Japan Co-signs International SBOM Minimum Elements Guidance
Overview
The Ministry of Economy, Trade and Industry and the National Cybersecurity Office of the Cabinet Secretariat jointly signed the international guidance “2026 Minimum Elements for a Software Bill of Materials (SBOM),” which updates minimum SBOM data fields, practices, and processes. Based on a July 2021 document from the U.S. NTIA, the guidance was developed in light of a CISA draft from August 2025 and international discussions. It creates no new obligations and is expected to help improve vulnerability response efficiency as a recommendation for creating new SBOMs and reviewing existing content. It applies to all software, including open-source software, AI software, and SaaS, and Japan’s SBOM Introduction Guide ver 2.0 was introduced as a case example from countries.
Key points
- Relevant Japanese institutions participated in the international update of the SBOM minimum elements.
- The update emphasizes risk-based decisions, scope, information quality, and responses to technological advances.
- Japan’s SBOM Introduction Guide ver 2.0 was introduced in the international guidance.
- Authorities and other organizations from 14 countries, including Japan and the United States, participated in the joint signing.
Overview
This guidance is an international document updating the expected minimum elements for the data fields that constitute SBOM documents and for the practices and processes organizations use to handle and document SBOM data.
Since the U.S. Department of Commerce’s National Telecommunications and Information Administration (NTIA) published a document defining the minimum elements in July 2021, SBOMs have gained international recognition for their role in software supply chain transparency and vulnerability management. This update reflects advances in the latest IT technologies, SBOM generation environments, tools, and technologies.
This guidance is a revised version of the document defining the minimum elements, following the international guidance published in September 2025 on SBOM fundamentals and the importance of using SBOMs.
Key figures
- Publication date of the minimum elements definition document
- July 2021
- Publication date of the CISA draft
- August 2025
- Publication date of the preceding international guidance
- September 2025
- Number of participating countries
- 14 countries
Impact
Software producers are encouraged to generate and manage an SBOM for each product and make it available to users. SBOMs are used in vulnerability management as one approach to addressing challenges faced by both development organizations and user organizations.
Internationally, cybersecurity authorities and other organizations from 14 countries, including Japan and the United States, jointly signed the guidance, which aims to promote the international adoption and advancement of SBOMs. The guidance also states that the European Union’s Cyber Resilience Act requires manufacturers of products with digital elements to provide SBOMs to regulatory authorities.
However, the guidance itself creates no new requirements and is positioned as a recommendation aimed at improving vulnerability response efficiency, rather than adding legal obligations.
Details
The scope covers all software, including open-source software, AI software, and SaaS. Additional elements that may be required for specific types of software are outside the scope of this guidance.
The main updates include adding new elements to support decisions based on risk information, clarifying the scope and identifying expectations, improving information quality, and making minor updates to align with technological advances. The guidance also reflects the removal and consolidation of unnecessary data fields, the organization and refinement of terms and definitions, and additions that improve data quality, reliability, and machine processability.
New items include the creator’s signature, data format name and version, generation context, tool name and version, SBOM version, component hash values and algorithms, and component licenses. Updated items include the creator, timestamp, provider, dependencies, identifiers, names, and versions. Access control was removed.
For practices and processes, the updates cover responses to SBOM data updates, distribution and provision of coverage, explicit indication of unknown information, frequency, and machine-processable data. The Ministry of Economy, Trade and Industry’s “SBOM Introduction Guide for Software Management ver 2.0” was introduced as a case example from Japan concerning implementation support.
Related Articles
2026-07-31 | Ministry of Economy, Trade and Industry
MLIT Trials Green Steel in Public Works
2026-07-31 | Ministry of Economy, Trade and Industry
Applications Open for Bold Investment Tax Incentive
2026-07-28 | Ministry of Economy, Trade and Industry
Revised Law for Sustainable Business Growth Takes Effect July 31
2025-09-17 | Ministry of Economy, Trade and Industry
Brazil's August CPI Turns Negative for First Time in a Year, Influenced by Temporary Electricity Rate Reduction