PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Compliance4 min readReviewed September 20269 sources

HBOM compliance: the frameworks that call for hardware and firmware inventory

Few rules say “produce an HBOM” in so many words, but many require evidence that only a hardware and firmware inventory can supply. This is a map of the main ones and the HBOM data each depends on.

Key takeaways
  • CERT-In’s Version 2.0 guidelines (9 July 2025) are the most explicit HBOM guidance, with a minimum element list.
  • The CISA HBOM Framework is voluntary but provides a shared vocabulary for suppliers and purchasers.
  • NIST SP 800-161 Rev. 1 and SP 800-193 set supply-chain and firmware resiliency expectations that HBOM data evidences.
  • CNSA 2.0 puts software and firmware signing on its earliest timeline: support and prefer by 2025, exclusive use by 2030.
  • India’s telecom licence conditions have required trusted products from trusted sources since 15 June 2021.

How HBOM obligations arise

HBOM requirements come from three directions: explicit bill-of-materials guidance (CERT-In), supply-chain risk frameworks that ask organisations to know their suppliers and components (CISA, NIST), and rules on specific hardware properties such as sourcing, cryptography and support status. In each case the underlying evidence is the same: an accurate, current record of what hardware and firmware is deployed and where it came from.

Framework map

FrameworkStatusWhat it asks forHBOM data that evidences it
CERT-In Technical Guidelines v2.0 (9 July 2025)Guidance for government, public sector and essential servicesMinimum HBOM elements (Table 11)All Table 11 elements, per component [1]
CISA HBOM Framework (Sept 2023)VoluntaryUse cases, format and taxonomy for supplier–purchaser exchangeSupplier, manufacturer, location and part data [2]
NIST SP 800-161 Rev. 1GuidanceCybersecurity supply chain risk management practicesSupplier and component traceability [3]
NIST SP 800-193 (May 2018)GuidanceProtect, detect and recover platform firmwareFirmware versions, update paths, integrity checks [4]
NSA CNSA 2.0Requirement for US national security systemsQuantum-resistant software and firmware signingSigning algorithm per firmware image [5]
DoT licence amendment (India, effective 15 June 2021)Licence condition for telecom licenseesOnly trusted products from trusted sourcesProduct and supplier identity per network element [6]

CERT-In Version 2.0

CERT-In’s Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 list minimum HBOM elements: component name, version, supplier, licence, dependencies, hardware vulnerabilities, patch status, release date, EOL date, criticality, checksums or hashes, and unique identifier [1]. The guidelines are aimed at government, public sector and essential services organisations and software exporters [1]. See CERT-In HBOM requirements for the field-by-field reading.

CISA HBOM Framework

CISA’s framework states that purchasers and vendors “can use the HBOM Framework on a voluntary basis” and that it is meant to be tailored [2]. Its compliance use-case category explicitly includes government requirements such as NDAA Section 889, which FAR 52.204-25 implements for named telecommunications and video surveillance equipment producers [7]. Covered in depth in The CISA HBOM Framework explained.

NIST SP 800-161 and SP 800-193

SP 800-161 Rev. 1, originally published in May 2022 and updated on 1 November 2024, addresses products that may contain malicious functionality, be counterfeit or be vulnerable due to poor manufacturing practices [3]. SP 800-193, Platform Firmware Resiliency Guidelines, sets out mechanisms for “protecting the platform against unauthorized changes, detecting unauthorized changes that occur, and recovering from attacks rapidly and securely” [4]. Neither prescribes an HBOM format, but both are hard to evidence without knowing which firmware runs on which platform.

CNSA 2.0 firmware signing

NSA’s CNSA 2.0 asks for quantum-resistant software and firmware signing to be supported and preferred by 2025 and used exclusively by 2030, with LMS and XMSS (NIST SP 800-208) approved for this purpose [5][8]. An HBOM that records the signing scheme per firmware image shows which devices can meet that date. The CNSA 2.0 timeline covers the wider schedule.

India: trusted sources for telecom networks

The Department of Telecommunications amended the Unified Licence on 10 March 2021, effective 15 June 2021, so that licensees connect only trusted products in their networks, with the National Cyber Security Coordinator as the designated authority; upgrades using non-designated equipment need permission, while existing maintenance contracts are not affected [6]. DoT’s compliance letters refer to the Trusted Telecom Portal becoming operational on 15 June 2021 under the National Security Directive on Telecommunication Sector [9]. For licensees, a per-element record of product and supplier is the natural evidence.

Practical steps

  1. List which of these frameworks apply to you, and to which estates.
  2. Build a single field policy that is the union of the elements they need.
  3. Validate supplier and operational HBOMs against it continuously.
  4. Keep version history so you can show the state on any given date.

How IntelliXBOM helps

IntelliXBOM validates HBOMs against required-field policies such as CERT-In’s, maps hardware and firmware inventory to framework controls, and produces timestamped evidence. It helps organisations address these frameworks; it does not certify compliance.

This article summarises public guidance and is not legal advice.

Frequently asked questions

Is there a law that requires an HBOM?

No single law requires a document called an HBOM in most jurisdictions. CERT-In’s guidelines set out minimum HBOM elements for its target sectors, and other rules on sourcing, firmware security and support status require evidence an HBOM provides.

Does NIST SP 800-193 require an HBOM?

No. SP 800-193 sets out protection, detection and recovery principles for platform firmware. Knowing which firmware versions run on which platforms, which an HBOM records, is what makes those principles verifiable.

Who must follow India’s telecom trusted-source rules?

The licence amendments apply to telecom licensees such as holders of the Unified Licence, with similar provisions added to other licences. Enterprises that are not licensees are not directly bound, but may be asked by operators for supporting product information.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. A Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management (September 2023)CISA ICT SCRM Task Forcewww.cisa.gov/sites/default/files/2023-09/A%20Hardware%20Bill%20of%20Materials%20Framework%20for%20Supply%20Chain%20Risk%20Management%20(508).pdf
  3. SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and OrganizationsNISTcsrc.nist.gov/pubs/sp/800/161/r1/upd1/final
  4. SP 800-193, Platform Firmware Resiliency Guidelines (May 2018)NISTcsrc.nist.gov/pubs/sp/800/193/final
  5. Announcing the Commercial National Security Algorithm Suite 2.0NSA Cybersecurity Advisorymedia.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
  6. DoT Amends the Unified License Agreement for Procurement of Telecommunication EquipmentAZB & Partnerswww.azbpartners.com/bank/dot-amends-the-unified-license-agreement-for-procurement-of-telecommunication-equipment/
  7. FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or EquipmentAcquisition.govwww.acquisition.gov/far/52.204-25
  8. CNSA 2.0: Complete Guide to NSA’s PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/
  9. Compliance to amendments in licence conditions on trusted sources (letters of 6 April and 18 June 2021)Department of Telecommunications, Government of Indiawww.dot.gov.in/static/uploads/2026/05/049c3a3a757931398eb38cd98df80552.pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related HBOM guides

Across the BOM Suite

Put your HBOM under governance.Hardware & firmware trust with continuous correlation and timestamped evidence.