CISA releases updated 2026 SBOM minimum elements
Public Sector Action
Summary
Hide ▲
Show ▼
CISA and partner agencies released updated 2026 SBOM minimum elements, giving software producers, buyers, and operators a revised baseline for supply chain security across open-source software, AI software, and SaaS. The update incorporates feedback from more than 90 comments and adds new fields for component and tool provenance. It also refreshes older terms to improve machine-readable supply-chain reporting and decision-making.
Related Happenings
Executive order NSA CISA NIST and Treasury Department created a voluntary pre-release review framework a classified benchmark federal hardening directives and an AI cybersecurity
Public Sector Action
H score26
First: 03.06.2026 14:00
Last: 03.06.2026 14:00
Sources 1
About this happening:
President Donald Trump signed a June 2 executive order creating a voluntary pre-release cybersecurity review for covered frontier AI models, giving the US government a...
Executive order NSA CISA NIST and Treasury Department created a voluntary pre-release review framework a classified benchmark federal hardening directives and an AI cybersecurity
Public Sector ActionAbout this happening: President Donald Trump signed a June 2 executive order creating a voluntary pre-release cybersecurity review for covered frontier AI models, giving the US government a...
CISA launches KEV Nomination Form
Public Sector Action
H score38
First: 21.05.2026 15:00
Last: 21.05.2026 15:00
Sources 1
About this happening:
CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
CISA launches KEV Nomination Form
Public Sector ActionAbout this happening: CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....
NIST CVE/NVD prioritization shift
Public Sector Action
H score35
First: 17.04.2026 00:47
Last: 17.04.2026 00:47
Sources 1
About this happening:
NIST is changing its CVE/NVD prioritization so that, starting April 15, 2026, it will provide full details only for a subset of CVEs. The shift matters because...
NIST CVE/NVD prioritization shift
Public Sector ActionAbout this happening: NIST is changing its CVE/NVD prioritization so that, starting April 15, 2026, it will provide full details only for a subset of CVEs. The shift matters because...
NIST/NVD risk-based CVE enrichment change
Public Sector Action
H score35
First: 16.04.2026 15:43
Last: 16.04.2026 15:43
Sources 1
About this happening:
NIST said the US National Vulnerability Database (NVD) will switch to a risk-based CVE enrichment model to cope with backlog growth. The change will drop enrichment...
NIST/NVD risk-based CVE enrichment change
Public Sector ActionAbout this happening: NIST said the US National Vulnerability Database (NVD) will switch to a risk-based CVE enrichment model to cope with backlog growth. The change will drop enrichment...
CISA end-of-support edge device decommissioning mandate (BOD 26-02)
Advisory/Mitigation
H score46
First: 06.02.2026 10:41
Last: 06.02.2026 10:41
Sources 1
About this happening:
CISA's BOD 26-02 now forces U.S. federal agencies to inventory, decommission, and replace end-of-support edge devices that no longer receive security updates. The dire...
CISA end-of-support edge device decommissioning mandate (BOD 26-02)
Advisory/MitigationAbout this happening: CISA's BOD 26-02 now forces U.S. federal agencies to inventory, decommission, and replace end-of-support edge devices that no longer receive security updates. The dire...
Timeline
-
29.07.2026 15:00 2 articles · 4h ago
CISA and partners release 2026 SBOM minimum elements
Industry Or Public Sector UpdateCISA and partner agencies release 2026 Minimum Elements for a Software Bill of Materials (SBOM), updating the 2021 NTIA baseline after more than 90 public comments and extending the minimum elements to all software, including open-source software, AI software, and software-as-a-service (SaaS). The revision adds Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context, and renames fields such as Author of SBOM Data to SBOM Author, Supplier Name to Component Producer, and Version of the Component to Component Version.
Show sources
- CISA and Partners Unveil Updated Software Bill of Materials Resource That Improves Transparency, Security and Risk-Informed Decision Making — www.cisa.gov — 29.07.2026 15:00
- CISA and Partners Unveil Updated Software Bill of Materials Resource That Improves Transparency, Security and Risk-Informed Decision Making — www.cisa.gov — 29.07.2026 15:00