PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 202610 sources

SBOM for Indian enterprises: what to do and in what order

Indian enterprises face SBOM expectations from several directions: CERT-In, sector regulators, government customers and overseas buyers. This guide sorts out which apply and sets out a phased roadmap.

Key takeaways
  • Which SBOM expectations apply depends on whether you buy software, build it, supply government or sell abroad.
  • CERT-In's guidelines explicitly address the software export and services industry, not only government.
  • Overseas customers bring their own baselines, such as the EU CRA and CISA's 2026 elements.
  • CERT-In's three-phase roadmap, Start, Progress and Advance, is a sensible sequence for most organisations.

Which expectations apply to you

If you…Expect
Supply software to government, public sector or essential servicesA complete SBOM with every delivery, under CERT-In recommendation 7.1.2 [1]
Are a SEBI regulated entitySBOMs for all core and critical software, in-house, third-party or SaaS [2]
Are an RBI regulated entityVendor confirmations on known vulnerabilities and source-code access for critical applications [3], with CERT-In alignment reported as advised [4]
Export software or servicesCERT-In addresses the software export and services industry directly [1]; customers apply their own rules
Sell products with digital elements in the EUAn SBOM covering at least top-level dependencies in the technical documentation [5]
Sell medical devices in the U.S.An SBOM to the FDA under FD&C Act section 524B [6]

Many organisations fall into more than one row. An IT services company may be a supplier to government, a vendor to banks and an exporter to European clients at the same time. See SBOM compliance for detail on each source.

Software exporters

For exporters, SBOM requests arrive through customer contracts. European customers subject to the Cyber Resilience Act will need SBOMs from component suppliers to meet their own obligations; the CRA's main obligations apply from 11 December 2027, and reporting obligations from 11 September 2026 [5][7]. U.S. customers commonly reference CISA's 2026 Minimum Elements, which add author signature, tool information, generation context and hashes to the NTIA baseline [8]. Build once to the broadest baseline you face; CERT-In's 21 fields cover most of what others ask for, though some customers will add requirements such as BSI's SHA-512 hashes [9].

A phased roadmap

CERT-In's guidelines set out three phases [1]:

  1. Start. Identify critical assets and a project plan; decide SBOM format and minimum requirements; identify security requirements, secure storage and tooling; acquire SBOMs through procurement.
  2. Progress. Develop secure installation and operation guidance; assign unique identifiers using Package URL; map supplier SBOMs to internal SBOMs; document installed components; integrate SBOMs into each phase of the secure development lifecycle; establish secure configuration management.
  3. Advance. Enhance vulnerability tracking and incident response; review SBOMs periodically; keep track of new components and industry developments.

The first 90 days

WeeksFocus
1–4Name an owner; list critical applications and suppliers; choose format and field baseline; pick generators (see SBOM tools)
5–8Generate SBOMs in CI/CD for in-house critical applications; request SBOMs from top suppliers; validate on intake
9–13Correlate with vulnerabilities and CISA's KEV catalogue [10]; start a VEX process; add SBOM clauses to new contracts

Common gaps to plan for

  • Legacy and proprietary software whose vendors cannot supply SBOMs. Analysed SBOMs of the delivered binaries can partly fill the gap; SEBI expects board-approved exceptions where SBOMs cannot be obtained [2].
  • Stale operational fields. Vulnerabilities, patch status and EOL dates in CERT-In's list change after delivery and need continuous enrichment.
  • SaaS. SEBI's FAQs include SaaS applications in scope, so contracts with SaaS providers need SBOM terms too.

Beyond software

CERT-In's Version 2.0 guidelines extend the same approach to cryptography, quantum, AI and hardware [1]. Once SBOMs are routine, extend to a CBOM for critical services, an AIBOM for deployed models and an HBOM for key infrastructure.

How IntelliXBOM helps

IntelliXBOM gives Indian enterprises one self-hosted inventory for SBOMs and the other BOM types, in CycloneDX and SPDX, validated against CERT-In and customer field policies. It correlates components with vulnerabilities, known-exploited lists, licences, end-of-life data and business services, and maps the result to framework controls with timestamped evidence.

This article summarises public guidance for information only and is not legal advice; refer to the current official documents before acting.

Frequently asked questions

Do Indian private companies need SBOMs?

It depends on who you sell to and who regulates you. Suppliers to government, SEBI regulated entities and exporters serving EU or U.S. customers all face SBOM expectations, and CERT-In encourages SBOM adoption across the software industry.

Where should an Indian enterprise start with SBOMs?

Follow CERT-In's Start phase: identify critical assets, choose a format and minimum fields, set up secure storage and tooling, and request SBOMs through procurement. Then generate SBOMs in CI/CD for in-house critical applications.

Is the CERT-In field list enough for overseas customers?

It covers most of what other baselines ask for, but some customers add specific requirements, such as SHA-512 hashes and minimum format versions under BSI TR-03183-2. Validate against each customer's stated baseline.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. Frequently Asked Questions (FAQs) on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (June 2025)SEBIwww.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
  3. Reserve Bank of India (Information Technology Governance, Risk, Controls and Assurance Practices) Directions, 2023Reserve Bank of Indiawww.rbi.org.in/Scripts/BS_ViewMasDirections.aspx?id=12562
  4. SBOM in India's Regulatory Landscape: Building Trust through Transparency (December 2025)KPMG in Indiaassets.kpmg.com/content/dam/kpmgsites/in/pdf/2025/12/sbom-in-indias-regulatory-landscape-building-trust-hrough-transparency.pdf
  5. Regulation (EU) 2024/2847, Cyber Resilience ActEUR-Lexeur-lex.europa.eu/eli/reg/2024/2847/oj
  6. 21 U.S. Code § 360n-2, Ensuring cybersecurity of devices (FD&C Act section 524B)Legal Information Institute, Cornell Law Schoolwww.law.cornell.edu/uscode/text/21/360n-2
  7. Cyber Resilience Act, Reporting obligationsEuropean Commissiondigital-strategy.ec.europa.eu/en/policies/cra-reporting
  8. CISA Releases the 2026 SBOM Minimum ElementsFOSSAfossa.com/blog/cisa-releases-2026-minimum-sbom-elements/
  9. BSI TR-03183-2: SBOM Requirements (v2.1.0)sbomifysbomify.com/compliance/bsi-tr-03183/
  10. Known Exploited Vulnerabilities CatalogCISAwww.cisa.gov/known-exploited-vulnerabilities-catalog

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related SBOM guides

Across the BOM Suite

Put your SBOM under governance.Software transparency with continuous correlation and timestamped evidence.