Publication status matters

DocumentStatus at October 4, 2026How to use it
NTIA 2021 reportHistorical baselineUnderstand older contracts and references.
CISA 2025 public-comment documentDraft consultation, followed by the 2026 publicationDo not cite it as the current final baseline.
CISA and partners 2026 documentPublished July 29, 2026; updates and replaces 2021Use for current guidance-based requirements.

Source: CISA · July 29, 2026 release announcement.

Source: CISA and partners · 2026 Minimum Elements (ACSC publication) · Introduction and Scope.

What the 2021 report established

NTIA grouped the baseline into data fields, automation support, and practices and processes. Its seven fields were supplier, component name, component version, other unique identifiers, dependency relationship, author of SBOM data and timestamp. Automation supported machine-readable exchange. The process areas included frequency, depth, known unknowns, delivery, access and mistakes.

Source: NTIA · 2021 Minimum Elements.

A contract may still refer to that report by date. Replacing an editorial baseline does not automatically rewrite a signed contract or an agency’s separate guidance. Map the referenced obligation, the current data policy and the receiving system’s support before changing deliveries.

What changed in 2026

The new guidance adds author signature, format name/version, generation context, tool name/version, SBOM version, component hash/algorithm and license. It replaces supplier name with component producer, expects coverage including transitive dependencies, and distinguishes unknown information from withheld information. It addresses corrections, release frequency, delivery and machine-processable exchange. These expectations do not create new legal requirements.

Source: CISA and partners · 2026 Minimum Elements (ACSC publication) · Notable updates, Coverage and Scope.

Turn guidance into a receiving contract

Receiving decisionSuggested acceptance evidence
Artifact and release bindingProduct identifier, release version, digest and generation context agree with delivery records.
Producer versus authorThe component creator and entity producing the inventory are distinguishable.
Identifiers and versionKnown package coordinates resolve; ambiguous identities are flagged.
Graph and coverageA reference application includes expected direct and transitive edges; exclusions are explained.
Unknowns and redactionsThe recipient can distinguish absent, unknown and withheld information.
IntegritySignature verification returns a trusted author and detects a modified document.
CorrectionsA revised inventory retains prior evidence and identifies the superseded revision.

These are buyer-designed tests, not a restatement of the official document. Choose severity levels for failures. An unexplained missing product version can block intake; a documented gap in a legacy supplier inventory may require a time-bound exception rather than deletion of the inventory.

A minimum is not an assurance level

Two documents may contain the expected metadata yet differ dramatically in coverage. One may come from resolved build inputs; another may come from heuristics over a stripped binary. Keep discovery evidence, confidence and known limitations alongside the normalized inventory.

For firmware, inspect how bundled code, static linking and proprietary modules are accounted for. For SaaS, agree which production environment and snapshot are described. For license review, distinguish observed license evidence from a legal conclusion. For vulnerability response, ensure identifiers work with the advisory sources you actually use.

Version the profile and test it

  1. Write a named intake profile with a date, authority and exact format versions.
  2. Provide suppliers with passing and failing examples.
  3. Run schema checks separately from identity and coverage checks.
  4. Store a machine-readable result with each accepted artifact.
  5. Review the profile when guidance, formats or receiving tools change.

The validation guide provides a layered test plan. The RFP matrix turns these tests into evidence requests for platform suppliers.

Primary sources