US and allies update SBOM minimum elements

The US and 13 partner countries published revised guidance this week defining minimum elements for software bill of materials, adding data fields and updating the 2021 NTIA framework.
Government agencies in the United States and 13 allied countries published updated guidance this week that defines the minimum elements for a software bill of materials (SBOM). The document expands data fields and revises the National Telecommunications and Information Administration’s 2021 SBOM minimum elements.
The guidance establishes a baseline of the technologies and practices expected in an SBOM. It follows a public comment period held last year and is intended to help organizations inventory software and its components across environments.
New elements added include Component Hash Algorithm, Component Hash Value, Component License, Author Signature, Data Format Name, Data Format Version, Generation Context, Tool Name, Tool Version and SBOM Version.
Two elements were removed: Access Control and Software Identification (SWID) Tags. Several other elements were rewritten or clarified; for example, the component name field now allows multiple entries so a single component can be recorded under different identifiers.
The guidance says the updated elements should improve data quality and interoperability. It notes that more mature SBOM tooling now allows requesters to require more detailed and higher-quality data than in 2021. The updated elements are intended to help map components across formats, track provenance and licensing, and verify component integrity using hash values and author signatures.
The document applies to all software but acknowledges that some types, such as artificial intelligence systems and software-as-a-service, may require additional metadata beyond the minimum set. The guidance references G7 agencies’ SBOM guidance for AI issued in May.
Agencies recommend that software producers, purchasers and operators use SBOM data to build inventories and to prioritize remediation of known and newly discovered vulnerabilities in components.






