DI-SCRE-82505
Software Bill of Materials (SBOM)
Defines the format, content, and intended use of a Software Bill of Materials (SBOM) that documents software components, supply chain relationships, and cybersecurity-related data for a DoD system or application.
Approval DateDecember 4, 2025
AMSC Number10607
Preparing ActivityRS
Project NumberSCRE-2025-003
OPR—
DTIC Applicable—
GIDEP ApplicableNo
Limitation—
Applicable Forms—
Approval Limitation—
Form Version—
DID Formatfree_text
963C CompliantYes
DISTRIBUTION STATEMENT A: Approved for public release; distribution is unlimited.
Application & Interrelationship
—
Use & Relationship
The Software Bill of Materials (SBOM) provides information that defines the software components for a particular system. The details of the SBOM include Cybersecurity and Integration related data and documents a record of the details and supply chain relationships of the elements that comprise a software baseline for a specific Department of Defense (DoD) product, component, system, or application. The cognizance and knowledge of the key software elements that are installed on any DoD system, equipment or device aids with timely risk analysis, vulnerability management and remediation associated with the instance and/or use of software applications, libraries, source code and executables. The SBOM Data Item Description (DID) references the mission related concerns and their integration within the system's software, firmware and supporting development libraries of source code and executables. Software obsolescence is a part of the DoD Program Manager's Total System Life Cycle Management responsibilities.
A current and accurate SBOM for DoD systems enables System and Manufacturing/Production Engineers, logisticians and software developers the ease of identifying and isolating software components that pose imminent cybersecurity threats, malicious intent or compromised system operations. Potential negative impact to a system's cybersecurity posture can be thwarted with regular SBOM review.
This Data Item Description (DID) contains the format, content, and intended use of information for the data product resulting from the work task described by the contract, where a corresponding SBOM for each program phase is defined.
Preparation Instructions
1FormatField Name, Definition, Notes, Data Type (see Table 1)
2ContentThe SBOM shall contain all information specified below. Fields which do not require data shall be left blank. Below contains a glossary of terms provided for the field content entries followed by the Format in Table 1 and an example in Table 2.
2.1SupplierThis is the name of the supplier or software originator.
2.2Supplier Point of ContactThis is the contact information for the supplier point of contact to include organization, email, and phone number.
2.3Supplier Cage Code(s)This is the CAGE code that has been assigned to the supplier by Defense Logistics Agency (DLA).
2.4Software TypeThis describes whether the software is Commercial Off the Shelf (COTS), Government Off the Shelf (GOTS) or Supplier Proprietary Developed.
2.5Software UseThis describes the software end use within the system such as Application Interface (API), Library, Compiler, Tool, Software as a Service (SaaS), Firmware, or Operating System.
2.6Free and Open SourceThis is a flag to signify whether this software is (FOSS)
2.7Software NameThis is the formal name of the software.
2.8Component/Application IdentifierThis is the equipment component or module that the software resides in.
2.9Unique IdentifiersThis is the software version designator or the logical reference to software build version update.
2.10Dependency relationshipThis specifies the software required for component operation.
2.11HashThis is the hash value.
2.12Hash FunctionThis is the hash function with specificity.
2.13Previous SW VersionThis is the software transition/build-up to arrive at this version.
2.14Licensing RestrictionsThis identifies if there are any restrictions levied on the license. The specific restrictions are not included.
2.15Licensing ExpirationThis is the expiration date for the license.
2.16Uniformity implementationThis is the description of how the software is uniformly applied and date when implemented.
2.17SBOM Product Owner / CustodianThis is the contact information for the authority for the software product.
2.18Date stampThis is the date for the SBOM at the time of program phase delivery.
2.19Program PhaseThis is the program phase for which this SBOM applies based on DoD Acquisition Pathways.
3Media RequirementThe SBOM shall be in an electronic format that supports auto generation and machine readability, and it is based on formats such as SPDX and CycloneDX.
4Other considerationsthis Data Item Description formally documents the actively maintained software and enables the awareness of currently supported software applications.
Figures

Figure Table 1. Table 1: Field Definitions and Instructions

Figure Table 2. Table 2. Sample Field Entries
Schema v3.0Community-maintained · Verify against ASSIST