How to use this library

Start with the authority relevant to your use case. For a statutory duty, inspect the legal provision and scope. For documentation recommendations, inspect current agency guidance. For interoperability, use the exact schema or specification edition implemented by your tools.

The current minimum-elements document is reproduced by Australia’s ACSC, a co-authoring government agency. CISA’s release bulletin independently confirms publication. Direct CISA pages returned access errors during this build; a blocked fetch is not evidence that the document was withdrawn.

U.S. baseline and CISA

Historical government guidance

NTIA · 2021 Minimum Elements

The original seven-field baseline and its three areas.

Multistakeholder guidance

NTIA · Framing Software Component Transparency (2021)

Component relationships, authorship and lifecycle concepts.

Official publication announcement

CISA · July 29, 2026 release announcement

Confirms the release of the joint 2026 guidance.

Published government guidance

CISA and partners · 2026 Minimum Elements (ACSC publication)

Updates and replaces the 2021 report; incorporates the 2025 consultation.

Community guidance

CISA · Tooling and Implementation (SBOM types)

Design, source, build, analyzed, deployed and runtime contexts.

Community guidance

CISA · Minimum Requirements for VEX

Product and vulnerability identification, status and justification.

FDA and medical devices

Final guidance publication record

FDA · Current guidance publication record

February 2026 guidance supersedes June 2025 guidance.

Final, nonbinding guidance

FDA · Cybersecurity guidance, February 2026

Sections V.A.4, VI and VII.C.3 address SBOM documentation and cyber devices.

Agency explanation of statute

FDA · Cybersecurity in Medical Devices FAQs

Section 524B scope, submission timing and component categories.

Federal procurement and NIST

Current federal policy memorandum

OMB · M-26-05, January 23, 2026

Rescinds M-22-18 and M-23-16; permits agency-specific assurance terms.

Final government guidance

NIST · SSDF 1.1, SP 800-218

Secure software development practices; not an SBOM format.

Initial public draft

NIST · SSDF 1.2, SP 800-218 Rev. 1

December 17, 2025 draft; closed comments do not establish final status.

EU Cyber Resilience Act

Binding EU regulation

EUR-Lex · Regulation (EU) 2024/2847

Articles 2, 13, 14, 31, 69 and 71; Annex I, Part II.

Official legal-text summary

European Commission · CRA legislative summary

Scope, economic operators and staged obligations.

Official implementation overview

European Commission · Cyber Resilience Act

Scope overview and links to July 2026 guidance.

Implementation timeline

European Commission · CRA implementation

Tracks guidance, standards work and staged application dates.

Agency implementation guidance

European Commission · CRA reporting obligations

Reporting is applicable from September 11, 2026; deadlines and platform.

Operational reporting guidance

ENISA · Single Reporting Platform FAQs

Reporting workflow, awareness and third-party components.

SPDX

Published specification

SPDX · Stable specification 3.0.1

Version used for the current data-model comparison.

Published specification

SPDX · Specification scope

Composition, licensing, security, build, AI and data relationships.

Published specification

SPDX · Licensing profile

Declared and concluded license relationships.

Published specification

SPDX · Build profile

Inputs, outputs, tools and build relationships.

Standards organization

SPDX · Specifications and ISO status

SPDX 3.0 family and prior 2.3 ecosystem; ISO/IEC 5962:2021.

Release candidate

SPDX · 3.1 release candidate announcement

January 2026 review announcement; not treated here as stable.

CycloneDX and Ecma

Published specification

CycloneDX · Specification overview

Current published version 1.7 and serializations.

Schema reference

CycloneDX · 1.7 JSON reference

Document metadata, components, graph and validation fields.

Standard

Ecma International · ECMA-424

Second edition, December 2025, defines CycloneDX 1.7.

Standards project news

CycloneDX · News and release announcements

2.0 announced as upcoming; published overview still lists 1.7.

Standard

Ecma International · ECMA-427 Package-URL

First edition, December 2025; package identity syntax.

Specification project documentation

CycloneDX · VEX capability

Vulnerability applicability within a product context.

Tool and exchange documentation

Project specification

OpenVEX · Specification

Machine-readable statements and their status fields.

Tool documentation

Syft · Official project documentation

Container and filesystem SBOM generation; documented output formats.

Tool documentation

cdxgen · Official project documentation

CycloneDX generation across supported package ecosystems.

Tool documentation

OWASP Dependency-Track · Official project

Component analysis using CycloneDX BOM ingestion.

Version and publication checks

ItemReference usedStatus
SPDX3.0.1 stable specification3.1 release candidate is separate.
CycloneDX1.7 published overview2.0 announcement is not treated as a release.
ECMA-424Second edition, December 2025Defines CycloneDX 1.7.
ECMA-427First edition, December 2025Package-URL syntax.
CISA minimum elements2026 published guidance2025 consultation incorporated; 2021 replaced.
FDA cybersecurityFebruary 2026 final guidanceSupersedes June 2025.
NIST SSDF1.1 final; 1.2 initial public draftDraft and final kept distinct.
Federal assuranceOMB M-26-05Earlier attestation memoranda rescinded.

Review dates record this edition’s research checks, not continuous monitoring. Recheck source status before a filing, procurement or conformity decision.

Known access limitations

The detailed Commission CRA guidance download was rate-limited. This edition uses the official regulation, implementation overview, legislative summary, reporting page and ENISA operational FAQ; it avoids interpretations relying solely on the inaccessible annex. Some direct CISA PDFs were access-blocked, although indexed official material was available.

A source link that returns a challenge, 403 or 429 for an automated checker should be checked manually. Do not replace it with a vendor interpretation just to obtain a successful HTTP status.