Key insight : CISA's update requires vendors to list every component in software, including borrowed code buried several layers down. : CISA's update requires vendors to list every component in software, including borrowed code buried several layers down. Forward look: The new elements will show up in the questionnaires banks send vendors before they show up in contracts, according to Cornerstone Advisors. A software bill of materials, usually called an SBOM, is essentially a highly detailed nutrition label for software; it inventories the components inside. Vendors resist writing component detail into a contract because ordinary product changes and retirements "can otherwise become contract issues," he said.