Government Advisory

New Global Guidance Aims to Strengthen Software Supply Chain Transparency

ACSC · 30 July 2026
Key Takeaway When choosing software vendors or IT providers, ask whether they can supply a Software Bill of Materials so you can better understand and manage your exposure to supply chain vulnerabilities.

The Australian Cyber Security Centre (ACSC) has partnered with international agencies to release updated guidance on the 2026 Minimum Elements for a Software Bill of Materials (SBOM). An SBOM is essentially a list of ingredients for software — it details the components, libraries, and dependencies that make up an application, similar to how a food label lists ingredients in a product.

This matters because modern software rarely comes from a single source. Applications are often built using many third-party and open-source components, and vulnerabilities in any one of these can expose the entire system. Having a clear SBOM allows organisations to quickly identify whether they are affected when a vulnerability is discovered in a widely used component, rather than scrambling to figure out what software they even have installed.

While SBOMs have traditionally been associated with software vendors and large enterprises, small and medium businesses are increasingly affected by supply chain risks too, particularly when relying on third-party software providers, IT contractors, or cloud services. Understanding what's inside the software you use — and asking vendors for this information — is becoming an important part of managing cyber risk.

SBOM supply chain security software transparency
Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from ACSC. We link back to every original so you can read it yourself.