Japan Co-signs International SBOM Minimum Elements Guidance

Overview

The Ministry of Economy, Trade and Industry and the National Cybersecurity Office of the Cabinet Secretariat jointly signed the international guidance “2026 Minimum Elements for a Software Bill of Materials (SBOM),” which updates minimum SBOM data fields, practices, and processes. Based on a July 2021 document from the U.S. NTIA, the guidance was developed in light of a CISA draft from August 2025 and international discussions. It creates no new obligations and is expected to help improve vulnerability response efficiency as a recommendation for creating new SBOMs and reviewing existing content. It applies to all software, including open-source software, AI software, and SaaS, and Japan’s SBOM Introduction Guide ver 2.0 was introduced as a case example from countries.

This summary was automatically generated by AI. Please refer to the original article for accuracy.

Key points

  • Relevant Japanese institutions participated in the international update of the SBOM minimum elements.
  • The update emphasizes risk-based decisions, scope, information quality, and responses to technological advances.
  • Japan’s SBOM Introduction Guide ver 2.0 was introduced in the international guidance.
  • Authorities and other organizations from 14 countries, including Japan and the United States, participated in the joint signing.

Overview

This guidance is an international document updating the expected minimum elements for the data fields that constitute SBOM documents and for the practices and processes organizations use to handle and document SBOM data.

Since the U.S. Department of Commerce’s National Telecommunications and Information Administration (NTIA) published a document defining the minimum elements in July 2021, SBOMs have gained international recognition for their role in software supply chain transparency and vulnerability management. This update reflects advances in the latest IT technologies, SBOM generation environments, tools, and technologies.

This guidance is a revised version of the document defining the minimum elements, following the international guidance published in September 2025 on SBOM fundamentals and the importance of using SBOMs.

Key figures

Publication date of the minimum elements definition document
July 2021
Publication date of the CISA draft
August 2025
Publication date of the preceding international guidance
September 2025
Number of participating countries
14 countries

Impact

Software producers are encouraged to generate and manage an SBOM for each product and make it available to users. SBOMs are used in vulnerability management as one approach to addressing challenges faced by both development organizations and user organizations.

Internationally, cybersecurity authorities and other organizations from 14 countries, including Japan and the United States, jointly signed the guidance, which aims to promote the international adoption and advancement of SBOMs. The guidance also states that the European Union’s Cyber Resilience Act requires manufacturers of products with digital elements to provide SBOMs to regulatory authorities.

However, the guidance itself creates no new requirements and is positioned as a recommendation aimed at improving vulnerability response efficiency, rather than adding legal obligations.

Details

The scope covers all software, including open-source software, AI software, and SaaS. Additional elements that may be required for specific types of software are outside the scope of this guidance.

The main updates include adding new elements to support decisions based on risk information, clarifying the scope and identifying expectations, improving information quality, and making minor updates to align with technological advances. The guidance also reflects the removal and consolidation of unnecessary data fields, the organization and refinement of terms and definitions, and additions that improve data quality, reliability, and machine processability.

New items include the creator’s signature, data format name and version, generation context, tool name and version, SBOM version, component hash values and algorithms, and component licenses. Updated items include the creator, timestamp, provider, dependencies, identifiers, names, and versions. Access control was removed.

For practices and processes, the updates cover responses to SBOM data updates, distribution and provision of coverage, explicit indication of unknown information, frequency, and machine-processable data. The Ministry of Economy, Trade and Industry’s “SBOM Introduction Guide for Software Management ver 2.0” was introduced as a case example from Japan concerning implementation support.

Related Articles