{"id":16304,"date":"2026-05-14T07:01:33","date_gmt":"2026-05-14T14:01:33","guid":{"rendered":"https:\/\/mattfife.com\/?p=16304"},"modified":"2026-04-26T07:11:00","modified_gmt":"2026-04-26T14:11:00","slug":"federal-agencies-will-no-longer-require-sboms","status":"publish","type":"post","link":"https:\/\/mattfife.com\/?p=16304","title":{"rendered":"Federal agencies will no longer require SBOMs"},"content":{"rendered":"\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/trump-administration-rescinds-biden-era-sbom-guidance\" data-type=\"link\" data-id=\"https:\/\/www.darkreading.com\/application-security\/trump-administration-rescinds-biden-era-sbom-guidance\">Federal agencies will no longer be required to solicit software attestations<\/a> that they comply with NIST&#8217;s <a href=\"https:\/\/csrc.nist.gov\/projects\/ssdf\" data-type=\"link\" data-id=\"https:\/\/csrc.nist.gov\/projects\/ssdf\">Secure Software Development Framework (SSDF)<\/a>.<\/p>\n\n\n\n<p>The SBOM requirement has lead to a small cottage industry of scanning and CI tools that provide this functionality. It will be interesting to see how that all develops, but constantly changing industry standards and practices is not good for businesses. <\/p>\n\n\n\n<p>The US used to thoughtfully and carefully roll out changes like this in the past. In our increasingly polarized political climate, software companies are increasingly whipsawed back and forth. Adding and removing requirements like this is not a zero-cost change. Compliance burdens cost money, time, and credibility to any company based here in the US.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Federal agencies will no longer be required to solicit software attestations that they comply with NIST&#8217;s Secure Software Development Framework (SSDF). The SBOM requirement has lead to a small cottage industry of scanning and CI tools that provide this functionality. It will be interesting to see how that all develops, but constantly changing industry standards and practices is not good for businesses. The US used to thoughtfully and carefully roll out changes like this in the past. In our increasingly&#8230;<\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"https:\/\/mattfife.com\/?p=16304\"> Read More<span class=\"screen-reader-text\">  Read More<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[9,5],"tags":[],"class_list":["post-16304","post","type-post","status-publish","format-standard","hentry","category-cool","category-technical"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p4WECr-4eY","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/posts\/16304","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/mattfife.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16304"}],"version-history":[{"count":3,"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/posts\/16304\/revisions"}],"predecessor-version":[{"id":16307,"href":"https:\/\/mattfife.com\/index.php?rest_route=\/wp\/v2\/posts\/16304\/revisions\/16307"}],"wp:attachment":[{"href":"https:\/\/mattfife.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16304"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mattfife.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16304"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mattfife.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16304"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}