Information Technology Industry Council
CISANonrulemakingCISA-2025-0007

Request for Comment on 2025 Minimum Elements for a Software Bill of Materials

RIN
Last modified
Oct 6, 2025
Comment window
closed 298d ago
Information Technology Industry Council filings
1

Activity

Information Technology Industry Council filed 1 comment on this docket between Oct 3, 2025 and Oct 3, 2025. 2 other organizations filed here. The comment window closed 298d ago.

What Information Technology Industry Council filed (1)

Oct 3, 2025· Comment Submitted by Information Technology Industry Council (ITI)· CISA-2025-0007-0054

The Information Technology Industry Council (ITI) appreciates the opportunity to provide feedback on the updated Minimum Elements for a Software Bill of Materials (SBOM). ITI is the premier global advocate for technology, representing the world's most innovative companies. Our members design, build, and operate the digital infrastructure that underpins the global economy, and we share the U.S. government's goal of improving software supply chain security and transparency. We appreciate the Cybersecurity and Infrastructure Security Agency's (CISA's) attention to the need to improve transparency across software supply chains. The updated draft of the Minimum Elements for SBOMs represents an important update to the original NTIA publication and reflects progress made by the community in advancing SBOM practices. We agree that transparency is critical for stronger vulnerability management and application security. At the same time, SBOMs will only deliver value if implementation challenges are addressed and guidance remains focused on outcomes. Consistency across tools, clarity on government use cases, and integration with practices like continuous monitoring are essential. ITI's recommendations focus on ensuring that SBOMs deliver meaningful value in practice. We urge CISA to clarify implementation expectations, avoid prescriptive requirements that lock in point-in-time approaches, and promote solutions that support continuous, real-time transparency as they mature. With clearer guidance and alignment across agencies, SBOMs can become a useful building block in a broader strategy to strengthen software supply chain security. We appreciate your attention to this matter and thank you for your consideration of our comments.

Abstract

No abstract recorded.

View on regulations.gov →