logo

CISA’s new SBOM standards go beyond checkbox security

ID: 8a0864b3-e0f8-5b21-b68d-a01a82486ed2

STIX ID: report--8a0864b3-e0f8-5b21-b68d-a01a82486ed2

Feed Name: ReversingLabs Blog

Date Published: 2025-09-18

Date Updated: 2026-04-29

Author: Jaikumar Vijayan

...
...

CISA has proposed the first major update to SBOM minimum elements since 2021, adding required fields (e.g., component hash, license, tool name, and generation context) to improve integrity verification, provenance tracking, and operational usability; public comments are open until October 3, 2025. The draft signals rising federal expectations and will push enterprises and vendors to enhance CI/CD pipelines, signing and attestation, coverage metrics, and alignment with SPDX/CycloneDX, while experts note gaps (transitive dependencies, explicit signing rules, runtime SBOMs) and urge integration with VEX and CSAF to ensure SBOMs drive actionable risk reduction rather than compliance noise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.