PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 20267 sources

HBOM for Indian enterprises

CERT-In names the HBOM in national guidance and lists its minimum elements. For enterprises, the question is how those elements fit alongside sector regulators and telecom rules.

Key takeaways
  • CERT-In’s Version 2.0 guidelines (9 July 2025) define minimum HBOM elements for government, public sector and essential services organisations.
  • RBI-regulated entities must monitor end-of-support and AMC dates for IT hardware.
  • Telecom licensees must use trusted products from trusted sources, a regime in force since 15 June 2021.
  • The Telecom Cyber Security Rules, 2024 require telecom entities to report security incidents within six hours.

The Indian context

Indian enterprises face HBOM-relevant expectations from several directions: CERT-In as the national CERT, sector regulators such as RBI and SEBI, and the Department of Telecommunications for network equipment. None of these creates a single “HBOM law”, but together they make hardware and firmware inventory a routine compliance input.

CERT-In Version 2.0

CERT-In’s Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0, dated 9 July 2025, extend its SBOM guidance to hardware [1]. The minimum HBOM elements are component name, version, supplier, licence, dependencies, hardware vulnerabilities, patch status, release date, EOL date, criticality, checksums or hashes and unique identifier [1]. Legal commentary highlights that the HBOM seeks “greater transparency in the sourcing and maintenance of hardware components” and extends to embedded software and firmware dependencies [2]. The guidelines are addressed to government, public sector, essential services and software export organisations; private enterprises that supply them, or that are designated as essential, should expect the fields to appear in contracts. See CERT-In HBOM requirements.

Sector regulators

RBI’s IT governance directions (effective 1 April 2024) require regulated entities to avoid outdated and unsupported hardware, to monitor end-of-support and AMC dates of IT hardware on an ongoing basis, and to keep a technology refresh plan [3]. SEBI’s Cybersecurity and Cyber Resilience Framework (August 2024) sets the cyber-resilience baseline for SEBI-regulated entities [4]. Neither prescribes an HBOM format, but both need the lifecycle and inventory data an HBOM holds. Banks and financial institutions should also read HBOM for banks.

Telecom equipment

DoT’s licence amendment of 10 March 2021, effective 15 June 2021, requires licensees to connect only trusted products, with the National Cyber Security Coordinator as the designated authority; upgrades using non-designated equipment need permission [5]. DoT’s letters to licensees describe the Trusted Telecom Portal becoming operational on 15 June 2021 [6]. The Telecommunications (Telecom Cyber Security) Rules, 2024, notified on 21 November 2024, add obligations including reporting security incidents within six hours and registering IMEI numbers before first sale for relevant equipment [7]. Enterprises that are not licensees are not directly bound, but operators may ask them for product information when connecting customer equipment.

What this means in practice

Enterprise typeMain driversHBOM priority
Government supplier or essential serviceCERT-In guidelines, procurement clausesTable 11 completeness for delivered hardware
Bank, NBFC or payment entityRBI directions, CERT-InEOS/AMC tracking; HSM and network firmware
Market intermediarySEBI CSCRF, CERT-InCritical system inventory and lifecycle
Telecom licenseeDoT trusted sources, Telecom Cyber Security RulesProduct and supplier identity per network element
Hardware exporter or OEMCustomer and export-market requirementsSupplier HBOMs in CycloneDX or SPDX

Firmware and imported equipment

Much enterprise hardware in India is imported, and its firmware is maintained by overseas vendors. Recording firmware provider and version per device, and integrating vendor bulletins with CERT-In advisories, lets security teams act on hardware advisories without waiting for a vendor to identify affected customers.

A starting plan

  1. Map which of these drivers apply to each business unit.
  2. Adopt the CERT-In HBOM elements as the baseline field policy, adding sector-specific dates such as AMC expiry.
  3. Inventory critical infrastructure first, with firmware versions and EOL dates.
  4. Add HBOM clauses to procurement templates.
  5. Integrate CERT-In advisories and vendor bulletins into vulnerability management for hardware and firmware.

How IntelliXBOM helps

IntelliXBOM validates HBOMs in CycloneDX and SPDX against the CERT-In elements, tracks EOL and patch status, and correlates hardware and firmware with vulnerabilities and business services. It maps the inventory to frameworks such as CERT-In’s guidelines and RBI’s directions as timestamped evidence, deployable on-premise or air-gapped.

This article summarises public guidance and is not legal advice.

Frequently asked questions

Are CERT-In HBOM guidelines mandatory for private companies?

The guidelines are addressed to government, public sector, essential services and software export organisations. Private companies are most likely to meet them as contract requirements from those organisations, or through sector regulators.

Which Indian rules affect telecom equipment sourcing?

DoT licence amendments effective 15 June 2021 require licensees to connect only trusted products designated by the National Cyber Security Coordinator. The Telecom Cyber Security Rules, 2024 add further security obligations for telecom entities.

What HBOM data do RBI-regulated entities need?

At a minimum, a hardware inventory with end-of-support and AMC dates, so that unsupported hardware can be identified and replaced under a technology refresh plan, as RBI’s IT governance directions require.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. CERT-In’s New BOM Guidelines: What India’s Software, AI, and Hardware Ecosystem Needs to KnowAZB & Partnerswww.azbpartners.com/bank/cert-ins-new-bom-guidelines-what-indias-software-ai-and-hardware-ecosystem-needs-to-know/
  3. Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023Reserve Bank of Indiawww.rbi.org.in/Scripts/NotificationUser.aspx?Id=12562&Mode=0
  4. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
  5. DoT Amends the Unified License Agreement for Procurement of Telecommunication EquipmentAZB & Partnerswww.azbpartners.com/bank/dot-amends-the-unified-license-agreement-for-procurement-of-telecommunication-equipment/
  6. Compliance to amendments in licence conditions on trusted sources (letters of 6 April and 18 June 2021)Department of Telecommunications, Government of Indiawww.dot.gov.in/static/uploads/2026/05/049c3a3a757931398eb38cd98df80552.pdf
  7. Government notifies Telecommunications (Telecom Cyber Security) Rules, 2024S.S. Rana & Co.ssrana.in/articles/governments-notifies-telecommunications-cyber-security-rules-2024/

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related HBOM guides

Across the BOM Suite

Put your HBOM under governance.Hardware & firmware trust with continuous correlation and timestamped evidence.