{
  "node_id": "cisa-sbom-minimum-elements-2021",
  "title": "The Minimum Elements For a Software Bill of Materials (SBOM)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-18",
  "bluf": "Mandated by U.S. Executive Order 14028, this standard from the NTIA defines the minimum required data fields, formats, and practices for a Software Bill of Materials (SBOM). It requires all software producers to provide SBOMs that list components, versions, suppliers, and dependency relationships to enhance software supply chain transparency for consumers and operators.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "c-scrm-practices-systems-organizations",
    "pci-dss-v4-requirement-6",
    "iso-iec-5230-openchain",
    "nis2-supply-chain-security-article-22"
  ],
  "primary_citations_count": 7
}