PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 20267 sources

HBOM for banks and financial services: HSMs, ATMs and network infrastructure

Banks run some of the most security-critical hardware in any sector: HSMs that hold payment keys, ATMs in public places and dense network estates. An HBOM ties each to its firmware, validation status and support dates.

Key takeaways
  • RBI’s IT governance directions expect regulated entities to monitor end-of-support and AMC dates and plan technology refresh.
  • HSMs carry validations tied to specific hardware and firmware versions, such as FIPS 140 certificates and PCI PTS HSM approvals.
  • FIPS 140-2 certificates can be accepted by US and Canadian federal agencies only through 21 September 2026.
  • ATMs, branch devices and network gear need firmware-level inventory for advisory response.

Why hardware matters in banking

Financial services depend on hardware that is both high-value and long-lived. HSMs protect PINs, card keys and signing keys. ATMs and branch devices operate in exposed locations for many years. Data-centre and network equipment carries payment and trading traffic. Each has firmware that must be kept current, and many carry certifications that apply only to particular versions.

Regulatory expectations in India

The Reserve Bank of India’s Information Technology Governance, Risk, Controls and Assurance Practices Directions, issued 7 November 2023 and effective 1 April 2024, state that regulated entities “shall avoid using outdated and unsupported hardware or software and shall monitor software’s end-of-support (EOS) date and Annual Maintenance Contract (AMC) dates of IT hardware on an ongoing basis”, and should maintain a technology refresh plan for replacement before EOS [1]. The directions define information assets to include hardware [1]. For SEBI-regulated entities, the Cybersecurity and Cyber Resilience Framework issued in August 2024 sets the broader cyber-resilience baseline [2]. CERT-In’s Version 2.0 guidelines add minimum HBOM elements, including EOL date and patch status [3].

Hardware security modules

HSMs are the clearest HBOM use case in banking. The PCI Security Standards Council’s PTS HSM standard covers the “characteristics and management of hardware security modules throughout their lifecycle”, and the Council maintains a listing of approved devices [4]. For cryptographic module validation, NIST’s CMVP has validated modules to FIPS 140-3 since 22 September 2020, and states that FIPS 140-2 certificates can be accepted by federal agencies only through 21 September 2026, after which they move to historical status [5]. Because approvals and validations apply to specific hardware and firmware versions, an HBOM entry per HSM should record:

  • Model, hardware revision, serial number and firmware version
  • Validation or approval reference, version of the standard and expiry
  • Location, owner and the business services that depend on it
  • Supported algorithms and key types, linked to a CBOM

ATMs and branch devices

ATMs combine a PC platform, dispensers, card readers, encrypting PIN pads and network equipment, each with firmware. Vendors publish advisories against specific models and firmware versions, so matching requires the same granularity in the inventory. Long service lives make EOL tracking particularly important: an ATM platform can outlive its vendor’s firmware support.

Network and data-centre hardware

Routers, switches, firewalls and servers are inventoried more often, but usually at device level only. Adding firmware versions from management interfaces such as Redfish [6] and correlating them with advisories and CISA’s KEV catalogue [7] turns the asset list into an HBOM that supports vulnerability response.

Cloud and outsourced hardware

Where HSMs, payment switches or core systems run in a service provider’s data centre, the hardware is still part of the bank’s risk. RBI’s directions expect vendor risk assessment and controls proportionate to materiality [1]. Ask providers for model, firmware and validation data for the hardware that serves you, and record it in the HBOM with the provider as supplier.

A practical sequence

  1. Inventory HSMs first, with validation status and expiry.
  2. Add core network and payment-processing servers, with firmware versions.
  3. Bring ATMs and branch estates in by model and firmware family.
  4. Link each device to the business services it supports, and track EOS and AMC dates as RBI expects.
  5. Record which HSMs and signing devices can support post-quantum algorithms, using the CNSA 2.0 timeline as a reference.

How IntelliXBOM helps

IntelliXBOM records HSMs, ATMs, network and server hardware with their firmware in CycloneDX or SPDX HBOMs, correlates them with vulnerabilities, known-exploited lists and EOL dates, and links each to the business services it supports. It maps the inventory to controls in frameworks such as RBI’s directions and produces timestamped evidence, deployable on-premise or air-gapped.

Frequently asked questions

Does RBI require an HBOM?

RBI’s IT governance directions do not use the term HBOM, but they require regulated entities to avoid unsupported hardware, monitor end-of-support and AMC dates, and plan technology refresh. A hardware inventory with lifecycle data is the natural way to evidence this.

Why do HSMs need special attention in an HBOM?

HSMs hold critical keys and carry validations and approvals that apply to specific hardware and firmware versions. Tracking those versions and expiry dates, including the FIPS 140-2 sunset on 21 September 2026, avoids running unapproved configurations.

Should ATMs be included in an HBOM programme?

Yes, at least by model and firmware version. ATMs have long service lives and multiple firmware-bearing components, and vendor advisories are issued against specific versions.

Sources

  1. Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023Reserve Bank of Indiawww.rbi.org.in/Scripts/NotificationUser.aspx?Id=12562&Mode=0
  2. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
  3. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  4. PTS Hardware Security Module (HSM) StandardPCI Security Standards Councilwww.pcisecuritystandards.org/standards/pts-hardware-security-module-hsm/
  5. Cryptographic Module Validation ProgramNISTcsrc.nist.gov/projects/cryptographic-module-validation-program
  6. DSP2062, Redfish Firmware Update White PaperDMTFwww.dmtf.org/sites/default/files/standards/documents/DSP2062_1.0.0.pdf
  7. Known Exploited Vulnerabilities CatalogCISAwww.cisa.gov/known-exploited-vulnerabilities-catalog

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related HBOM guides

Across the BOM Suite

Put your HBOM under governance.Hardware & firmware trust with continuous correlation and timestamped evidence.