Step 3 of 5

SBOM / Vulnerabilities Baseline

Provide your SBOM and security information so we can establish an initial vulnerability baseline.

03

Software Bill of Materials

Fill in the details below about your software components and security contacts.

Use the numeric ID from Step 2. May be left empty.

2026 SBOM minimum elements

Under the 2026 SBOM Minimum Elements (CISA and partners), each component should list its supplier, component name, version, unique identifiers, cryptographic hash, license and dependency relationships. The SBOM itself should record the author, timestamp, generation tool, format and version, generation context, and a digital signature by the author. This applies to all software, including open-source, AI and SaaS.

Back to overview