ssdftrade-pressNewsThe Broadside2 min read

GAO urges CISA to resolve OMB-NIST SBOM conflict

Federal procurement moved before the compliance mechanics existed, leaving vendors to reconcile static paperwork with operational vulnerability data.


TL;DR

Inside Cybersecurity reports that the Government Accountability Office found 17 of 24 surveyed agencies saw a conflict between Office of Management and Budget (OMB) and National Institute of Standards and Technology (NIST) Software Bill of Materials (SBOM) guidance. OMB treated SBOMs as optional static artifacts; NIST treated them as compliance data for vulnerability management. Contractors, primes, subs and Certified Third-Party Assessment Organizations (C3PAOs) get the result: parallel agency collection workflows unless the Cybersecurity and Infrastructure Security Agency (CISA) gives agencies a common implementation model.

Inside Cybersecurity reports that GAO's June 23 report found the federal Software Bill of Materials (SBOM) program split at the root: 17 of 24 surveyed agencies said Office of Management and Budget (OMB) guidance conflicted with National Institute of Standards and Technology (NIST) guidance, including for cloud-related software. OMB's 2022 M-22-18 treated SBOM collection as optional and pushed agencies to build their own collection processes. NIST treated SBOMs as standards-based data producers should share for vulnerability scanning and risk management. That distinction changes the work.

The 18-month implementation gap after the executive order matters because agencies were pushed toward procurement enforcement before OMB and NIST settled whether an SBOM was a file to collect, a data stream to operate, or both.

Contractors, primes, subs and Certified Third-Party Assessment Organizations (C3PAOs) feel the split as duplicated evidence collection. A vendor selling into multiple agencies can be asked to maintain different SBOM repositories, forms, timing rules and contract terms while also supporting the operational use case NIST described. That is the expensive version of ambiguity: every agency gets discretion, and every supplier gets another workflow.

GAO's recommendation is procedural and practical: the Department of Homeland Security should direct the Cybersecurity and Infrastructure Security Agency (CISA) to tell agencies how to integrate SBOM generation, consumption and analysis into risk management, purchasing and software development, including tools where appropriate. DHS said CISA is updating SBOM minimum-elements guidance and expects a final version by the end of fiscal year 2026.

OMB's January 2026 memo may have narrowed the paperwork conflict by rescinding prior memorandums and clarifying that agency heads remain responsible for software and hardware allowed on their networks. GAO's open point is harder: optional SBOM collection does not make agencies capable of ingesting and using SBOM data. Until CISA standardizes the operating model, Monday's work is still mapping each agency's SBOM demand separately.


Published ·Deep Fathom

GAO urges CISA to resolve OMB-NIST SBOM conflict — The Broadside