Requires suppliers to provide a Hardware Bill of Materials (HBOM) cataloging hardware components to support Cybersecurity Supply Chain Risk Management (C-SCRM) practices.
This Data Item Description (DID) is designated to ensure that suppliers and vendors are actively engaged in maintaining and improving Cybersecurity Supply Chain Risk Management (C-SCRM) practices. The DID mandates the creation and provision of a comprehensive Hardware Bill of Materials (HBOM). It provides a standardized and systematic methodology for cataloging hardware components within embedded and connected devices to facilitate better understanding and management of potential cybersecurity risks.
a. The HBOM provided must be a representation of the production release manufacturing bill of materials, or "as-built" BOM representing the components that were actually used in the production of the product. These should include (where applicable)
(1) Configurable BOM (CBOM) - These BOMs describe multiple options in the manufacturing process driven by selection of options for unique models in a product family. The supplier must provide all iterations of the BOM that are relevant for the "as-built" models procured by the customer.
(2) BOM Variant - These BOMs describe multiple options in the manufacturing process used for the same model of a product. For instance, one server may use network adapter cards from multiple vendors with the same form, fit and function. If BOM variants are used for this purpose, the supplier must provide all of the relevant BOM variants for the "as-built" models procured by the customer.
(3) Manufacturing Deviations - Any exceptions to approved or "as-built" manufacturing that have been applied. These are temporary exceptions to documented manufacturing procedure or process that are put in place until a permanent change can be made. For instance, a component may have been specified with a tighter tolerance than actually needed (1% instead of 5%) for form, fit, and function. A deviation can be written to allow use of 5% parts for a specified period of time while a change order is written to replace the 1% parts.
b. Unless otherwise specified hardware BOM type should not include:
(1) Engineering BOM (EBOM) - Used in the design of the product, but may not be an accurate representation of the manufactured product. This would only be appropriate in the prototype phase of a project.
c. The word "item" is used throughout the document to refer to hardware components of the system.
d. This DID contain the format, content, and intended use information for the data product resulting from the work task described in the solicitation.
e. This DID should be tailored in the Contract Data Requirements List (CDRL) to include the necessary field categories from Table 1.
Hardware Bill of Materials (HBOM) Framework for Supply Chain Risk Management | CISA https://www.cisa.gov/resources-tools/resources/hardware-bill-materials-hbom-framework-supply-chain-risk-management

Figure 1. FIGURE 1

Figure Table 1. TABLE 1

Figure Table 1 (continued). TABLE 1 (continued)