supply-chaintrade-pressNewsThe Broadside2 min read

FCC weighs SBOM, HBOM mandate for equipment authorization

The proposal makes component provenance a market-access question, with hardware and firmware pulled into the supply-chain disclosure regime.


TL;DR

Inside Cybersecurity reports the FCC will consider at its July 22 meeting a draft further notice that would require equipment authorization applicants to submit signed Software Bills of Materials and Hardware Bills of Materials identifying each component’s producer, production location and value share, then update filings within 30 days. Manufacturers, primes, contractors and independent software vendors would have to prove provenance before U.S. certification. The unresolved point is whether currently certified equipment faces retroactive disclosure, or only new applications do.

FCC weighs SBOM, HBOM mandate for equipment authorization
Editorial illustration · drawn by The Broadside

Inside Cybersecurity reports that the FCC’s draft further notice would take equipment authorization down a level, from finished-device screening to component provenance. Applicants would submit written, signed Software Bills of Materials (SBOMs) and Hardware Bills of Materials (HBOMs) at certification, covering hardware, software and firmware components. The disclosures would identify each component’s producer, where it was produced and the percentage of component value associated with each production location. Grantees would update those filings within 30 days after changes.

For manufacturers, primes, contractors and independent software vendors tied to radiofrequency devices, routers, drones, modular transmitters or logic-bearing hardware, that filing becomes a market-access control. The FCC already uses the Covered List to block communications equipment and services deemed national security risks, and GAO described the 2021 rule as publishing that list and creating a reimbursement program for removal and replacement by smaller providers (https://www.gao.gov/products/b-332866). The draft, as reported, extends the same logic to embedded components. A device can clear branding and final assembly questions and still fail if its parts point to a covered entity or risky production location.

This borrows from the federal software supply-chain playbook and widens it. NIST’s EO 14028 SBOM guidance describes an SBOM as a formal record of components and supply-chain relationships and says SBOMs can improve provenance and vulnerability response when acquirers can use the data (https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-supply-chain-security-guidance-20). NIST also warns that SBOMs complement existing supply-chain risk management and do little if agencies cannot ingest, analyze and act on them (https://www.nist.gov/itl/executive-order-14028-improving-nations-cybersecurity/software-supply-chain-security-guidance-20). The FCC version would add HBOMs and make the ingestion problem a condition of certification.

The practical fight will be over scope and timing. Inside Cybersecurity reports that the FCC estimates automated SBOM generation for newly developed software would carry negligible burden, existing software could cost under $5,000 per program, HBOM work could reach $10,000 per hardware item and roughly half of authorization applicants already meet the proposed SBOM and HBOM requirements. The FCC also floats limiting the mandate to Covered List sectors, which it estimates would cover below 10 percent of certification applications. The open question is the one that matters to existing product lines: whether current certifications eventually need retroactive disclosure, or whether the new gate only catches new applications and later changes.


Published ·Deep Fathom