Comment on 2025 Minimum Elements for a Software Bill of Materials submitted by the SPDX (System Package Data Exchange) Project. The Cybersecurity and Infrastructure Security Agency (CISA) announces the publication and request for public comment on draft guidance entitled, “2025 Minimum Elements for a Software Bill of Materials (SBOM)” (2025 CISA SBOM Minimum Elements), which updates the elements of an SBOM to reflect improvements in SBOM tooling and increased maturity of SBOM implementation. CISA requests input on the clarifications and enhancements in the proposed voluntary guidance. https://www.federalregister.gov/documents/2025/08/22/2025-16147/request-for-comment-on-2025-minimum-elements-for-a-software-bill-of-materials The SPDX Project has submitted feedback regarding the proposed 2025 CISA SBOM Minimum Elements document. The document includes comments on data fields update, automation support update, practices and processes update, and general comments.
Stewart et al. (2025) studied this question.