Addition Suggestion
CISA's new proposed minimal sbom elements shows they intend to require SBOMs contain licensing elements. I would recommend adding a 1st or 2nd level Baseline along the lines of:
OSPOS-LE-04.01: When package formats support it, machine-readable licensing metadata (e.g. SPDX Expressions) must be present in package metadata files (e.g. pom.xml, package.json. setup.py).