HBOM for government and defence
Public-sector buyers face the strictest hardware rules: restricted suppliers, counterfeit controls and cryptographic mandates. Each depends on knowing exactly what is inside the equipment they buy.
- CERT-In’s Version 2.0 guidelines address government, public sector and essential services organisations.
- US rules such as FAR 52.204-25 and DFARS 252.246-7007 show how restricted-source and counterfeit controls rely on component data.
- CNSA 2.0 requires national security systems to move firmware signing to quantum-resistant algorithms, exclusively by 2030.
- India’s telecom trusted-source regime illustrates designation of trusted products by a national authority.
Why the public sector leads
Government and defence bodies operate long-lived systems, buy at scale through formal procurement and face adversaries interested in the supply chain itself. They also have the leverage to require suppliers to disclose component data. The CISA HBOM Framework’s compliance, security and availability use cases map closely to public-sector concerns [1].
India: CERT-In and trusted sources
CERT-In’s Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025) are addressed to government, public sector and essential services organisations, and set out minimum HBOM elements including supplier, hardware vulnerabilities, patch status, EOL date and unique identifier [2]. In telecoms, DoT’s licence amendments effective 15 June 2021 require licensees to connect only trusted products designated by the National Cyber Security Coordinator [3], administered through the Trusted Telecom Portal [4]. Departments that run their own networks or buy from licensees benefit from recording the same product and supplier identity.
Restricted sources
FAR 52.204-25 implements Section 889 of the FY2019 NDAA, prohibiting US federal procurement of covered telecommunications and video surveillance equipment from named producers used as a substantial or essential component of any system, and requiring contractors to report covered equipment they identify within one business day [5]. Checking this requires entity data at component level: the finished product’s brand is not enough. The CISA framework lists NDAA Section 889 as a compliance use case for this reason [1].
Counterfeit avoidance
DFARS 252.246-7007 requires defence contractors to operate a counterfeit electronic part detection and avoidance system, including traceability from original manufacturer to government acceptance, purchasing from authorised suppliers, flow-down to subcontractors and reporting of suspect counterfeits to GIDEP [6]. Supplier HBOMs with manufacturer part numbers and date codes supply the data these processes use.
Cryptography in firmware
For US national security systems, NSA’s CNSA 2.0 requires software and firmware signing to support and prefer quantum-resistant algorithms by 2025 and use them exclusively by 2030 [7]. LMS and XMSS under NIST SP 800-208 are approved for this purpose [8]. Validated cryptographic modules are also a common requirement; NIST’s CMVP notes that FIPS 140-2 certificates are accepted only through 21 September 2026 [9]. An HBOM that records signing schemes and module validation per device shows where replacement is unavoidable. See the CNSA 2.0 timeline.
Supply-chain risk management
NIST SP 800-161 Rev. 1 provides the overarching cybersecurity supply chain risk management practices for organisations, addressing counterfeit and malicious components and poor manufacturing practices [10]. HBOMs are one of the inputs that make those practices concrete for hardware.
Long-lived systems
Public-sector systems often stay in service far longer than commercial vendor support windows. That makes end-of-life dates, availability of spares and alternate sources, which the CISA framework captures in its production and entity fields [1], as important as vulnerabilities. An HBOM that records main and alternate manufacturers and lead times supports sustainment planning as well as security.
Programme priorities
| Priority | HBOM focus |
|---|---|
| Procurement | Require supplier HBOMs with entity names and locations at component level |
| Restricted sources | Screen entity data against applicable lists before award and on change |
| Firmware | Record firmware versions, signing algorithms and update channels |
| Validation | Record module validations and expiry dates |
| Lifecycle | Plan replacement before end of support |
For contract wording, see HBOM procurement requirements.
How IntelliXBOM helps
IntelliXBOM ingests supplier HBOMs in CycloneDX and SPDX, validates them against required-field policies such as CERT-In’s, and correlates hardware and firmware with vulnerabilities, known-exploited lists and EOL data. It runs self-hosted, including air-gapped, and maps the inventory to framework controls as timestamped evidence.
Frequently asked questions
Do Indian government bodies need HBOMs?
CERT-In’s Version 2.0 guidelines address government, public sector and essential services organisations and set out minimum HBOM elements. Departments should read them alongside their own procurement rules and any sector-specific requirements.
How does an HBOM help with NDAA Section 889?
Section 889, implemented through FAR 52.204-25, concerns covered equipment used as a substantial or essential component of a system. Component-level entity data in an HBOM lets buyers check for covered producers beneath the finished product brand.
Why is air-gapped deployment relevant for defence HBOMs?
Hardware inventories reveal the composition and location of sensitive systems. Many defence environments require such data to remain on isolated networks, so HBOM tooling must work without external connectivity.
Sources
- A Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management (September 2023)CISA ICT SCRM Task Forcewww.cisa.gov/sites/default/files/2023-09/A%20Hardware%20Bill%20of%20Materials%20Framework%20for%20Supply%20Chain%20Risk%20Management%20(508).pdf
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- DoT Amends the Unified License Agreement for Procurement of Telecommunication EquipmentAZB & Partnerswww.azbpartners.com/bank/dot-amends-the-unified-license-agreement-for-procurement-of-telecommunication-equipment/
- Compliance to amendments in licence conditions on trusted sources (letters of 6 April and 18 June 2021)Department of Telecommunications, Government of Indiawww.dot.gov.in/static/uploads/2026/05/049c3a3a757931398eb38cd98df80552.pdf
- FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or EquipmentAcquisition.govwww.acquisition.gov/far/52.204-25
- DFARS 252.246-7007, Contractor Counterfeit Electronic Part Detection and Avoidance SystemAcquisition.govwww.acquisition.gov/dfars/252.246-7007-contractor-counterfeit-electronic-part-detection-and-avoidance-system.
- Announcing the Commercial National Security Algorithm Suite 2.0NSA Cybersecurity Advisorymedia.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
- CNSA 2.0: Complete Guide to NSA’s PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/
- Cryptographic Module Validation ProgramNISTcsrc.nist.gov/projects/cryptographic-module-validation-program
- SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and OrganizationsNISTcsrc.nist.gov/pubs/sp/800/161/r1/upd1/final
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.