New Regulations Introduce Hashes and Licenses to SBOM – Skepticism Remains on Adoption
In a notable development regarding cybersecurity, a coalition comprising several leading global agencies, including the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI), has recently established standardized guidelines for crafting a Software Bill of Materials (SBOM). Despite the consensus on what constitutes an SBOM, doubts linger about the effectiveness and engagement regarding its implementation across various sectors.
The announcement, which marks the first significant update to a five-year-old federal baseline, was made public on August 4, 2026. This guidance comes as part of ongoing initiatives aimed at enhancing transparency in software supply chains, particularly important in light of past vulnerabilities like the SolarWinds hack, which prompted a federal executive order in 2021 for agencies to bolster their software supply-chain security.
An SBOM serves as a detailed inventory, outlining the various components and associated supply-chain relationships of a software application. The recently released revision adds ten new data fields to the original 2021 baseline, four of which pertain to the SBOM document itself. Importantly, new component-level fields have been introduced to include cryptographic hash values, the algorithms used for their computation, and licensing information for each software component.
In an effort to enhance clarity, some existing elements have undergone renaming; for instance, "Supplier Name" has been changed to "Component Producer" due to ambiguities surrounding the term "supplier" in practical applications, especially in the context of software distribution. Furthermore, the new guidance expands the coverage requirements to include transitive dependencies, indicating that a user should be able to ascertain that a newly discovered vulnerability does not pose a risk if the SBOM does not include the vulnerable component.
CISA’s Acting Executive Assistant Director for Cybersecurity, Chris Butera, expressed optimism about the update, stating, "This advancement in SBOM minimum elements reflects the advancements we have made as a community in supply-chain security." The agency intends for the SBOMs to be adopted more broadly, thereby improving the landscape of supply-chain security.
The revisions draw from feedback garnered from over 90 comments received after a draft was made available for public review in August 2025. Notably, this new guidance now explicitly covers all forms of software, including open-source code, artificial intelligence systems, and software-as-a-service platforms. However, it does not specifically introduce AI-related fields, acknowledging that artifacts like model cards provide essential supply-chain context not captured in the existing framework.
Despite these improvements, skepticism regarding the practical utility of SBOMs persists among industry experts. Jeff Williams, the founder of the Open Worldwide Application Security Project and Chief Technology Officer of Contrast Security, criticized the initiative, perceiving it as largely administrative. “An SBOM is just a list of ingredients,” he exclaimed, emphasizing that the real concern lies in how these components are integrated and utilized within applications.
Williams further pointed out that merely possessing a comprehensive list of software libraries does not translate into actionable information, arguing that many applications contain libraries harboring vulnerabilities that remain dormant and thereby pose no immediate risk. He highlighted a systemic issue where consumers struggle to differentiate between secure and insecure software, often opting for the cheapest alternative instead.
This sentiment reflects a broader concern within the cybersecurity community that simply establishing new frameworks may not yield tangible improvements unless there is a shift towards prioritizing quality benchmarks, conformance testing, and providing evidence that SBOMs facilitate timely and effective vulnerability responses. Williams asserted that unless CISA concentrates on these outcomes, enhancements to the minimum elements of SBOMs will likely lead to minimal change in real-world application.
In addressing future efforts, a CISA representative expressed confidence that the updated minimum elements will catalyze wider adoption of SBOMs across various industries and global sectors. However, the agency has opted not to provide details regarding plans for conformance testing or the timeline for forthcoming guidance beyond the current document.
Concerns about implementation challenges have been echoed repeatedly by industry practitioners, who caution that inconsistent tools and immature consumption practices could undermine well-crafted guidelines designed to promote SBOM usage. In an attempt to alleviate these barriers, CISA has initiated efforts aimed at simplifying the generation and dissemination of SBOMs for organizations with limited resources.
Importantly, the new guidance does not create any mandatory requirements on its own. At the same time, regulatory pressures are mounting internationally, with the European Union’s Cyber Resilience Act mandating that manufacturers of products with digital components furnish an SBOM as part of their technical documentation. Countries such as Germany, India, and Japan have also introduced their own specific SBOM requirements.
Last fall, CISA and 19 international partners released a "shared vision" for SBOMs, identifying component transparency as a fundamental necessity for managing software risk. This spring, the organization and its collaborators released AI-specific guidelines. The authors of the latest guidance identified four future areas of focus: enhancing SBOMs within cloud and SaaS environments, adding elements specific to AI systems, validating the accuracy of SBOMs, and correlating SBOM data with security advisories.
In conclusion, while the advancement of SBOM minimum elements signifies progress in addressing software supply chain security, experts like Williams emphasize that SBOMs should not be regarded as the ultimate solution, but rather as a preliminary step in a larger sequence of necessary actions to achieve true cybersecurity resilience. As the landscape evolves, the challenge will lie in ensuring effective implementation and real-world applicability of these guidelines.
