Publication status matters
| Document | Status at October 4, 2026 | How to use it |
|---|---|---|
| NTIA 2021 report | Historical baseline | Understand older contracts and references. |
| CISA 2025 public-comment document | Draft consultation, followed by the 2026 publication | Do not cite it as the current final baseline. |
| CISA and partners 2026 document | Published July 29, 2026; updates and replaces 2021 | Use for current guidance-based requirements. |
Source: CISA · July 29, 2026 release announcement.
Source: CISA and partners · 2026 Minimum Elements (ACSC publication) · Introduction and Scope.
What the 2021 report established
NTIA grouped the baseline into data fields, automation support, and practices and processes. Its seven fields were supplier, component name, component version, other unique identifiers, dependency relationship, author of SBOM data and timestamp. Automation supported machine-readable exchange. The process areas included frequency, depth, known unknowns, delivery, access and mistakes.
Source: NTIA · 2021 Minimum Elements.
A contract may still refer to that report by date. Replacing an editorial baseline does not automatically rewrite a signed contract or an agency’s separate guidance. Map the referenced obligation, the current data policy and the receiving system’s support before changing deliveries.
What changed in 2026
The new guidance adds author signature, format name/version, generation context, tool name/version, SBOM version, component hash/algorithm and license. It replaces supplier name with component producer, expects coverage including transitive dependencies, and distinguishes unknown information from withheld information. It addresses corrections, release frequency, delivery and machine-processable exchange. These expectations do not create new legal requirements.
Source: CISA and partners · 2026 Minimum Elements (ACSC publication) · Notable updates, Coverage and Scope.
Turn guidance into a receiving contract
| Receiving decision | Suggested acceptance evidence |
|---|---|
| Artifact and release binding | Product identifier, release version, digest and generation context agree with delivery records. |
| Producer versus author | The component creator and entity producing the inventory are distinguishable. |
| Identifiers and version | Known package coordinates resolve; ambiguous identities are flagged. |
| Graph and coverage | A reference application includes expected direct and transitive edges; exclusions are explained. |
| Unknowns and redactions | The recipient can distinguish absent, unknown and withheld information. |
| Integrity | Signature verification returns a trusted author and detects a modified document. |
| Corrections | A revised inventory retains prior evidence and identifies the superseded revision. |
These are buyer-designed tests, not a restatement of the official document. Choose severity levels for failures. An unexplained missing product version can block intake; a documented gap in a legacy supplier inventory may require a time-bound exception rather than deletion of the inventory.
A minimum is not an assurance level
Two documents may contain the expected metadata yet differ dramatically in coverage. One may come from resolved build inputs; another may come from heuristics over a stripped binary. Keep discovery evidence, confidence and known limitations alongside the normalized inventory.
For firmware, inspect how bundled code, static linking and proprietary modules are accounted for. For SaaS, agree which production environment and snapshot are described. For license review, distinguish observed license evidence from a legal conclusion. For vulnerability response, ensure identifiers work with the advisory sources you actually use.
Version the profile and test it
- Write a named intake profile with a date, authority and exact format versions.
- Provide suppliers with passing and failing examples.
- Run schema checks separately from identity and coverage checks.
- Store a machine-readable result with each accepted artifact.
- Review the profile when guidance, formats or receiving tools change.
The validation guide provides a layered test plan. The RFP matrix turns these tests into evidence requests for platform suppliers.
Primary sources
- NTIA · 2021 Minimum ElementsHistorical government guidance
- CISA and partners · 2026 Minimum Elements (ACSC publication)Published government guidance
- CISA · July 29, 2026 release announcementOfficial publication announcement