Today, in collaboration with international partners, we have released updated guidance on the 2026 Minimum Elements for a Software Bill of Materials (SBOM). The guidance helps organisations gain greater visibility of software components and better manage cybersecurity risks.
SBOMs provide a structured inventory of the components that make up a software application or system. They are an important tool for improving software transparency, identifying dependencies and vulnerabilities, and supporting cybersecurity risk management.
As the use of SBOMs has expanded across government and industry, organisations have identified new ways to use SBOM data to strengthen software security and support supply chain risk management. Our updated guidance reflects these developments and outlines the minimum information, practices and processes that should be included in an SBOM.
Organisations that produce, procure or operate software are encouraged to review our advice and consider how SBOMs can support their cyber security outcomes.
Read the publication 2026 Minimum Elements for a Software Bill of Materials (SBOM).