CISA Updates SBOM Standards for 2026, Mandating Hashes and Covering AI and SaaS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released updated 2026 minimum requirements for Software Bills of Materials (SBOMs), replacing the baseline set by NTIA in 2021. The new standard, developed alongside the NSA, FBI, and international partners, makes component hashes mandatory and adds fields for component license and SBOM generation context. Crucially, the updated rules extend SBOM requirements beyond traditional software to cover open-source projects, AI systems, and SaaS platforms. For SaaS and AI, where no conventional build process exists, the requirements are expected to flow into procurement contracts, since suppliers must provide SBOMs with their services. CISA describes the document as a minimum floor, but experts warn that the harder challenge lies in keeping SBOMs accurate after release, as deployed components can drift from what was originally documented.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in