CISA has released updated 2026 SBOM guidance, expanding requirements to include AI systems and SaaS while mandating component hashes for better validation. This transition shifts supply chain security responsibilities from simple build pipelines toward robust vendor contract management and ongoing component verification.