CISA’s 2025 SBOM Guidance Adds Hashes, Licenses, Tool Metada...
Blog post from Socket
CISA's 2025 draft update to the Minimum Elements for a Software Bill of Materials (SBOM) introduces new fields such as hashes, licenses, tool metadata, and generation context to enhance the transparency, verifiability, and operational utility of software inventories. Released for public comment until October 3, 2025, the draft reflects advancements since the 2021 NTIA SBOM Minimum Elements, aiming to support security and compliance workflows by making SBOMs more actionable. The inclusion of component hashes enables integrity checks, while license data extends the usefulness of SBOMs into compliance and legal risk management. Tool metadata provides insights into the provenance of an SBOM, and generation context clarifies the stage at which it was created, aiding consumers in understanding its applications and limitations. As SBOM practices mature, CISA seeks feedback from various stakeholders on the draft, which is available as a 17-page PDF, to address challenges in adapting SBOMs to emerging technologies and use cases.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.