SBOM for government and the public sector
Governments buy software from many suppliers and integrators, often for essential services. CERT-In's guidelines make SBOMs part of that procurement. This guide explains the expectations and compares them with U.S. federal policy.
- CERT-In recommends that government, public-sector and essential-services organisations include SBOM requirements in all software procurement.
- Software supplied to these organisations must be accompanied by a complete SBOM, under CERT-In recommendation 7.1.2.
- System integrators carry the obligation to deliver accurate SBOMs with every deliverable.
- U.S. federal policy has moved from central SBOM guidance to agency-level, risk-based decisions.
CERT-In's expectations for the public sector
CERT-In's Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM (Version 2.0, 9 July 2025) are aimed particularly at government, the public sector, essential services and the software export and services industry [1]. Two recommendations are central for public buyers [1]:
- 7.1.1: government, public-sector and essential-services organisations "should include requirements for SBOM in all their software and solutions Purchase/Procurement".
- 7.1.2: "All software supplied to the government; public sector & essential services organizations/departments must be accompanied by a complete SBOM."
Law-firm commentary notes that the guidelines are framed as recommendations rather than a statutory mandate [2], but a procurement requirement written into a tender makes them contractually binding for suppliers.
Roles in the supply chain
| Role | CERT-In expectation [1] |
|---|---|
| Software consumer (the department) | Ask for a complete SBOM; map it to an internal SBOM; include it in vulnerability management; update it when patches are applied |
| Software developer | Supply a correct and complete SBOM; issue VEX and CSAF advisories when vulnerabilities are found |
| System integrator or reseller | Distribute products with complete SBOMs and include accurate SBOMs in all deliverables |
Integrators matter most in public-sector projects, because a single contract may bundle software from many vendors. The integrator should aggregate component SBOMs into a delivery SBOM for the whole solution; CERT-In defines a delivery SBOM as describing every part, library and dependency in a release or delivery package [1].
Audits
CERT-In's Comprehensive Cyber Security Audit Policy Guidelines (25 July 2025) include SBOM, QBOM and AIBOM auditing in the scope of audit engagements, covering component traceability, known vulnerabilities, licensing and supply-chain risk [3]. Departments should expect auditors to ask for SBOMs and for evidence that they are maintained.
How U.S. federal policy compares
Executive Order 14028 (May 2021) directed the publication of minimum SBOM elements and listed providing purchasers an SBOM as a secure-development practice [4]. OMB memorandum M-22-18 (September 2022) then allowed agencies to require SBOMs in solicitations based on criticality [5]. In February 2026, OMB memorandum M-26-05 rescinded M-22-18 and its update, making attestations and SBOMs agency decisions based on risk, and noting that SBOMs requested from cloud providers should cover the runtime production environment [6]. The 2026 Minimum Elements for an SBOM, published by CISA with the NSA and partners, remain the technical reference [7].
| India (CERT-In) | United States (federal) | |
|---|---|---|
| Instrument | Technical guidelines with procurement recommendations | Executive order, OMB memoranda, CISA guidance |
| Current posture | SBOM in all public-sector procurement; complete SBOM with supplied software | Agency discretion under M-26-05 |
| Field baseline | 21 fields | 2026 Minimum Elements |
| Exploitability | VEX then CSAF advisory | VEX minimum requirements published by CISA [8] |
Practical steps for departments
- Add SBOM clauses to tender templates; see SBOM procurement requirements.
- Specify format (SPDX or CycloneDX), depth (complete), and field baseline (the 21 CERT-In fields).
- Validate SBOMs at delivery acceptance, not months later.
- Require updated SBOMs and VEX for every patch and release during the contract.
- Keep SBOMs, validation results and VEX decisions as audit evidence.
How IntelliXBOM helps
IntelliXBOM helps public-sector teams validate supplier SBOMs in CycloneDX and SPDX against the CERT-In field list, keep version history per delivery and correlate components with vulnerabilities and known-exploited lists. It records VEX decisions, maps the inventory to framework controls with timestamped evidence, and can be deployed on-premise or air-gapped.
This article summarises public guidance for information only and is not legal advice; refer to the current official documents before acting.
Frequently asked questions
Is an SBOM required for software sold to the Indian government?
CERT-In's Version 2.0 guidelines state that all software supplied to government, public-sector and essential-services organisations must be accompanied by a complete SBOM, and recommend including SBOM requirements in all procurement. Tender documents make this binding on suppliers.
Who provides the SBOM in a system-integration project?
CERT-In expects system integrators and resellers to include accurate SBOMs in all deliverables. In practice the integrator collects component SBOMs from each vendor and provides a delivery SBOM for the whole solution.
Does the U.S. government still require SBOMs?
Since OMB memorandum M-26-05 in February 2026, each agency decides based on risk whether to require SBOMs. CISA's 2026 Minimum Elements remain the reference for SBOM content.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- CERT-In's Technical Guidelines on SBOM, QBOM and CBOM, AIBOM and HBOMAZB & Partnerswww.azbpartners.com/bank/cert-ins-technical-guidelines-on-sbom-qbom-and-cbom-aibom-and-hbom/
- Comprehensive Cyber Security Audit Policy Guidelines, Version 1.0 (25 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/Comprehensive_Cyber_Security_Audit_Policy_Guidelines.pdf
- Executive Order 14028, Improving the Nation's Cybersecurity (May 2021)Federal Registerwww.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity
- M-22-18, Enhancing the Security of the Software Supply Chain through Secure Software Development Practices (14 September 2022)Office of Management and Budgetbidenwhitehouse.archives.gov/wp-content/uploads/2022/09/M-22-18.pdf
- OMB Rescinds Biden-Era Software Security Requirements, Directs Agency-Led and Risk-Based Approach (February 2026)Davis Wright Tremainewww.dwt.com/blogs/privacy--security-law-blog/2026/02/omb-changes-course-on-software-security
- 2026 Minimum Elements for a Software Bill of Materials (SBOM)CISA with NSA and partner agencieswww.cisa.gov/resources-tools/resources/2026-minimum-elements-software-bill-materials-sbom
- Minimum Requirements for Vulnerability Exploitability eXchange (VEX), April 2023CISAwww.cisa.gov/sites/default/files/2023-04/minimum-requirements-for-vex-508c.pdf
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.