HBOM · Hardware & firmware trust
Hardware and firmware visibility you can evidence
Build, validate and maintain Hardware Bills of Materials for servers, network equipment, HSMs and devices, linked to firmware, vulnerabilities, lifecycle dates and business services.
- Devicerack-db-07
- Board2U server · dual socket
- FirmwareBMC 2.61
- ComponentTPM 2.0 module
- AdvisoryVendor firmware advisory
- LifecycleEnd of support
Why HBOM
Hardware Bill of Materials
Most supply-chain tooling stops at the operating system, yet firmware, controllers and components beneath it can undermine every control above. CISA’s 2023 HBOM Framework and CERT-In’s Version 2.0 guidelines give organisations a shared vocabulary for hardware inventory. An HBOM turns that vocabulary into a record of what is deployed, where it came from and how long it will be supported.
What HBOM tracks
Capabilities
What IntelliXBOM does with your HBOM.
One governed inventory, correlated with the rest of your BOMs, the risks they carry and the controls they support.
Supplier and operational HBOMs
Ingest supplier-declared HBOMs and collected device data in CycloneDX or SPDX, and keep both views side by side.
Device and firmware modelling
Represent boards, modules and controllers as device components with their firmware nested beneath, linked to firmware SBOMs.
Field-level validation
Validate each component against required-field policies such as the CERT-In HBOM minimum elements, with gaps reported per component.
Advisory and vulnerability correlation
Match hardware and firmware versions to vulnerabilities and known-exploited lists, and record VEX decisions per device.
Lifecycle and EOL tracking
Track release, end-of-sale and end-of-support dates so replacements are planned before support ends.
Evidence and version history
Keep every HBOM version with diffs, and map hardware inventory to framework controls as timestamped evidence.
How it works
From collection to evidence.
The same five-step loop runs continuously, so the HBOM never becomes yesterday’s inventory.
- 01Collect
Import supplier HBOMs and device data from sources such as Redfish, fwupd or asset systems.
- 02Normalise
Align manufacturers, part numbers, CPE names and firmware versions into CycloneDX or SPDX components.
- 03Validate
Check structure and required fields against your policy and flag gaps per component.
- 04Correlate
Link devices and firmware to vulnerabilities, known-exploited lists, EOL dates and business services.
- 05Evidence
Record versions, diffs and VEX decisions, and export evidence mapped to framework controls.
Use cases
The questions HBOM answers.
Each question resolves to a governed, versioned record, and to the frameworks that record helps provide evidence for.
Which servers run the firmware version named in this vendor advisory?
Correlating firmware components with the advisory lists affected devices and the services they support, so remediation can be prioritised.
Which network devices and HSMs reach end of support in the next 18 months?
Lifecycle dates recorded per component show upcoming end-of-support events early enough to budget and plan replacement.
Does the delivered hardware match what the supplier declared?
Comparing the supplier HBOM with collected device data highlights substituted components or unexpected firmware versions.
Are our supplier HBOMs complete against CERT-In’s minimum elements?
Field-level validation reports which components lack elements such as EOL date, patch status or unique identifier.
HBOM resources
HBOM guides, from fundamentals to procurement.
18 source-cited articles. Open the HBOM resource hub →
Fundamentals
Tools & platforms
Operations
Compliance
Industries
HBOM questions, answered
What is an HBOM?
A Hardware Bill of Materials is a structured inventory of the physical components of a product or system, such as boards, chips, modules and controllers, together with their firmware and relationships. It records supplier, provenance, vulnerability and lifecycle data so hardware risk can be managed like software risk.
What is the CISA HBOM Framework?
Published in September 2023 by CISA’s ICT Supply Chain Risk Management Task Force, it provides use-case categories, a consistent HBOM format and a data field taxonomy for exchanging hardware supply-chain information. Its use cases are grouped into compliance, security and availability, and it is voluntary.
What does CERT-In require in an HBOM?
CERT-In’s Technical Guidelines Version 2.0, dated 9 July 2025, list minimum HBOM elements including component name, version, supplier, licence, dependencies, hardware vulnerabilities, patch status, release and end-of-life dates, criticality, checksums or hashes and a unique identifier.
Which formats support HBOMs?
CycloneDX defines device and firmware component types, and SPDX 3.0 includes device and firmware software purposes. Using the same formats as SBOMs lets hardware, software and cryptographic inventories be linked.
How is an HBOM different from an SBOM?
An SBOM lists software components, while an HBOM lists physical components with manufacturer, part number, location and lifecycle data. Firmware sits in both, and the CISA HBOM Framework treats SBOM information as out of scope, so the two need to be linked deliberately.
Why does firmware signing matter for HBOMs?
Firmware signing keys are built into devices and are hard to change after deployment. NSA’s CNSA 2.0 asks for quantum-resistant software and firmware signing to be preferred by 2025 and used exclusively by 2030, so recording the signing scheme per device shows which hardware can meet that date.
Sources
- A Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management (September 2023)CISA ICT SCRM Task Forcewww.cisa.gov/sites/default/files/2023-09/A%20Hardware%20Bill%20of%20Materials%20Framework%20for%20Supply%20Chain%20Risk%20Management%20(508).pdf
- CISA Releases Hardware Bill of Materials Framework (HBOM) for Supply Chain Risk ManagementCISAwww.cisa.gov/news-events/news/cisa-releases-hardware-bill-materials-framework-hbom-supply-chain-risk-management-scrm
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- CycloneDX v1.6 JSON ReferenceOWASP CycloneDXcyclonedx.org/docs/1.6/json/
- SPDX 3.0.1, SoftwarePurpose vocabularySPDX / Linux Foundationspdx.github.io/spdx-spec/v3.0.1/model/Software/Vocabularies/SoftwarePurpose/
- Hardware Bill of Materials (HBOM)OWASP CycloneDXcyclonedx.org/capabilities/hbom/
- Announcing the Commercial National Security Algorithm Suite 2.0NSA Cybersecurity Advisorymedia.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.
The rest of the BOM Suite