Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
US and Allies Revise Software Bill of Materials Guidelines

US and Allies Revise Software Bill of Materials Guidelines

Posted on July 30, 2026 By CWS

This week, the United States and 13 allied countries unveiled revised guidelines for the minimum elements of a Software Bill of Materials (SBOM). These updates are intended to enhance supply chain security and software transparency, building on the SBOM Minimum Elements guidance issued by the National Telecommunications and Information Administration (NTIA) in 2021. The revisions incorporate public feedback received last year.

Enhancing Software Transparency and Security

An SBOM is described by the agencies as a fundamental component for software security and supply chain risk management. It aids organizations in cataloging the software and its components within their systems accurately. The updated guidance outlines the baseline technologies and practices that should be integrated into an SBOM.

By utilizing SBOM data, organizations involved in the production, procurement, and operation of software can gain greater insight into their supply chains. This visibility is crucial for making informed risk management decisions, addressing both known and emerging vulnerabilities and risks.

Key Changes in the Updated Guidance

The updated document maintains the core principles of the 2021 guidelines while addressing current SBOM needs. It enhances data quality, supports a broader range of applications, introduces new elements, and clarifies existing descriptions. New elements include the Component Hash Algorithm, Component Hash Value, and Author Signature, among others.

Although two elements—Access Control and Software Identification (SWID) Tags—were removed, several others were replaced, clarified, or modified to improve data mapping. For example, the component name now allows multiple entries, reflecting advancements in SBOM tooling and growing demands for supply chain visibility.

Broader Implications and Future Outlook

The revised guidelines are applicable to all types of software, but specific categories, like AI systems and Software as a Service (SaaS), may require additional elements. In May, the Group of Seven (G7) countries released SBOM guidance focused on AI.

The advancements in SBOM tooling, driven by the increasing number of organizations generating and analyzing SBOMs, enable more comprehensive supply chain insights than were possible in 2021. As these tools evolve, organizations are better equipped to demand detailed information about their software components.

In conclusion, the updated SBOM guidelines represent a significant step forward in enhancing software security. By refining these elements, the US and its allies are reinforcing efforts to protect against supply chain risks and vulnerabilities, ensuring a more secure digital environment.

Security Week News Tags:AI systems, Cybersecurity, G7 countries, NTIA, SaaS, SBOM, software components, Software Security, software transparency, supply chain, supply chain risk, US government

Post navigation

Previous Post: Russian Hackers Leverage Microsoft OWA Vulnerability
Next Post: Cisco Urges Update Amid Firewall Vulnerability Exploit

Related Posts

‘SolyxImmortal’ Information Stealer Emerges – SecurityWeek ‘SolyxImmortal’ Information Stealer Emerges – SecurityWeek Security Week News
NewCore Launches with  Million in Seed Funding NewCore Launches with $66 Million in Seed Funding Security Week News
Chinese Hacker Extradited to US for Cyberattacks Chinese Hacker Extradited to US for Cyberattacks Security Week News
Tycoon 2FA Resumes Activity After Global Law Enforcement Disruption Tycoon 2FA Resumes Activity After Global Law Enforcement Disruption Security Week News
Exaforce Secures 5M to Advance AI-Driven SOC Platform Exaforce Secures $125M to Advance AI-Driven SOC Platform Security Week News
Critical Dialogflow CX Flaw Exposed AI Conversations Critical Dialogflow CX Flaw Exposed AI Conversations Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet
  • Critical Flaw in Ruflo AI Exposes Systems to Attack
  • FCC Restricts Foreign Robots and Inverters Over Cyber Threats
  • Cisco Urges Update Amid Firewall Vulnerability Exploit
  • US and Allies Revise Software Bill of Materials Guidelines

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Linux Cryptomining Attack Uses PAM to Conceal XMRig Botnet
  • Critical Flaw in Ruflo AI Exposes Systems to Attack
  • FCC Restricts Foreign Robots and Inverters Over Cyber Threats
  • Cisco Urges Update Amid Firewall Vulnerability Exploit
  • US and Allies Revise Software Bill of Materials Guidelines

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark