How to use this library
Start with the authority relevant to your use case. For a statutory duty, inspect the legal provision and scope. For documentation recommendations, inspect current agency guidance. For interoperability, use the exact schema or specification edition implemented by your tools.
The current minimum-elements document is reproduced by Australia’s ACSC, a co-authoring government agency. CISA’s release bulletin independently confirms publication. Direct CISA pages returned access errors during this build; a blocked fetch is not evidence that the document was withdrawn.
U.S. baseline and CISA
NTIA · 2021 Minimum Elements
The original seven-field baseline and its three areas.
NTIA · Framing Software Component Transparency (2021)
Component relationships, authorship and lifecycle concepts.
CISA · July 29, 2026 release announcement
Confirms the release of the joint 2026 guidance.
CISA and partners · 2026 Minimum Elements (ACSC publication)
Updates and replaces the 2021 report; incorporates the 2025 consultation.
CISA · Tooling and Implementation (SBOM types)
Design, source, build, analyzed, deployed and runtime contexts.
CISA · Minimum Requirements for VEX
Product and vulnerability identification, status and justification.
FDA and medical devices
FDA · Current guidance publication record
February 2026 guidance supersedes June 2025 guidance.
FDA · Cybersecurity guidance, February 2026
Sections V.A.4, VI and VII.C.3 address SBOM documentation and cyber devices.
FDA · Cybersecurity in Medical Devices FAQs
Section 524B scope, submission timing and component categories.
Federal procurement and NIST
OMB · M-26-05, January 23, 2026
Rescinds M-22-18 and M-23-16; permits agency-specific assurance terms.
NIST · SSDF 1.1, SP 800-218
Secure software development practices; not an SBOM format.
NIST · SSDF 1.2, SP 800-218 Rev. 1
December 17, 2025 draft; closed comments do not establish final status.
EU Cyber Resilience Act
EUR-Lex · Regulation (EU) 2024/2847
Articles 2, 13, 14, 31, 69 and 71; Annex I, Part II.
European Commission · CRA legislative summary
Scope, economic operators and staged obligations.
European Commission · Cyber Resilience Act
Scope overview and links to July 2026 guidance.
European Commission · CRA implementation
Tracks guidance, standards work and staged application dates.
European Commission · CRA reporting obligations
Reporting is applicable from September 11, 2026; deadlines and platform.
ENISA · Single Reporting Platform FAQs
Reporting workflow, awareness and third-party components.
SPDX
SPDX · Stable specification 3.0.1
Version used for the current data-model comparison.
SPDX · Specification scope
Composition, licensing, security, build, AI and data relationships.
SPDX · Specifications and ISO status
SPDX 3.0 family and prior 2.3 ecosystem; ISO/IEC 5962:2021.
SPDX · 3.1 release candidate announcement
January 2026 review announcement; not treated here as stable.
CycloneDX and Ecma
CycloneDX · Specification overview
Current published version 1.7 and serializations.
CycloneDX · 1.7 JSON reference
Document metadata, components, graph and validation fields.
CycloneDX · News and release announcements
2.0 announced as upcoming; published overview still lists 1.7.
Ecma International · ECMA-427 Package-URL
First edition, December 2025; package identity syntax.
CycloneDX · VEX capability
Vulnerability applicability within a product context.
Tool and exchange documentation
Syft · Official project documentation
Container and filesystem SBOM generation; documented output formats.
cdxgen · Official project documentation
CycloneDX generation across supported package ecosystems.
OWASP Dependency-Track · Official project
Component analysis using CycloneDX BOM ingestion.
Version and publication checks
| Item | Reference used | Status |
|---|---|---|
| SPDX | 3.0.1 stable specification | 3.1 release candidate is separate. |
| CycloneDX | 1.7 published overview | 2.0 announcement is not treated as a release. |
| ECMA-424 | Second edition, December 2025 | Defines CycloneDX 1.7. |
| ECMA-427 | First edition, December 2025 | Package-URL syntax. |
| CISA minimum elements | 2026 published guidance | 2025 consultation incorporated; 2021 replaced. |
| FDA cybersecurity | February 2026 final guidance | Supersedes June 2025. |
| NIST SSDF | 1.1 final; 1.2 initial public draft | Draft and final kept distinct. |
| Federal assurance | OMB M-26-05 | Earlier attestation memoranda rescinded. |
Review dates record this edition’s research checks, not continuous monitoring. Recheck source status before a filing, procurement or conformity decision.
Known access limitations
The detailed Commission CRA guidance download was rate-limited. This edition uses the official regulation, implementation overview, legislative summary, reporting page and ENISA operational FAQ; it avoids interpretations relying solely on the inaccessible annex. Some direct CISA PDFs were access-blocked, although indexed official material was available.
A source link that returns a challenge, 403 or 429 for an automated checker should be checked manually. Do not replace it with a vendor interpretation just to obtain a successful HTTP status.