CISA, the FBI, the NSA, and 15 international cybersecurity authorities have published updated guidance on the minimum elements of a software bill of materials, replacing the 2021 framework that defined the standard.
An SBOM lists the software components, open-source libraries, and hidden dependencies in an application, along with their vendors. The agencies updated the guidance because SBOM tooling has advanced and organizations requesting SBOMs can now demand more detail about their supply chains. The new document adds ten data fields, updates eight components to clarify scope, and makes five minor revisions.
The guidance applies to all software, with additional expectations flagged for AI-based systems and software-as-a-service products in cloud environments. The agencies recommend that organizations use the document to check that vendor SBOMs include the minimum requirements and assess whether further software transparency efforts are needed.
For healthcare organizations, the update matters well beyond IT procurement. FDA cybersecurity requirements for medical devices push manufacturers to provide SBOMs for connected products, and hospital software supply chains have become a prime attack surface, as the Change Healthcare, Craneware, and CareCloud incidents demonstrate. Spotting a vulnerable component in an SBOM before a vendor ships a patch gives security teams time to apply mitigations, a key defense when third-party flaws are exploited in the wild.
