HBOM for Indian enterprises
CERT-In names the HBOM in national guidance and lists its minimum elements. For enterprises, the question is how those elements fit alongside sector regulators and telecom rules.
- CERT-In’s Version 2.0 guidelines (9 July 2025) define minimum HBOM elements for government, public sector and essential services organisations.
- RBI-regulated entities must monitor end-of-support and AMC dates for IT hardware.
- Telecom licensees must use trusted products from trusted sources, a regime in force since 15 June 2021.
- The Telecom Cyber Security Rules, 2024 require telecom entities to report security incidents within six hours.
The Indian context
Indian enterprises face HBOM-relevant expectations from several directions: CERT-In as the national CERT, sector regulators such as RBI and SEBI, and the Department of Telecommunications for network equipment. None of these creates a single “HBOM law”, but together they make hardware and firmware inventory a routine compliance input.
CERT-In Version 2.0
CERT-In’s Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0, dated 9 July 2025, extend its SBOM guidance to hardware [1]. The minimum HBOM elements are component name, version, supplier, licence, dependencies, hardware vulnerabilities, patch status, release date, EOL date, criticality, checksums or hashes and unique identifier [1]. Legal commentary highlights that the HBOM seeks “greater transparency in the sourcing and maintenance of hardware components” and extends to embedded software and firmware dependencies [2]. The guidelines are addressed to government, public sector, essential services and software export organisations; private enterprises that supply them, or that are designated as essential, should expect the fields to appear in contracts. See CERT-In HBOM requirements.
Sector regulators
RBI’s IT governance directions (effective 1 April 2024) require regulated entities to avoid outdated and unsupported hardware, to monitor end-of-support and AMC dates of IT hardware on an ongoing basis, and to keep a technology refresh plan [3]. SEBI’s Cybersecurity and Cyber Resilience Framework (August 2024) sets the cyber-resilience baseline for SEBI-regulated entities [4]. Neither prescribes an HBOM format, but both need the lifecycle and inventory data an HBOM holds. Banks and financial institutions should also read HBOM for banks.
Telecom equipment
DoT’s licence amendment of 10 March 2021, effective 15 June 2021, requires licensees to connect only trusted products, with the National Cyber Security Coordinator as the designated authority; upgrades using non-designated equipment need permission [5]. DoT’s letters to licensees describe the Trusted Telecom Portal becoming operational on 15 June 2021 [6]. The Telecommunications (Telecom Cyber Security) Rules, 2024, notified on 21 November 2024, add obligations including reporting security incidents within six hours and registering IMEI numbers before first sale for relevant equipment [7]. Enterprises that are not licensees are not directly bound, but operators may ask them for product information when connecting customer equipment.
What this means in practice
| Enterprise type | Main drivers | HBOM priority |
|---|---|---|
| Government supplier or essential service | CERT-In guidelines, procurement clauses | Table 11 completeness for delivered hardware |
| Bank, NBFC or payment entity | RBI directions, CERT-In | EOS/AMC tracking; HSM and network firmware |
| Market intermediary | SEBI CSCRF, CERT-In | Critical system inventory and lifecycle |
| Telecom licensee | DoT trusted sources, Telecom Cyber Security Rules | Product and supplier identity per network element |
| Hardware exporter or OEM | Customer and export-market requirements | Supplier HBOMs in CycloneDX or SPDX |
Firmware and imported equipment
Much enterprise hardware in India is imported, and its firmware is maintained by overseas vendors. Recording firmware provider and version per device, and integrating vendor bulletins with CERT-In advisories, lets security teams act on hardware advisories without waiting for a vendor to identify affected customers.
A starting plan
- Map which of these drivers apply to each business unit.
- Adopt the CERT-In HBOM elements as the baseline field policy, adding sector-specific dates such as AMC expiry.
- Inventory critical infrastructure first, with firmware versions and EOL dates.
- Add HBOM clauses to procurement templates.
- Integrate CERT-In advisories and vendor bulletins into vulnerability management for hardware and firmware.
How IntelliXBOM helps
IntelliXBOM validates HBOMs in CycloneDX and SPDX against the CERT-In elements, tracks EOL and patch status, and correlates hardware and firmware with vulnerabilities and business services. It maps the inventory to frameworks such as CERT-In’s guidelines and RBI’s directions as timestamped evidence, deployable on-premise or air-gapped.
This article summarises public guidance and is not legal advice.
Frequently asked questions
Are CERT-In HBOM guidelines mandatory for private companies?
The guidelines are addressed to government, public sector, essential services and software export organisations. Private companies are most likely to meet them as contract requirements from those organisations, or through sector regulators.
Which Indian rules affect telecom equipment sourcing?
DoT licence amendments effective 15 June 2021 require licensees to connect only trusted products designated by the National Cyber Security Coordinator. The Telecom Cyber Security Rules, 2024 add further security obligations for telecom entities.
What HBOM data do RBI-regulated entities need?
At a minimum, a hardware inventory with end-of-support and AMC dates, so that unsupported hardware can be identified and replaced under a technology refresh plan, as RBI’s IT governance directions require.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- CERT-In’s New BOM Guidelines: What India’s Software, AI, and Hardware Ecosystem Needs to KnowAZB & Partnerswww.azbpartners.com/bank/cert-ins-new-bom-guidelines-what-indias-software-ai-and-hardware-ecosystem-needs-to-know/
- Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023Reserve Bank of Indiawww.rbi.org.in/Scripts/NotificationUser.aspx?Id=12562&Mode=0
- Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
- DoT Amends the Unified License Agreement for Procurement of Telecommunication EquipmentAZB & Partnerswww.azbpartners.com/bank/dot-amends-the-unified-license-agreement-for-procurement-of-telecommunication-equipment/
- Compliance to amendments in licence conditions on trusted sources (letters of 6 April and 18 June 2021)Department of Telecommunications, Government of Indiawww.dot.gov.in/static/uploads/2026/05/049c3a3a757931398eb38cd98df80552.pdf
- Government notifies Telecommunications (Telecom Cyber Security) Rules, 2024S.S. Rana & Co.ssrana.in/articles/governments-notifies-telecommunications-cyber-security-rules-2024/
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.