Hardware supply-chain risks: counterfeits, tampering and firmware vulnerabilities
Hardware risk is not one problem but several, each with different causes and controls. An HBOM does not remove any of them, but it is the record that makes them measurable.
- NIST SP 800-161 Rev. 1 names malicious functionality, counterfeits and poor manufacturing practices as core supply-chain concerns.
- Firmware vulnerabilities such as the BlackLotus bootkit operate beneath OS security controls.
- Restricted-source rules, such as FAR 52.204-25 and India’s telecom trusted-source conditions, require knowing who made what.
- The CISA HBOM Framework adds availability, meaning single points of failure and supply clustering, to the risk picture.
The risk landscape
NIST SP 800-161 Rev. 1 describes the problem as reduced visibility into how technology is developed and delivered, with products that may contain “malicious functionality, are counterfeit, or are vulnerable due to poor manufacturing and development practices” [1]. CISA’s HBOM Framework organises the purchaser’s view into compliance, security and availability use cases [2]. Combining the two gives six practical risk classes.
| Risk | What goes wrong | HBOM data that helps |
|---|---|---|
| Counterfeit parts | Non-genuine or recycled parts enter the product | Manufacturer and supplier part numbers, date codes, authorised-source records |
| Tampering and malicious functionality | Components or firmware modified in the supply chain | Expected firmware versions and hashes; supplier and location data |
| Firmware vulnerabilities | Exploitable flaws below the OS | Firmware name, version and provider per device |
| Restricted or untrusted sources | Components from entities you may not use | Entity names and locations at every level |
| Availability | Disruption at a single factory or region | Main and alternate manufacturers, locations, lead times |
| Obsolescence | Components out of support and unpatched | Release, EOL and patch status |
Counterfeit parts
Counterfeits are hard to detect once installed, so controls focus on sourcing. US defence procurement sets a clear model: DFARS 252.246-7007 requires contractors to operate risk-based processes that track electronic parts from the original manufacturer to acceptance, to buy from authorised suppliers, and to report counterfeit and suspect counterfeit parts to the contracting officer and the Government-Industry Data Exchange Program [3]. Organisations outside defence can adopt proportionate versions of the same controls for critical assets.
Tampering and malicious functionality
Tampering can target hardware or firmware at any point between factory and rack. The practical defences are knowing what should be present and checking it. NIST SP 800-193 frames firmware resiliency as protection against unauthorised changes, detection of changes that occur, and rapid, secure recovery [4]. An HBOM with expected firmware versions and hashes provides the baseline for detection.
Firmware vulnerabilities
Firmware flaws are attractive because they sit beneath operating system defences. BlackLotus, a UEFI bootkit, used CVE-2022-21894 to bypass Secure Boot and, running before the OS, could interfere with BitLocker, HVCI and Microsoft Defender Antivirus [5]. Responding to such issues requires knowing which devices run which firmware, then correlating that with advisories and CISA’s Known Exploited Vulnerabilities catalogue [6]. See Firmware BOMs.
Restricted and untrusted sources
Some rules prohibit specific sources. FAR 52.204-25, implementing Section 889 of the FY2019 NDAA, prohibits US federal procurement of covered telecommunications and video surveillance equipment from named producers when used as a substantial or essential component of any system [7]. In India, telecom licensees must connect only trusted products, as designated under licence amendments effective 15 June 2021 [8]. Both require knowing who manufactured the components, not just who sold the finished product.
Availability and obsolescence
The CISA framework’s availability category covers world events, single points of failure and supply-chain clustering, with factory shutdowns during COVID-19 given as an example [2]. Location and alternate-source fields let purchasers see where several products depend on one facility. Obsolescence is quieter but common: components past end of support stop receiving firmware fixes. Tracking EOL dates is covered in HBOM management.
Prioritising
- Start with assets whose compromise would disable other controls: management controllers, network cores, HSMs, hypervisor hosts.
- Apply sourcing and provenance controls at procurement, where they cost least.
- Automate firmware inventory and advisory correlation across the estate.
- Reserve physical inspection and deep firmware analysis for the highest-risk supply routes.
How IntelliXBOM helps
IntelliXBOM records hardware, firmware, supplier and lifecycle data in CycloneDX or SPDX HBOMs and correlates them with vulnerabilities, known-exploited lists and EOL dates. It links devices to the business services they support, so hardware risks can be prioritised by impact, and maps the result to framework controls.
Frequently asked questions
What is the biggest hardware supply-chain risk?
It depends on the organisation. For most, unpatched firmware and end-of-support hardware are the most frequent issues, while counterfeits and tampering are less frequent but harder to detect. Restricted-source rules make provenance a compliance risk as well.
Can an HBOM detect tampering?
Not by itself. An HBOM records what should be present, such as firmware versions and hashes, which provides the baseline. Detection comes from comparing that baseline with what devices actually report and from integrity checks.
Where can I find guidance on hardware supply-chain risk?
NIST SP 800-161 Rev. 1 covers cybersecurity supply chain risk management broadly, NIST SP 800-193 covers platform firmware resiliency, and the CISA HBOM Framework provides a structure for exchanging hardware supply-chain data.
Sources
- SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and OrganizationsNISTcsrc.nist.gov/pubs/sp/800/161/r1/upd1/final
- A Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management (September 2023)CISA ICT SCRM Task Forcewww.cisa.gov/sites/default/files/2023-09/A%20Hardware%20Bill%20of%20Materials%20Framework%20for%20Supply%20Chain%20Risk%20Management%20(508).pdf
- DFARS 252.246-7007, Contractor Counterfeit Electronic Part Detection and Avoidance SystemAcquisition.govwww.acquisition.gov/dfars/252.246-7007-contractor-counterfeit-electronic-part-detection-and-avoidance-system.
- SP 800-193, Platform Firmware Resiliency Guidelines (May 2018)NISTcsrc.nist.gov/pubs/sp/800/193/final
- Guidance for investigating attacks using CVE-2022-21894: The BlackLotus campaignMicrosoft Securitywww.microsoft.com/en-us/security/blog/2023/04/11/guidance-for-investigating-attacks-using-cve-2022-21894-the-blacklotus-campaign/
- Known Exploited Vulnerabilities CatalogCISAwww.cisa.gov/known-exploited-vulnerabilities-catalog
- FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or EquipmentAcquisition.govwww.acquisition.gov/far/52.204-25
- DoT Amends the Unified License Agreement for Procurement of Telecommunication EquipmentAZB & Partnerswww.azbpartners.com/bank/dot-amends-the-unified-license-agreement-for-procurement-of-telecommunication-equipment/
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.