PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 20268 sources

SBOM for banks and financial services: SEBI CSCRF, RBI and CERT-In

Financial institutions run large estates of vendor, in-house and SaaS software under close supervision. This guide explains where SBOM expectations come from in Indian financial services and how to meet them in practice.

Key takeaways
  • SEBI's CSCRF requires SBOMs for all software supporting core and critical business operations, in-house, third-party or SaaS.
  • RBI's IT governance directions do not use the term SBOM, but their vendor and vulnerability expectations are easier to evidence with one.
  • CERT-In's Version 2.0 guidelines provide the field list and VEX process most Indian programmes align to.
  • Where a vendor will not supply an SBOM, SEBI expects board-level approval of the exception with a risk rationale.

Why financial services are in scope

Banks, brokers, depositories, asset managers and payment firms depend on core banking platforms, trading systems, payment switches and SaaS services from a small number of vendors. A vulnerability in one widely used component can affect many institutions at once. Regulators have responded by asking for component-level transparency.

SEBI CSCRF

SEBI's Cybersecurity and Cyber Resilience Framework for regulated entities was issued by circular on 20 August 2024 [1]. SEBI's June 2025 FAQs clarify the SBOM requirement [2]:

  • "SBOM shall be obtained for all the software/applications required for core and critical business operations", including applications in data centres and SaaS.
  • The requirement applies "irrespective of in-house or third-party" development.
  • Where an SBOM cannot be obtained, for example for legacy or proprietary software, "the Board/Partners/Proprietor of the organization shall approve the same with proper limitation, rationale, and risk management approach".

FOSSA's analysis summarises the expected SBOM content as including licence information, supplier name, top-level and transitive components with relationships, encryption used, cryptographic hash, update frequency, known unknowns, access control and accommodation of errors, and notes that SEBI does not mandate a particular format [3]. Banks that are also SEBI-registered intermediaries, for example as depository participants, should check how CSCRF applies to those activities.

RBI

RBI's Information Technology Governance, Risk, Controls and Assurance Practices Directions, 2023 (issued 7 November 2023, effective 1 April 2024) do not use the term SBOM. They do require regulated entities to obtain source code for critical applications from vendors, or put an escrow arrangement in place, and to obtain a certificate or written confirmation from the developer or vendor that the application is free of known vulnerabilities, malware and covert channels [4]. A current SBOM, correlated with vulnerability data, is a practical way to test and evidence such confirmations. KPMG's December 2025 review reports that RBI has advised regulated entities to adopt CERT-In's SBOM guidelines [5].

CERT-In and card payments

CERT-In's Version 2.0 guidelines give the most detailed Indian field list (21 SBOM fields) and recommend VEX and CSAF advisories from suppliers [6]. For card environments, PCI DSS v4.0 requirement 6.3.2 requires an inventory of bespoke and custom software and its third-party components, mandatory from 31 March 2025 [7].

What this means in practice

AreaAction
ScopeList applications supporting core and critical operations, including SaaS and in-house systems
ContractsAdd SBOM, update and VEX clauses to vendor agreements; see procurement requirements
In-houseGenerate SBOMs in CI/CD for every release
IntakeValidate vendor SBOMs against the CERT-In fields and your SEBI checklist
ExceptionsRecord vendors unable to supply SBOMs, with board approval and compensating controls
MonitoringCorrelate SBOMs daily with vulnerabilities and CISA's Known Exploited Vulnerabilities catalogue [8]
EvidenceKeep timestamped SBOM versions, validation results and VEX decisions for auditors

Cryptography and beyond

Financial institutions rely heavily on cryptography for payments, authentication and data protection. The SBOM identifies cryptographic libraries, but migration planning needs a CBOM of algorithms, keys, protocols and certificates. Hardware security modules and network appliances fall under the HBOM.

How IntelliXBOM helps

IntelliXBOM ingests vendor and in-house SBOMs in CycloneDX and SPDX, validates them against CERT-In and internal field policies, and correlates components with vulnerabilities, known-exploited lists, licences, end-of-life data and business services. It records VEX decisions and exceptions, maps inventory to framework controls, and produces timestamped evidence, self-hosted or air-gapped.

This article summarises public guidance for information only and is not legal advice; refer to the current official documents before acting.

Frequently asked questions

Does SEBI require an SBOM?

Yes. SEBI's CSCRF requires regulated entities to obtain SBOMs for all software and applications required for core and critical business operations, whether developed in-house or by third parties, including SaaS.

Does RBI mandate SBOMs for banks?

RBI's 2023 IT governance directions do not use the term SBOM, but they require vendor confirmation that critical applications are free of known vulnerabilities and access to source code or escrow. KPMG reports that RBI has advised regulated entities to adopt CERT-In's SBOM guidelines.

What if a vendor refuses to provide an SBOM?

SEBI's FAQs say the Board, Partners or Proprietor should approve the exception with a stated limitation, rationale and risk-management approach. Record compensating controls and revisit at contract renewal.

Sources

  1. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities, Circular SEBI/HO/ITD-1/ITD_CSC_EXT/P/CIR/2024/113 (20 August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
  2. Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (June 2025)SEBIwww.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
  3. Complying with SEBI SBOM RequirementsFOSSAfossa.com/blog/complying-sebi-sbom-requirements/
  4. Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023Reserve Bank of Indiawww.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12562
  5. SBOM in India's Regulatory Landscape: Building Trust through Transparency (December 2025)KPMG in Indiaassets.kpmg.com/content/dam/kpmgsites/in/pdf/2025/12/sbom-in-indias-regulatory-landscape-building-trust-hrough-transparency.pdf
  6. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  7. Understanding SBOM Requirements in PCI DSSFOSSAfossa.com/blog/understanding-sbom-requirements-pci-dss/
  8. Known Exploited Vulnerabilities CatalogCISAwww.cisa.gov/known-exploited-vulnerabilities-catalog

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related SBOM guides

Across the BOM Suite

Put your SBOM under governance.Software transparency with continuous correlation and timestamped evidence.