← Back to services

SBOM-MIN-ELEMENTS

SBOM minimum-elements check

Bounded checklist of CISA 2026 SBOM minimum elements for one named software unit. Named gaps, not a compliance certificate.

What is claimed

This review packages a checklist of CISA 2026 SBOM minimum elements for one named software unit: present, partial, missing, or unknown fields with named gaps. It is not a compliance certificate and not a vulnerability assessment.

What you receive

  • SBOM artifact in scope
  • generation context
  • CISA 2026 minimum-elements checklist
  • named gaps
  • evidence manifest
  • report or package summary

How to inspect the result

Inspect the SBOM artifact, generation context, checklist, evidence manifest, and sample-scoped receipt where produced. Structural package checks do not prove supplier honesty or exploitability.

Boundaries

  • not cisa certification
  • not vulnerability assessment
  • not kev absence
  • named software unit only

Not included

  • CISA or federal compliance certification
  • vulnerability-free software claim
  • KEV absence
  • full AI-SBOM or multi-tenant SaaS coverage
  • live customer SBOM authenticity by default

Start a review

Primary route: /review/request

Fallback contact: engage@mail.witnessops.com

Do not send passwords, private keys, API keys, recovery codes, session tokens or other secrets.

SBOM minimum-elements check | WitnessOps