METI - Ministry of Economy, Trade and Industry of the State of Japan

07/30/2026 | Press release | Distributed by Public on 07/30/2026 00:13

METI Jointly Signs International Guidance on Minimum Elements for Software Bill of Materials (SBOM) for Cybersecurity with National Cybersecurity Office (NCO)

Jul 30, 2026

Joint News Release with the National Cybersecurity Office (NCO)

Today, the Ministry of Economy, Trade and Industry (METI) and the National Cybersecurity Office (NCO) jointly signed the 2026 Minimum Elements for a Software Bill of Materials (SBOM) (hereinafter referred to as the "Guidance"), which provides international guidance concerning the minimum elements for an SBOM for software vulnerability management.

In July 2021, the National Telecommunications and Information Administration (NTIA) of the United States Department of Commerce published the Minimum Elements for a Software Bill of Materials (SBOM), which defined the "minimum elements" for an SBOM, namely, the recommended items for compliance among data fields, practices, and processes for SBOM generation. The Guidance was issued based on this document, while also taking into account the latest IT technologies and the SBOM generation environment, as well as discussions among countries and regions interested in SBOM creation following the release of a draft document by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in August 2025.

Japan also actively participated in the discussion, which led the Guidance to cite the ministry's Guide on Introduction of Software Bill of Materials (SBOM) for Software Management Ver. 2.0 as an example of initiatives implemented by countries to support the introduction of SBOM.

1. Background and purpose

In recent years, the SBOM, which is also called a "list of software components," has attracted companies' attention as a method for solving problems faced by both software development and user organizations in managing software vulnerabilities. Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Secure by Design Software (the revised version of Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security by Design and Default), which was formulated primarily by the Cybersecurity and Infrastructure Security Agency (CISA) and jointly signed by the National Cybersecurity Office (formerly known as the National Center of Incident Readiness and Strategy for Cybersecurity [NISC]), upholds the Secure-by-Design approach, which aims to ensure safety in IT products, in particular, software, beginning from the design process. In this approach, software manufacturers are recommended to generate and manage an SBOM for each product so that users can make use of SBOMs.

As the first in a series of international SBOM guidance documents, A Shared Vision of Software Bill of Materials (SBOM) for Cybersecurity was published in September 2025, outlining a shared understanding among various countries regarding the overview of SBOMs and the importance of their use. METI and the National Cybersecurity Office (NCO) jointly signed the document.  

Since the National Telecommunications and Information Administration (NTIA) of the United States Department of Commerce released the Minimum Elements for a Software Bill of Materials (SBOM) (a document defining the "minimum elements" for an SBOM) in July 2021, the role of SBOMs in securing transparency in the software supply chain has gained international recognition. As SBOM tools and technologies advanced, CISA announced a draft document in August 2025 that updated the minimum elements for an SBOM.

In view of the draft document on the minimum elements for an SBOM, METI endorsed the preparation of the Guidance, a revised version of the Minimum Elements for a Software Bill of Materials (SBOM), which will contribute to the widespread use of SBOMs. METI therefore signed

the Guidance along with other countries and regions that participated in its development.

As a result of Japan's active participation in the discussions, the Guide on Introduction of Software Bill of Materials (SBOM) for Software Management Ver. 2.0 developed by METI was featured in the Guidance as an example of initiatives undertaken by countries to support the adoption of SBOM.

As stated in the Guidance, the EU Cyber Resilience Act imposes an obligation on manufacturers of products with digital elements to provide an SBOM to the relevant regulatory authorities.

Cybersecurity authorities from a total of 14 countries jointly signed the Guidance, including Japan, the United States of America, the Commonwealth of Australia, Canada, the Czech Republic, the French Republic, the Federal Republic of Germany, the Republic of India, the Italian Republic, the Republic of Korea, the Kingdom of the Netherlands, New Zealand, the Republic of Poland, and the Slovak Republic.

2. Outline of the Guidance

The Guidance updates the baseline data fields, practices, and processes for the minimum elements of an SBOM.

  • Data fields: The data that makes up the SBOM document.
  • Practices and processes: How an entity engages with and documents the SBOM data.

Specifically, the updates reflect the removal and consolidation of unnecessary data fields, the organization and refinement of terminology and definitions, and the addition of data fields that enhance data quality, reliability, and machine processability.

​Note: This Guidance does not establish any new requirements. Rather, it is intended to be used as a set of recommendations when generating new SBOMs or reviewing existing ones, with the aim of enhancing efficiency in responding to vulnerabilities.

(1) Major points updated

  • Addition of new elements to support decision-making based on risk information
  • Updates to clarify the scope of the target and to identify expectations
  • Minor updates to enhance information quality and to align with technological advancements

(2) Scope of application

  • Applies to all software, including open source software, AI software, and software as a service (SaaS)
  • Additional elements that may be required for certain types of software are outside the scope of the Guidance.

(3) Minimum elements

Data fields:

  • The newly added items are as follows.
    SBOM Author Signature, SBOM Data Format Name, SBOM Format Version, SBOM Generation Context, SBOM Tool Name, SBOM Tool Version, SBOM Version, Component Hash Value, Component Hash Algorithm, Component License
  • The updated items (major and minor updates) are as follows.
    SBOM Author, SBOM Timestamp, Component Producer, Component Dependency Relationship, Component Identifiers, Component Name, Component Version
  • The following item was removed.
    Access Controls

Practices and processes:

  • The updated items (major and minor updates) are as follows.
    Accommodation of Updates to SBOM Data, Coverage, Distribution and Delivery, Explicitly Identifying Unknown Information, Frequency, Machine-Processable Data

Related Material

Related Links

Division in Charge

Cybersecurity Division, Commerce and Information Policy Bureau

Related website
METI - Ministry of Economy, Trade and Industry of the State of Japan published this content on July 30, 2026, and is solely responsible for the information contained herein. Distributed via Public Technologies (PUBT), unedited and unaltered, on July 30, 2026 at 06:13 UTC. If you believe the information included in the content is inaccurate or outdated and requires editing or removal, please contact us at [email protected]