CISA's New SBOM Guidelines Get Mixed Reviews
ID: 2e43ceaa-1e8e-5c16-ae5e-cf0bbdb95c5b
STIX ID: report--2e43ceaa-1e8e-5c16-ae5e-cf0bbdb95c5b
Feed Name: Dark Reading
CISA released updated 2025 SBOM guidance requiring machine-readable formats (e.g., SPDX, CycloneDX), component cryptographic hashes, tool names, timestamps, and other identifiers to improve verifiability and automation; industry experts generally welcome the move but raise concerns about implementation, standardization, automation (including AI/SaaS use cases), enforcement, and the need for sector-specific guidance and practical playbooks to make SBOMs operationally useful.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
