Feeds2.Feedburner International Guidance Signed for Software Bill of Materials (SBOM)
Article Content
Browse articles
- •Japan's METI and NCO signed new SBOM guidance on July 30, 2026.
- •The guidance updates the 2021 SBOM framework from the U.S. NTIA.
- •14 countries collaborated on the new SBOM standards, enhancing software vulnerability management.
On July 30, 2026, Japan's METI and NCO signed the 2026 Minimum Elements for an SBOM, providing international guidance for software vulnerability management. This guidance updates the initial 2021 SBOM framework from the U.S. NTIA, incorporating insights from recent discussions among 14 countries. The new guidance includes refined terminology, consolidated data fields, and enhanced data quality measures. The EU Cyber Resilience Act mandates manufacturers to provide SBOMs to regulatory authorities. Japan's SBOM initiatives were highlighted as exemplary in the guidance, reflecting its active participation in international cybersecurity discussions.
Ask AI about this cluster
Answers cite the sources they use
Updated 53d ago How this analysis works
Timeline
2021-07-01
Initial SBOM guidance published
The U.S. NTIA released the first Minimum Elements for a Software Bill of Materials to define compliance standards.
Meti.Go.Jp2025-08-01
Draft SBOM document released by CISA
CISA released a draft document prompting international discussions on SBOM creation.
Meti.Go.Jp2026-07-30
New SBOM guidance signed
Japan's METI and NCO signed the updated SBOM guidance, reflecting contributions from 14 countries.
Meti.Go.JpMore articles in this cluster (2)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…