EO 14412 (June 22, 2026) is the first US federal document to name CBOM: CISA and NIST must publish minimum-elements guidance within 270 days (~March 2027), with federal PQC deadlines behind it (key establishment by end-2030, signatures by end-2031, FAR rules proposed for contractors). PCI DSS 12.3.3 is the already-mandatory commercial driver (cipher-suite and protocol inventory, since 2025-03-31).
Write the "NTIA moment for CBOM" post: what the EO says, what minimum elements will likely contain, how sbomify handles CBOMs today. When the guidance lands, a minimum-elements assessment plugin becomes the product follow-up.
Acceptance:
EO 14412 (June 22, 2026) is the first US federal document to name CBOM: CISA and NIST must publish minimum-elements guidance within 270 days (~March 2027), with federal PQC deadlines behind it (key establishment by end-2030, signatures by end-2031, FAR rules proposed for contractors). PCI DSS 12.3.3 is the already-mandatory commercial driver (cipher-suite and protocol inventory, since 2025-03-31).
Write the "NTIA moment for CBOM" post: what the EO says, what minimum elements will likely contain, how sbomify handles CBOMs today. When the guidance lands, a minimum-elements assessment plugin becomes the product follow-up.
Acceptance: