HBOM procurement requirements for hardware suppliers
Most of what an HBOM needs is known only to the supplier. Procurement is where you ask for it, in a form you can check, with obligations that last beyond delivery.
- Specify CycloneDX or SPDX, the required fields and the nesting depth, not just “provide an HBOM”.
- Combine CERT-In’s minimum elements with CISA taxonomy fields selected for your use cases.
- Require firmware versions, hashes and signing algorithms, with post-quantum plans where CNSA 2.0 applies.
- Include authorised-source, restricted-entity, advisory and end-of-life notice obligations.
Why procurement is the control point
Operational tools can see models, serials and firmware versions, but not which factory made a sub-component or which alternate sources a supplier uses. The CISA HBOM Framework exists to let “vendors and purchasers … communicate about hardware components” [1], and CERT-In’s Version 2.0 guidelines give a baseline element list [2]. Contract clauses turn both into obligations.
Requirement areas
| Area | What to require | Reference |
|---|---|---|
| Format | Machine-readable HBOM in CycloneDX (device/firmware types) or SPDX, schema-valid | [3] |
| Minimum fields | All CERT-In Table 11 elements per component | [2] |
| Provenance fields | Manufacturer, supplier and location fields from the CISA taxonomy, selected by use case | [4] |
| Depth | Agreed nesting level (e.g. to replaceable module, or to component for critical items) | [4] |
| Firmware | Firmware name, version, provider, hashes; firmware SBOM where available | [3] |
| Signing | Firmware signing algorithm and roadmap to quantum-resistant signing where CNSA 2.0 applies | [5] |
| Firmware resiliency | Description of protection, detection and recovery mechanisms | [6] |
| Authorised sources | Parts from original manufacturers or authorised suppliers; counterfeit reporting | [7] |
| Restricted entities | Declaration of no covered or non-trusted components under applicable rules | [8][9] |
| Vulnerabilities | Advisories in CSAF; VEX statements for hardware and firmware issues | [10] |
| Lifecycle | Release, end-of-sale and end-of-support dates; minimum notice before EOL | [2] |
| Updates | Updated HBOM on hardware revision, component substitution or firmware release |
Drafting the clauses
Delivery
“The Supplier shall deliver, with each product model and hardware revision, a Hardware Bill of Materials in CycloneDX (version 1.6 or later) or SPDX (version 3.0 or later) format, valid against the published schema, containing at minimum the elements in Annex A for every component to the depth specified in Annex B.” Annex A combines the CERT-In elements with the CISA fields you need.
Maintenance
“The Supplier shall provide an updated HBOM within an agreed period of any component substitution, hardware revision or firmware release, and shall notify the Purchaser of any change in manufacturer or manufacturing location for components designated critical.”
Vulnerabilities and lifecycle
“The Supplier shall publish security advisories affecting delivered products in a machine-readable format, provide exploitability status per affected model and firmware version, and give written notice of end of sale and end of support no less than an agreed period in advance.”
These are illustrations to adapt with legal counsel, not model contract terms.
Sector-specific additions
- Telecom (India): confirmation that products are designated trusted products where the licensee’s obligations apply [9].
- Cryptographic hardware: validation references and expiry, noting the FIPS 140-2 acceptance end date of 21 September 2026 [11].
- Banking (India): end-of-support and AMC dates to support RBI’s monitoring requirement [12].
Confidentiality and phasing
Suppliers may regard sub-component sourcing as commercially sensitive. Common compromises are to limit full disclosure to components designated critical, to accept supplier attestations for the rest, and to protect the HBOM itself under the contract’s confidentiality terms. For existing contracts, a phased plan can start with firmware versions and lifecycle dates, which suppliers usually hold already, before moving to provenance fields at renewal.
Evaluating responses
In tenders, score HBOM capability rather than treating it as pass or fail: format and schema validity, completeness against the field policy, depth, firmware detail and the supplier’s update process. Ask for a sample HBOM for one product during evaluation and validate it before award.
Checking what you receive
Validate every supplier HBOM on receipt: schema, required fields and consistency with delivered units. See How to validate an HBOM. Suppliers who cannot yet provide full HBOMs can be given a phased plan, with critical components first.
How IntelliXBOM helps
IntelliXBOM ingests supplier HBOMs in CycloneDX and SPDX, validates them against the field policy in your contract annex and keeps each delivery as a version. It correlates supplier data with vulnerabilities, EOL dates and business services, and records the result as evidence.
This article summarises public guidance and is not legal advice.
Frequently asked questions
What should an HBOM clause in a hardware contract include?
At minimum: the format and version, the required fields and nesting depth, firmware details, update obligations when components or firmware change, vulnerability disclosure, and end-of-life notice. Sector rules may add sourcing or validation requirements.
Can suppliers refuse to disclose sub-component sources?
Some treat sourcing as commercially sensitive. Options include restricting disclosure to critical components, accepting attestations for less critical items, and agreeing confidentiality terms for the HBOM itself.
Should HBOM requirements reference the CISA framework or CERT-In?
Both can be useful. CERT-In’s Table 11 provides a compact minimum element list, while the CISA taxonomy offers provenance and sourcing fields to choose from according to use case.
Sources
- CISA Releases Hardware Bill of Materials Framework (HBOM) for Supply Chain Risk ManagementCISAwww.cisa.gov/news-events/news/cisa-releases-hardware-bill-materials-framework-hbom-supply-chain-risk-management-scrm
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- CycloneDX v1.6 JSON ReferenceOWASP CycloneDXcyclonedx.org/docs/1.6/json/
- A Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management (September 2023)CISA ICT SCRM Task Forcewww.cisa.gov/sites/default/files/2023-09/A%20Hardware%20Bill%20of%20Materials%20Framework%20for%20Supply%20Chain%20Risk%20Management%20(508).pdf
- Announcing the Commercial National Security Algorithm Suite 2.0NSA Cybersecurity Advisorymedia.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
- SP 800-193, Platform Firmware Resiliency Guidelines (May 2018)NISTcsrc.nist.gov/pubs/sp/800/193/final
- DFARS 252.246-7007, Contractor Counterfeit Electronic Part Detection and Avoidance SystemAcquisition.govwww.acquisition.gov/dfars/252.246-7007-contractor-counterfeit-electronic-part-detection-and-avoidance-system.
- FAR 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or EquipmentAcquisition.govwww.acquisition.gov/far/52.204-25
- DoT Amends the Unified License Agreement for Procurement of Telecommunication EquipmentAZB & Partnerswww.azbpartners.com/bank/dot-amends-the-unified-license-agreement-for-procurement-of-telecommunication-equipment/
- Common Security Advisory Framework (CSAF) Version 2.0OASISdocs.oasis-open.org/csaf/csaf/v2.0/csaf-v2.0.html
- Cryptographic Module Validation ProgramNISTcsrc.nist.gov/projects/cryptographic-module-validation-program
- Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023Reserve Bank of Indiawww.rbi.org.in/Scripts/NotificationUser.aspx?Id=12562&Mode=0
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.