Find notable cyber news and cases, enriched with sources, timelines, and signals.

CISA releases updated 2026 SBOM minimum elements

Public Sector Action
First reported
Last updated
Happening score
H score 25
1 unique sources, 1 articles

Summary

Hide ▲

CISA and partner agencies released updated 2026 SBOM minimum elements, giving software producers, buyers, and operators a revised baseline for supply chain security across open-source software, AI software, and SaaS. The update incorporates feedback from more than 90 comments and adds new fields for component and tool provenance. It also refreshes older terms to improve machine-readable supply-chain reporting and decision-making.

Related Happenings

Executive order NSA CISA NIST and Treasury Department created a voluntary pre-release review framework a classified benchmark federal hardening directives and an AI cybersecurity

Public Sector Action
H score26 First: 03.06.2026 14:00 Last: 03.06.2026 14:00 Sources 1

About this happening: President Donald Trump signed a June 2 executive order creating a voluntary pre-release cybersecurity review for covered frontier AI models, giving the US government a...

CISA launches KEV Nomination Form

Public Sector Action
H score38 First: 21.05.2026 15:00 Last: 21.05.2026 15:00 Sources 1

About this happening: CISA launched a new Nomination Form for the KEV catalog, giving researchers, vendors, and industry partners a direct way to report known exploited vulnerabilities....

NIST CVE/NVD prioritization shift

Public Sector Action
H score35 First: 17.04.2026 00:47 Last: 17.04.2026 00:47 Sources 1

About this happening: NIST is changing its CVE/NVD prioritization so that, starting April 15, 2026, it will provide full details only for a subset of CVEs. The shift matters because...

NIST/NVD risk-based CVE enrichment change

Public Sector Action
H score35 First: 16.04.2026 15:43 Last: 16.04.2026 15:43 Sources 1

About this happening: NIST said the US National Vulnerability Database (NVD) will switch to a risk-based CVE enrichment model to cope with backlog growth. The change will drop enrichment...

CISA end-of-support edge device decommissioning mandate (BOD 26-02)

Advisory/Mitigation
H score46 First: 06.02.2026 10:41 Last: 06.02.2026 10:41 Sources 1

About this happening: CISA's BOD 26-02 now forces U.S. federal agencies to inventory, decommission, and replace end-of-support edge devices that no longer receive security updates. The dire...

Timeline

  1. 29.07.2026 15:00 2 articles · 4h ago

    CISA and partners release 2026 SBOM minimum elements

    Industry Or Public Sector Update

    CISA and partner agencies release 2026 Minimum Elements for a Software Bill of Materials (SBOM), updating the 2021 NTIA baseline after more than 90 public comments and extending the minimum elements to all software, including open-source software, AI software, and software-as-a-service (SaaS). The revision adds Component Hash Algorithm, Component License, SBOM Tool Name, and SBOM Generation Context, and renames fields such as Author of SBOM Data to SBOM Author, Supplier Name to Component Producer, and Version of the Component to Component Version.

    Show sources