers can now reference a current, internationally recognized standard in contract language, moving beyond the 2021 baseline. However, the non-mandatory status of the AI clusters and the acknowledged difficulty in cross-organizational measurement mean that organizations should treat the AI guidance as a maturity model rather than a compliance checklist today. The critical takeaway from both publications is that an SBOM—whether for traditional software or AI—is a foundational data layer, not a security control. Its value is realized only when fed into vulnerability management pipelines, asset inventories, and incident response playbooks. Organizations that invest in tooling to consume and act on SBOM data will gain the earliest advantage as these standards mature into regulatory requirements across critical infrastructure sectors.
