Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CISA’s Hardware Bill of Materials (HBOM) Framework is voluntary guidance for describing the hardware components in a physical product in a consistent, structured way. It helps vendors and purchasers examine supply-chain risks; it is not a universal requirement to create or submit an HBOM.

What is an HBOM?

An HBOM is a structured record of the parts, assemblies and components used to create a physical product, including information about their manufacturers and related firmware. The aim is to make hardware supply-chain relationships easier for vendors and purchasers to communicate and assess.

A later U.S. Department of Commerce Bureau of Industry and Security (BIS) rule defined an HBOM as “a formal record of the supply chain relationships of parts, assemblies, and components required to create a physical product, including information identifying the manufacturer, and related firmware.” That definition is from the rule published January 16, 2025.

An HBOM centers on physical-product components and their supply-chain relationships. An SBOM, by contrast, centers on software components. A product may involve both hardware and software records; the two serve related but distinct inventory and risk-analysis purposes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What does CISA’s framework contain?

CISA released the framework through the ICT Supply Chain Risk Management Task Force on September 25, 2023. It is organized around three elements:

Element What it does How an organization can use it
Use-case categories (Appendix A) Connects an HBOM to the risk or procurement question being evaluated. Choose the question first so the requested information is relevant to the decision.
Format of HBOMs (Appendix B) Provides a consistent structure for exchanging component information. Use a structured format that suppliers and purchasers can interpret and transfer.
Data-field taxonomy (Appendix C) Defines component and attribute names to make records more predictable and portable. Use the taxonomy when agreeing on field names rather than relying on inconsistent labels.

The framework is designed to make information more consistent; it does not mean that every supplier will disclose the same level of detail or that one record automatically answers every risk question.

What risks can an HBOM help assess?

CISA describes HBOMs as a way to illuminate upstream supply chains and support economic and security risk assessment. Depending on the information available and the use case, a purchaser may use a record to investigate:

  • Whether a component comes from an untrusted or potentially compromised source.
  • Whether a part depends on a single supplier or production region, creating availability or continuity exposure.
  • Whether supply relationships raise legal concerns, including concerns involving forced labor.
  • Whether supplier and component information is sufficiently clear to support safer procurement decisions.

An HBOM is an input to due diligence, not a risk verdict. It does not by itself establish that a component is safe, that a supplier’s information is complete, or that a supply interruption will occur.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Is a hardware bill of materials mandatory?

CISA’s framework is guidance, not a universal mandate to produce or submit an HBOM. A separate BIS rule published in the Federal Register on January 16, 2025, removed a requirement to submit HBOMs with Declarations of Conformity. The rule requires firms within its scope to retain primary business records showing hardware-supply-chain due diligence; those records may include HBOMs.

That distinction matters: removing an HBOM submission requirement does not remove the record-retention obligation described in the rule. Whether the rule applies to a particular organization depends on its scope; organizations should check the rule and their applicable obligations rather than assume the CISA framework itself imposes them.

What information should an HBOM include?

The exact fields should follow the intended use case and the CISA framework’s Appendix C taxonomy. At a minimum, the record should make it possible to identify hardware components, their manufacturers, their relationships to parts or assemblies, and related firmware where applicable. CISA’s framework does not enumerate every taxonomy field in this summary, so a field-by-field list should not be inferred from it.

Before requesting data, agree with suppliers on the component naming scheme, structured format, level of detail, update expectations and handling of confidential business information. These choices affect whether records can be compared across suppliers and used later in procurement or an investigation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should a purchaser use an HBOM to assess supplier risk?

  1. Define the decision. State whether the request is for procurement screening, availability planning, security review or another specific risk question. Use that question to select the relevant information.
  2. Request structured, consistently named records. Ask suppliers to identify components and manufacturers, show component or assembly relationships, and include related firmware where applicable.
  3. Set exchange and stewardship rules. Agree how records will be delivered, protected as confidential business information, updated and retained.
  4. Review the response for decision-useful coverage. Check completeness, naming consistency and whether the supplier’s response can be compared with other suppliers’ records. Note gaps rather than treating missing information as proof of safety or danger.
  5. Combine the record with other due diligence. Consider procurement context, geopolitical exposure, component availability and security analysis alongside the HBOM before deciding how to manage risk.

How to compare HBOM implementations

When evaluating a supplier’s process, an inventory system or an implementation approach, compare the dimensions that determine whether its records will support the intended decision:

  • Use case: Does the record answer the procurement or risk question at hand?
  • Field depth: Are component identities and relationships detailed enough for the task?
  • Supplier participation: Can relevant suppliers provide the information, and are gaps visible?
  • Portability: Can records move between suppliers and purchasers without losing meaning?
  • Manufacturer and firmware relationships: Are those details captured where applicable?
  • Update cadence: Is there an agreed approach to refreshing records as products or supply chains change?
  • Confidentiality controls: Are sensitive business details handled under agreed protections?
  • Operational usefulness: Can the records support procurement decisions or investigations when needed?

CISA’s 2023 announcement presented the framework as a consistent and repeatable way for vendors and purchasers to communicate about hardware components. It quoted Mona Harrington, then CISA National Risk Management Center Assistant Director and ICT SCRM Task Force co-chair, describing standardized naming and comprehensive information as tools for assessing and mitigating supply-chain risk.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.