Overview
- CISA published the 2026 Minimum Elements on July 29, retiring the 2021 NTIA baseline and issuing an internationally co-signed, non-binding specification.
- The guidance replaces the old 'Depth' concept with a 'Coverage' requirement that expects visibility into all components including transitive dependencies so recipients can more accurately rule in or rule out vulnerability exposure.
- New verifiability fields include component hash algorithm and hash value, SBOM author signature, common software identifiers like CPE or Package-URL, tool name and version, and component license to enable integrity checks and automated matching to vulnerability databases.
- The document applies to all software but notes limits for continuous cloud-delivered SaaS and AI artifacts, does not add AI-specific fields, and points to separate G7 AI supply-chain guidance for model and data card issues.
- Procurement and operations teams, especially in health systems, can now cite the 2026 baseline in contracts to demand fuller coverage and cryptographic validation, a change likely to shift negotiation pressure onto software producers and speed vendor adoption of SBOM tooling.