What are Minimum Elements?
The baseline for what an SBOM must contain
The SBOM Minimum Elements are a baseline for what an SBOM must contain. They were published in July 2021 by the US National Telecommunications and Information Administration (NTIA), as directed by Executive Order 14028.
The document is American, but it is used as a reference in Europe too, and by most tools that check SBOM quality.
Three parts
The Minimum Elements consist of three parts:
- Data fields. The information that must exist about each component.
- Automation support. The SBOM must be machine-readable and follow a standard format.
- Practices and processes. How and when SBOMs are created, updated and shared.
The data fields
| Field | Description |
|---|---|
| Supplier Name | The entity that creates, defines and identifies the component |
| Component Name | The name the supplier has given the component |
| Version of the Component | The version the SBOM refers to |
| Other Unique Identifiers | For example Package URL (purl) or CPE |
| Dependency Relationship | That one component is included in another |
| Author of SBOM Data | The entity that created the SBOM |
| Timestamp | When the SBOM was created |
Automation support
The SBOM must be in a format that tools can read and produce. NTIA named three formats: SPDX, CycloneDX and SWID tags. In practice CycloneDX and SPDX are used.
Practices and processes
- Frequency. A new SBOM is created when the software changes, for example with a new version.
- Depth. The SBOM contains at least the top-level dependencies, and preferably the transitive ones too.
- Known unknowns. If part of the dependency tree is not known, that is stated explicitly.
- Distribution. The SBOM is made available to those who need it without undue delay.
- Access control. The supplier may set the terms for who gets access to it.
- Accommodation of mistakes. The practice is new, and mistakes should be correctable without penalty.
The 2025 update
In August 2025 CISA published a draft of updated Minimum Elements for comment. The draft clarifies the existing fields and adds four new ones:
- Component Hash
- License
- Tool Name, the tool that created the SBOM
- Generation Context, whether the SBOM was created from source, at build time or from a finished product
The draft also states that the elements apply to all software, including open source, AI systems and software as a service.
Minimum Elements and the CRA
The Cyber Resilience Act (CRA) does not refer to the Minimum Elements. The regulation requires an SBOM in a commonly used and machine-readable format that covers at least the top-level dependencies, but it does not state which fields to include. The German guideline BSI TR-03183-2 specifies the content in more detail for CRA purposes.
References
- NTIA: SBOM Minimum ElementsPDF, ntia.doc.gov
NTIA:s rapport från juli 2021 med lägstanivån för vad en SBOM ska innehålla.
- CISA: 2025 Minimum Elements for a Software Bill of Materials (draft)PDF, cisa.gov
CISA's draft update of the Minimum Elements, published for comment in August 2025.