Australia's 2026 SBOM Minimum Elements: Guide for IT Procurement & Cyber Security Teams
23 September 2026
TechnologySHARE
On 30 July 2026, the Australian Cyber Security Centre (ACSC), alongside international authorities including the U.S. Cybersecurity and Infrastructure Security Agency (CISA), released the updated "2026 Minimum Elements for a Software Bill of Materials (SBOM)". Although this joint guidance does not impose a formal statutory mandate, it effectively elevates SBOMs into cryptographically verified procurement credentials for government and enterprise IT contracts. This article outlines what this shift means for Australian IT professionals, why standard PDFs are no longer enough, and how your organisation can prepare its software supply chain.
What's Changing in 2026: Machine-Readable, Signed SBOMs Replace the 2021 NTIA Baseline
Modernising software supply chain risk management
The 2026 update, co-authored by ASD's ACSC and international partners, officially replaces the 2021 National Telecommunications and Information Administration (NTIA) baseline by expanding the core minimum requirements from 14 to 23 elements. This substantial update aims to modernise software supply chain risk management and improve the overall quality of data that organisations rely on.
The key structural and data differences between the two frameworks are summarised in the table below:
Feature / Baseline | 2021 NTIA Baseline | 2026 ACSC / CISA Minimum Elements |
Core Minimum Elements | 14 baseline elements | Expanded to 23 elements |
Authenticity & Integrity | Basic author and timestamp metadata | Mandatory digital signatures and component hashes |
Licence Information | Optional / Not explicitly required | Mandatory component licences (e.g. SPDX licence IDs) |
Accepted Formats | Machine-readable formats recommended | Strictly interoperable, machine-readable formats (SPDX or CycloneDX) |
Dependency Depth | Primary / Top-level dependencies | "No minimum depth" (transitive dependencies mapped as deep as technically feasible) |
Crucial new data fields for authenticity
The new guidance adds several crucial data fields to ensure authenticity and integrity. Specifically, it requires the inclusion of the SBOM author's digital signature, component hash values, and component licences.
The shift to interoperable, machine-readable formats
It also emphasises that an SBOM must be delivered in an interoperable, machine-readable format — such as SPDX or CycloneDX — and explicitly tied to a specific software release.
Expanded dependency mapping with "no minimum depth"
A major structural change is the requirement for expanded dependency mapping. The updated guidance removes previous depth limits, stating there is "no minimum depth". This requires software producers to map transitive dependencies as deeply as technically feasible, ensuring hidden vulnerabilities are not overlooked deep within the supply chain.
3 Immediate Steps to Verify SBOMs in Your IT Supply Chain
1. Review vendor capabilities and compliance
Organisations must first assess whether current software vendors and service providers possess the technical capability to generate signed, machine-readable Software Bills of Materials (SBOMs) aligned with the 2026 minimum elements. IT procurement leads should audit key suppliers to verify their capability to deliver cryptographically signed SBOMs mapping transitive dependencies without depth limitations.
2. Modernise procurement criteria and contract schedules
Review and update contract schedules, tender documentation, and supplier governance frameworks to explicitly mandate acceptable SBOM formats, specifically SPDX or CycloneDX. Contracts should require vendors to supply a matching, verified SBOM alongside every material software update, patch, or major release rather than treating SBOM delivery as a one-off compliance exercise.
3. Establish internal ingestion and verification processes
Ensure your internal IT security and operations teams have the necessary tooling to automatically ingest, parse, and validate incoming SBOM data. Organisations need systems capable of verifying digital signatures, continuously cross-referencing component hashes against vulnerability databases, and integrating SBOM metrics into existing supply chain risk management workflows.
What Remains Unclear: AI Models and SaaS Components
Dynamic environments and additional AI/SaaS considerations
While the 2026 minimum elements explicitly apply to all software types—including AI models and SaaS—the joint guidance acknowledges that these dynamic architectures present unique transparency challenges. As a result, organisations must treat the minimum elements as a baseline while preparing for specialised frameworks that address cloud and AI-specific risks.
Uncertainty around prime contractor enforcement timelines
It also remains unclear how rapidly prime contractors and major enterprise buyers in Australia will enforce these updated expectations across their supply chains through flow-down contract requirements. While the guidance is active, individual procurement timelines and strictness of enforcement will vary across industry sectors.
Building a Resilient Software Supply Chain in 2026
The 2026 Minimum Elements guidance transforms software transparency from a voluntary best practice into a verifiable necessity for modern IT procurement. While the framework does not constitute a legal mandate, ignoring these updated standards risks severely restricting market access for software providers and exposing enterprise buyers to unmanaged supply chain vulnerabilities.
Official sources:
SHARE
