CISA Publishes Draft Software Bill of Materials Guide for Public Comment
Summary
Hide β²
Show βΌ
The Cybersecurity and Infrastructure Security Agency (CISA) has released a draft of the Minimum Elements for a Software Bill of Materials (SBOM) for public comment. This updated guide reflects advancements in SBOM practices and provides a revised baseline for documenting and sharing software component information. The public can submit comments until October 3, 2025. The draft includes new elements such as component hash, license, tool name, and generation context, along with updates to existing elements for improved clarity. The goal is to enhance transparency in the software supply chain, enabling organizations to make risk-informed decisions and strengthen their cybersecurity posture. Industry experts have expressed mixed reviews, highlighting concerns about the practicality and operationalization of SBOMs despite the positive steps forward.
Timeline
-
22.08.2025 15:00 π° 2 articles Β· β± 25d ago
CISA Publishes Draft Software Bill of Materials Guide
On August 22, 2025, CISA released a draft of the Minimum Elements for a Software Bill of Materials (SBOM) for public comment. The draft includes new elements such as component hash, license, tool name, and generation context, along with updates to existing elements for improved clarity. The public comment period concludes on October 3, 2025. Industry experts have expressed mixed reviews, highlighting concerns about the practicality and operationalization of SBOMs despite the positive steps forward. The new guidelines require component hashes and machine-readable formats to enhance transparency and solve data verification challenges. There is a call for more practical guidance and better vulnerability integration to make SBOMs truly operational.
Show sources
- CISA Issues Draft Software Bill of Materials Guide for Public Comment β www.cisa.gov β 22.08.2025 15:00
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
Information Snippets
-
CISA released a draft of the Minimum Elements for a Software Bill of Materials (SBOM) on August 22, 2025.
First reported: 22.08.2025 15:00π° 2 sources, 2 articlesShow sources
- CISA Issues Draft Software Bill of Materials Guide for Public Comment β www.cisa.gov β 22.08.2025 15:00
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
The draft incorporates lessons learned from increased SBOM generation and usage.
First reported: 22.08.2025 15:00π° 1 source, 1 articleShow sources
- CISA Issues Draft Software Bill of Materials Guide for Public Comment β www.cisa.gov β 22.08.2025 15:00
-
New elements in the draft include component hash, license, tool name, and generation context.
First reported: 22.08.2025 15:00π° 2 sources, 2 articlesShow sources
- CISA Issues Draft Software Bill of Materials Guide for Public Comment β www.cisa.gov β 22.08.2025 15:00
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
Existing elements have been updated for improved clarity.
First reported: 22.08.2025 15:00π° 1 source, 1 articleShow sources
- CISA Issues Draft Software Bill of Materials Guide for Public Comment β www.cisa.gov β 22.08.2025 15:00
-
The public comment period concludes on October 3, 2025.
First reported: 22.08.2025 15:00π° 2 sources, 2 articlesShow sources
- CISA Issues Draft Software Bill of Materials Guide for Public Comment β www.cisa.gov β 22.08.2025 15:00
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
CISA encourages public review and feedback to improve the list of minimum elements.
First reported: 22.08.2025 15:00π° 1 source, 1 articleShow sources
- CISA Issues Draft Software Bill of Materials Guide for Public Comment β www.cisa.gov β 22.08.2025 15:00
-
The new SBOM guidelines require component hash, license, tool name, timestamp, and other software identifiers to enhance transparency.
First reported: 28.08.2025 18:17π° 1 source, 1 articleShow sources
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
The new guidelines mandate SBOMs to be produced in machine-readable formats like SPDX and CycloneDX to drive automation.
First reported: 28.08.2025 18:17π° 1 source, 1 articleShow sources
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
CISA's updated SBOM guidelines aim to solve the data verification challenge by requiring cryptographic hashes for components.
First reported: 28.08.2025 18:17π° 1 source, 1 articleShow sources
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
Industry experts express concerns about the practicality and operationalization of SBOMs despite the positive steps forward.
First reported: 28.08.2025 18:17π° 1 source, 1 articleShow sources
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
There is a call for more practical guidance, including sector-specific guidance, playbooks, and trust and sharing models.
First reported: 28.08.2025 18:17π° 1 source, 1 articleShow sources
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
Experts highlight the need for better vulnerability integration and automation to make SBOMs truly operational.
First reported: 28.08.2025 18:17π° 1 source, 1 articleShow sources
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
-
The updated SBOM guidelines have received mixed reviews, with skepticism about implementation and standardization.
First reported: 28.08.2025 18:17π° 1 source, 1 articleShow sources
- CISA's New SBOM Guidelines Get Mixed Reviews β www.darkreading.com β 28.08.2025 18:17
Similar Happenings
AI Adoption Guidelines for Cybersecurity Leaders
Cybersecurity leaders face challenges in safely adopting AI within organizations. Five key rules are outlined to balance innovation and protection. These rules focus on visibility, risk assessment, data protection, access controls, and continuous oversight. The goal is to enable safe AI usage without hindering productivity. AI adoption is accelerating, but it lacks necessary controls and safeguards. Security leaders must implement practical principles and technological capabilities to create a secure environment for AI usage. The rules emphasize the importance of visibility, contextual risk assessment, data protection, access controls, and continuous oversight.
CISA Adjusts Cybersecurity Alerts and Notifications Strategy
The Cybersecurity and Infrastructure Security Agency (CISA) announced a temporary pause in implementing changes to its cybersecurity alerts and notifications strategy. This decision follows feedback from the cyber community regarding confusion caused by recent adjustments. CISA aims to re-evaluate the best approach to sharing timely and actionable information with stakeholders. The agency had previously announced changes to enhance user experience and highlight the most critical information for cyber defenders. The pause allows CISA to reassess and clarify its communication strategy.