Compare an SBOM to CISA's Minimum Elements

An SBOM is more useful when students can explain what information it contains and what questions it still cannot answer.

Goal

Evaluate an SBOM as evidence about a software supply chain rather than treating its existence as proof of security.

Activity

  1. Obtain an SBOM from a small sample project or instructor-provided example.
  2. Open CISA’s 2026 Minimum Elements for a Software Bill of Materials.
  3. Build a two-column checklist: Present and Missing/unclear.
  4. Locate fields such as component identity/version, supplier or author information, relationships, hashes, licenses, generation context, and SBOM tool information when applicable.
  5. Pick one missing field and explain what risk or uncertainty it creates.

Deliverable

Submit the checklist and a paragraph answering: What can this SBOM support confidently, and what still requires another source or control?

Safety note

Use a classroom project or public sample. Do not upload proprietary software inventories or credentials to third-party services for this exercise.

Source material

First spotted in PTIR: August 1, 2026, Morning Briefing.

CISA’s July 2026 SBOM update expanded the minimum baseline beyond package names and versions to include fields such as component hashes, licenses, the SBOM-generation tool, and generation context. The source is valuable for teaching because students can treat an SBOM as structured evidence and ask which supply-chain questions it can—and cannot—answer.

Consult CISA’s 2026 SBOM minimum-elements resource · Official PDF

Written on August 1, 2026