CyberzSOC

Publication detail
← Back to advisories & guidance

Joint Guidance: A Shared Vision of Software Bill Of Materials For Cybersecurity ↗ source

September 3, 2025 NSA Advisory
Co-sealed by: ANSSI, ASD/ACSC, BSI, CCCS, CISA, CSA, NCO, NCSC-NL, NCSC-NZ, NIS, NSA, NUKIB

Summary

The authoring organizations aim to further inform producers, choosers (i.e., procuring organizations), and operators of software about the advantages of integrating SBOM generation, analysis, and sharing into security processes and practices. Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components. The first step to addressing these risks is to increase transparency. This is especially important for software in critical infrastructure and systems that carry out essential functions that affect public safety. 1 Hereafter referred to as the authoring organizations. CISA | NSA | ASD’s ACSC | Cyber Centre | NÚKIB | ANSSI | BSI | CERT-IN | ACN METI | NCO | NCSC-NL | NCSC-NZ | NASK | CSA | NBÚ | NIS/NCSC | KISA Software component and supply chain transparency are fundamental for a more secure software ecosystem, as identified in the international Secure by Design efforts.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

No CVEs are referenced in this publication.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.