ACSC updates guidance on SBOMs
The Australian Cyber Security Centre (ACSC) has, in collaboration with international partners, released updated guidance on the minimum elements for a software bill of materials (SBOM).
The 2026 Minimum Elements for a Software Bill of Materials (SBOM) guidance aims to help organisations gain greater visibility of software components and better manage cybersecurity risks. SBOMs provide a structured inventory of the components that make up a software application or system. They are an important tool for improving software transparency, identifying dependencies and vulnerabilities, and supporting cybersecurity risk management.
As the use of SBOMs has expanded across government and industry, organisations have identified new ways to use SBOM data to strengthen software security and support supply chain risk management. The updated guidance reflects these developments and outlines the minimum information, practices and processes that should be included in an SBOM.
The ACSC says the 2026 update to the SBOM Minimum Elements reflects current SBOM needs while preserving the core principles of the 2021 version. For example, automation remains critical for driving security at scale. The 2026 update incorporates public feedback received in response to the US Department of Homeland Security’s Request for Comment on 2025 Minimum Elements for a Software Bill of Materials. The revisions improve data quality and support a broader range of SBOM use cases.
The minimum elements outlined apply to SBOMs for all software, including open source software, AI software and SaaS. While additional elements may be necessary to make more complex software systems (such as AI or SaaS) transparent, an SBOM should still include the minimum elements. Additional elements that may be necessary to enable transparency for specific types of software are out of scope for this document.
Organisations that produce, procure or operate software are encouraged to review the advice and consider how SBOMs can support their cybersecurity outcomes.
ASD urges care in the adoption of agentic AI for cyber defence
Care must be taken in the deployment of agentic AI in the wake of news that models being tested...
ASD issues advice on assessing vendor PQC readiness
New guidance helps organisations assess vendor readiness for post-quantum cryptography.
ASD recommends improving router hygiene to counter Russian threat
Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly...
