SBOM Guide
SBOM basics

What are Minimum Elements?

The baseline for what an SBOM must contain

The SBOM Minimum Elements are a baseline for what an SBOM must contain. They were published in July 2021 by the US National Telecommunications and Information Administration (NTIA), as directed by Executive Order 14028.

The document is American, but it is used as a reference in Europe too, and by most tools that check SBOM quality.

Three parts

The Minimum Elements consist of three parts:

  • Data fields. The information that must exist about each component.
  • Automation support. The SBOM must be machine-readable and follow a standard format.
  • Practices and processes. How and when SBOMs are created, updated and shared.

The data fields

FieldDescription
Supplier NameThe entity that creates, defines and identifies the component
Component NameThe name the supplier has given the component
Version of the ComponentThe version the SBOM refers to
Other Unique IdentifiersFor example Package URL (purl) or CPE
Dependency RelationshipThat one component is included in another
Author of SBOM DataThe entity that created the SBOM
TimestampWhen the SBOM was created

Automation support

The SBOM must be in a format that tools can read and produce. NTIA named three formats: SPDX, CycloneDX and SWID tags. In practice CycloneDX and SPDX are used.

Practices and processes

  • Frequency. A new SBOM is created when the software changes, for example with a new version.
  • Depth. The SBOM contains at least the top-level dependencies, and preferably the transitive ones too.
  • Known unknowns. If part of the dependency tree is not known, that is stated explicitly.
  • Distribution. The SBOM is made available to those who need it without undue delay.
  • Access control. The supplier may set the terms for who gets access to it.
  • Accommodation of mistakes. The practice is new, and mistakes should be correctable without penalty.

The 2025 update

In August 2025 CISA published a draft of updated Minimum Elements for comment. The draft clarifies the existing fields and adds four new ones:

  • Component Hash
  • License
  • Tool Name, the tool that created the SBOM
  • Generation Context, whether the SBOM was created from source, at build time or from a finished product

The draft also states that the elements apply to all software, including open source, AI systems and software as a service.

Minimum Elements and the CRA

The Cyber Resilience Act (CRA) does not refer to the Minimum Elements. The regulation requires an SBOM in a commonly used and machine-readable format that covers at least the top-level dependencies, but it does not state which fields to include. The German guideline BSI TR-03183-2 specifies the content in more detail for CRA purposes.

References

On this page