logo

CISA's New SBOM Guidelines Get Mixed Reviews

ID: 2e43ceaa-1e8e-5c16-ae5e-cf0bbdb95c5b

STIX ID: report--2e43ceaa-1e8e-5c16-ae5e-cf0bbdb95c5b

Feed Name: Dark Reading

Date Published: 2025-08-28

Date Updated: 2026-05-05

Author: Becky Bracken

...
...

CISA released updated 2025 SBOM guidance requiring machine-readable formats (e.g., SPDX, CycloneDX), component cryptographic hashes, tool names, timestamps, and other identifiers to improve verifiability and automation; industry experts generally welcome the move but raise concerns about implementation, standardization, automation (including AI/SaaS use cases), enforcement, and the need for sector-specific guidance and practical playbooks to make SBOMs operationally useful.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.