25% off all training courses Offer ends August 28, 2026
View HIPAA Courses
25% off all training courses
View HIPAA Courses
Offer ends August 28, 2026

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

CISA Issues Updated Guidance on Minimum Elements of an SBOM

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Investigation (FBI), National Security Agency (NSA), and 15 international cybersecurity authorities have published joint guidance on the minimum elements of a Software Bill of Materials (SBOM). An SBOM is a detailed list of software components, including open-source libraries and hidden dependencies, together with the creators or vendors associated with those components.

Software supply chains are often large and complex, and vendors can be slow to release patches to address vulnerabilities, especially when those vulnerabilities affect third-party components. Cybercriminals target software supply chains as they often have ample time to exploit vulnerabilities before patches are released. Keeping up to date with vendor patches is important; however, simply applying vendor patches does not guarantee that the software is secure. If an SBOM is obtained from a software vendor, users will be able to identify vulnerable or risky components long before patches are released by vendors, allowing them to implement temporary solutions to protect against software supply chain attacks.

In 2021, the National Telecommunications and Information Administration (NTIA) published guidance on the minimum elements for an SBOM, and the latest guidance replaces that document, incorporating stakeholder feedback obtained following the publication of draft guidance in 2025. “SBOM tooling has advanced, driven by the growing number of organizations generating, sharing, consuming, and analyzing SBOMs,” wrote the authoring agencies. “These advancements enable organizations requesting SBOMs to demand more information about their supply chain and software components than they could have in 2021.”

The latest guidance applies to all software solutions, although additional requirements may be necessary for certain types of software, such as AI-based software systems and software-as-a-service (SaaS) solutions in cloud environments. The authoring agencies recommend using the guidance to ensure that their SBOMs include the minimum requirements and then assessing each software solution to determine if any further efforts are required to improve software transparency.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The update includes an additional ten data fields, updates to eight components to clarify scope and specify expectations, and five minor updates to improve information quality and align the guidance with the latest technical developments. The guidance is aimed at organizations that produce, procure, or operate software, and will allow them to better understand the makeup of their software components and supply chains and make more risk-informed decisions.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist