07/30/2026 | Press release | Distributed by Public on 07/30/2026 00:13
Jul 30, 2026
Joint News Release with the National Cybersecurity Office (NCO)
Today, the Ministry of Economy, Trade and Industry (METI) and the National Cybersecurity Office (NCO) jointly signed the 2026 Minimum Elements for a Software Bill of Materials (SBOM) (hereinafter referred to as the "Guidance"), which provides international guidance concerning the minimum elements for an SBOM for software vulnerability management.
In July 2021, the National Telecommunications and Information Administration (NTIA) of the United States Department of Commerce published the Minimum Elements for a Software Bill of Materials (SBOM), which defined the "minimum elements" for an SBOM, namely, the recommended items for compliance among data fields, practices, and processes for SBOM generation. The Guidance was issued based on this document, while also taking into account the latest IT technologies and the SBOM generation environment, as well as discussions among countries and regions interested in SBOM creation following the release of a draft document by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) in August 2025.
Japan also actively participated in the discussion, which led the Guidance to cite the ministry's Guide on Introduction of Software Bill of Materials (SBOM) for Software Management Ver. 2.0 as an example of initiatives implemented by countries to support the introduction of SBOM.
the Guidance along with other countries and regions that participated in its development.
As a result of Japan's active participation in the discussions, the Guide on Introduction of Software Bill of Materials (SBOM) for Software Management Ver. 2.0 developed by METI was featured in the Guidance as an example of initiatives undertaken by countries to support the adoption of SBOM.
As stated in the Guidance, the EU Cyber Resilience Act imposes an obligation on manufacturers of products with digital elements to provide an SBOM to the relevant regulatory authorities.
Cybersecurity authorities from a total of 14 countries jointly signed the Guidance, including Japan, the United States of America, the Commonwealth of Australia, Canada, the Czech Republic, the French Republic, the Federal Republic of Germany, the Republic of India, the Italian Republic, the Republic of Korea, the Kingdom of the Netherlands, New Zealand, the Republic of Poland, and the Slovak Republic.
The Guidance updates the baseline data fields, practices, and processes for the minimum elements of an SBOM.
Specifically, the updates reflect the removal and consolidation of unnecessary data fields, the organization and refinement of terminology and definitions, and the addition of data fields that enhance data quality, reliability, and machine processability.
Cybersecurity Division, Commerce and Information Policy Bureau