HBOM compliance: the frameworks that call for hardware and firmware inventory
Few rules say “produce an HBOM” in so many words, but many require evidence that only a hardware and firmware inventory can supply. This is a map of the main ones and the HBOM data each depends on.
- CERT-In’s Version 2.0 guidelines (9 July 2025) are the most explicit HBOM guidance, with a minimum element list.
- The CISA HBOM Framework is voluntary but provides a shared vocabulary for suppliers and purchasers.
- NIST SP 800-161 Rev. 1 and SP 800-193 set supply-chain and firmware resiliency expectations that HBOM data evidences.
- CNSA 2.0 puts software and firmware signing on its earliest timeline: support and prefer by 2025, exclusive use by 2030.
- India’s telecom licence conditions have required trusted products from trusted sources since 15 June 2021.
How HBOM obligations arise
HBOM requirements come from three directions: explicit bill-of-materials guidance (CERT-In), supply-chain risk frameworks that ask organisations to know their suppliers and components (CISA, NIST), and rules on specific hardware properties such as sourcing, cryptography and support status. In each case the underlying evidence is the same: an accurate, current record of what hardware and firmware is deployed and where it came from.
Framework map
| Framework | Status | What it asks for | HBOM data that evidences it |
|---|---|---|---|
| CERT-In Technical Guidelines v2.0 (9 July 2025) | Guidance for government, public sector and essential services | Minimum HBOM elements (Table 11) | All Table 11 elements, per component [1] |
| CISA HBOM Framework (Sept 2023) | Voluntary | Use cases, format and taxonomy for supplier–purchaser exchange | Supplier, manufacturer, location and part data [2] |
| NIST SP 800-161 Rev. 1 | Guidance | Cybersecurity supply chain risk management practices | Supplier and component traceability [3] |
| NIST SP 800-193 (May 2018) | Guidance | Protect, detect and recover platform firmware | Firmware versions, update paths, integrity checks [4] |
| NSA CNSA 2.0 | Requirement for US national security systems | Quantum-resistant software and firmware signing | Signing algorithm per firmware image [5] |
| DoT licence amendment (India, effective 15 June 2021) | Licence condition for telecom licensees | Only trusted products from trusted sources | Product and supplier identity per network element [6] |
CERT-In Version 2.0
CERT-In’s Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 list minimum HBOM elements: component name, version, supplier, licence, dependencies, hardware vulnerabilities, patch status, release date, EOL date, criticality, checksums or hashes, and unique identifier [1]. The guidelines are aimed at government, public sector and essential services organisations and software exporters [1]. See CERT-In HBOM requirements for the field-by-field reading.
CISA HBOM Framework
CISA’s framework states that purchasers and vendors “can use the HBOM Framework on a voluntary basis” and that it is meant to be tailored [2]. Its compliance use-case category explicitly includes government requirements such as NDAA Section 889, which FAR 52.204-25 implements for named telecommunications and video surveillance equipment producers [7]. Covered in depth in The CISA HBOM Framework explained.
NIST SP 800-161 and SP 800-193
SP 800-161 Rev. 1, originally published in May 2022 and updated on 1 November 2024, addresses products that may contain malicious functionality, be counterfeit or be vulnerable due to poor manufacturing practices [3]. SP 800-193, Platform Firmware Resiliency Guidelines, sets out mechanisms for “protecting the platform against unauthorized changes, detecting unauthorized changes that occur, and recovering from attacks rapidly and securely” [4]. Neither prescribes an HBOM format, but both are hard to evidence without knowing which firmware runs on which platform.
CNSA 2.0 firmware signing
NSA’s CNSA 2.0 asks for quantum-resistant software and firmware signing to be supported and preferred by 2025 and used exclusively by 2030, with LMS and XMSS (NIST SP 800-208) approved for this purpose [5][8]. An HBOM that records the signing scheme per firmware image shows which devices can meet that date. The CNSA 2.0 timeline covers the wider schedule.
India: trusted sources for telecom networks
The Department of Telecommunications amended the Unified Licence on 10 March 2021, effective 15 June 2021, so that licensees connect only trusted products in their networks, with the National Cyber Security Coordinator as the designated authority; upgrades using non-designated equipment need permission, while existing maintenance contracts are not affected [6]. DoT’s compliance letters refer to the Trusted Telecom Portal becoming operational on 15 June 2021 under the National Security Directive on Telecommunication Sector [9]. For licensees, a per-element record of product and supplier is the natural evidence.
Practical steps
- List which of these frameworks apply to you, and to which estates.
- Build a single field policy that is the union of the elements they need.
- Validate supplier and operational HBOMs against it continuously.
- Keep version history so you can show the state on any given date.
How IntelliXBOM helps
IntelliXBOM validates HBOMs against required-field policies such as CERT-In’s, maps hardware and firmware inventory to framework controls, and produces timestamped evidence. It helps organisations address these frameworks; it does not certify compliance.
This article summarises public guidance and is not legal advice.
Frequently asked questions
Is there a law that requires an HBOM?
No single law requires a document called an HBOM in most jurisdictions. CERT-In’s guidelines set out minimum HBOM elements for its target sectors, and other rules on sourcing, firmware security and support status require evidence an HBOM provides.
Does NIST SP 800-193 require an HBOM?
No. SP 800-193 sets out protection, detection and recovery principles for platform firmware. Knowing which firmware versions run on which platforms, which an HBOM records, is what makes those principles verifiable.
Who must follow India’s telecom trusted-source rules?
The licence amendments apply to telecom licensees such as holders of the Unified Licence, with similar provisions added to other licences. Enterprises that are not licensees are not directly bound, but may be asked by operators for supporting product information.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- A Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management (September 2023)CISA ICT SCRM Task Forcewww.cisa.gov/sites/default/files/2023-09/A%20Hardware%20Bill%20of%20Materials%20Framework%20for%20Supply%20Chain%20Risk%20Management%20(508).pdf
- SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and OrganizationsNISTcsrc.nist.gov/pubs/sp/800/161/r1/upd1/final
- SP 800-193, Platform Firmware Resiliency Guidelines (May 2018)NISTcsrc.nist.gov/pubs/sp/800/193/final
- Announcing the Commercial National Security Algorithm Suite 2.0NSA Cybersecurity Advisorymedia.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
- DoT Amends the Unified License Agreement for Procurement of Telecommunication EquipmentAZB & Partnerswww.azbpartners.com/bank/dot-amends-the-unified-license-agreement-for-procurement-of-telecommunication-equipment/
- FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or EquipmentAcquisition.govwww.acquisition.gov/far/52.204-25
- CNSA 2.0: Complete Guide to NSA’s PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/
- Compliance to amendments in licence conditions on trusted sources (letters of 6 April and 18 June 2021)Department of Telecommunications, Government of Indiawww.dot.gov.in/static/uploads/2026/05/049c3a3a757931398eb38cd98df80552.pdf
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.