← Back to advisories & guidance
September 3, 2025
NSA
Advisory
Co-sealed by: ANSSI, ASD/ACSC, BSI, CCCS, CISA, CSA, NCO, NCSC-NL, NCSC-NZ, NIS, NSA, NUKIB
Summary
The authoring organizations aim to further inform producers, choosers (i.e., procuring organizations), and operators of software about the advantages of integrating SBOM generation, analysis, and sharing into security processes and practices. Widespread adoption of SBOM will strengthen security, reduce risk, and Most modern software is comprised of software components, modules, and libraries from open source and proprietary software worlds, rather than developers creating it from scratch. As concerns about the security and provenance of software grow, it is critical to understand the risks in the software’s supply chain— including the risks of the underlying software components. The first step to addressing these risks is to increase transparency. This is especially important for software in critical infrastructure and systems that carry out essential functions that affect public safety. 1 Hereafter referred to as the authoring organizations. CISA | NSA | ASD’s ACSC | Cyber Centre | NÚKIB | ANSSI | BSI | CERT-IN | ACN METI | NCO | NCSC-NL | NCSC-NZ | NASK | CSA | NBÚ | NIS/NCSC | KISA Software component and supply chain transparency are fundamental for a more secure software ecosystem, as identified in the international Secure by Design efforts.
News Coverage
No coverage found in monitored research blogs or news feeds.
CVEs Referenced in This Publication
No CVEs are referenced in this publication.
Vendors Named in This Publication
Each vendor links to its Known Exploited Vulnerabilities catalog page.
Only vendors that appear in the KEV catalog are listed, either because
the publication cites one of their KEV entries or because it names them
directly.