The Canadian Centre for Cyber Security (Cyber Centre) has joined the United States' Cybersecurity and Infrastructure Security Agency (CISA) and other international partners in issuing guidance on the minimum elements for a software bill of materials (SBOM).
An SBOM is a nested inventory of the elements that make up software applications and systems. Organizations that produce, procure and operate software can use SBOM data to better understand their software supply chain, identify vulnerabilities and manage risks.
This publication updates and replaces the 2021 Minimum Elements for a Software Bill of Materials published by the United States' National Telecommunications and Information Administration. The updated minimum elements reflect advances in SBOM adoption, tooling and use cases while preserving the core principles of the 2021 framework. They specify the baseline technologies and practices that SBOMs should meet and apply to all software, including open-source software, artificial intelligence software, and software as a service.
Organizations that develop, procure and operate software should produce and request SBOMs that meet the minimum expected data fields and the practices and processes, as specified in this guidance.
Read the full joint guidance: 2026 Minimum Elements for a Software Bill of Materials (SBOM)