{"id":24679,"date":"2022-10-24T10:14:00","date_gmt":"2022-10-24T10:14:00","guid":{"rendered":"https:\/\/one.sightlinemg.com\/c4isrnet\/uncategorized\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/"},"modified":"2026-08-08T05:01:41","modified_gmt":"2026-08-08T05:01:41","slug":"sbom-disclosure-rules-loom-for-federal-software-procurement","status":"publish","type":"post","link":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/","title":{"rendered":"\u2018SBOM\u2019 disclosure rules loom for federal software procurement"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">The Software Bill of Materials, or SBOM, disclosure requirement is coming for federal agencies and their contractors. Are managers and executives ready?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.youtube.com%2Fwatch%3Fv%3Dp3qrmJP_CYo&#038;data=05%7C01%7Ccary.oreilly%40mco.com%7C2b299551e41049a0a53e08dab379a343%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638019632270598632%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&#038;sdata=nnm9i701AeCPEk03yvOBbLdbZK5nFH23aH7bzMxfVJk%3D&#038;reserved=0\">SBOM<\/a> is a formal, machine-readable inventory of software components. They may include open source or proprietary software and are designed to reduce cost as well as security, licensing and compliance risk. The White House Office of Management and Budget last month <a href=\"https:\/\/nam04.safelinks.protection.outlook.com\/?url=https%3A%2F%2Fwww.whitehouse.gov%2Fwp-content%2Fuploads%2F2022%2F09%2FM-22-18.pdf&#038;data=05%7C01%7Ccary.oreilly%40mco.com%7C2b299551e41049a0a53e08dab379a343%7C1d5c96e57ee2446dbed8d0f8c50edea5%7C1%7C1%7C638019632270598632%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&#038;sdata=IH16k0mvPyizFfG6s1HJKYpeMLs2zFhUMx1Av0fSt0k%3D&#038;reserved=0\">gave<\/a> federal agencies a year to collect software attestations and artifacts like SBOMs from government software vendors verifying adherence to secure development practices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The limit is just 270 days for \u201ccritical software.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once federal agencies receive an SBOM, what will they do with it, how will they manage it, and how will they integrate it into existing enterprise processes? Managers must begin planning how to operationalize SBOMs now, lest they miss a critical opportunity to enhance the security of the software supply chain.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Technologists <a href=\"https:\/\/www.youtube.com\/watch?v=p3qrmJP_CYo\">compare<\/a> SBOMs to the list of ingredients found on food packaging. They list the component pieces of software within a larger software product and thus enable consumers to assess their known vulnerabilities. In addition, consumers can determine if software critical to business functions or national security contains other risk indicators, like <a href=\"https:\/\/nvlpubs.nist.gov\/nistpubs\/SpecialPublications\/NIST.SP.800-53r5.pdf\">data<\/a> about the country of origin, ownership, and frequency of updates. With this information, consumers can quickly take action to mitigate the problem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For this reason, Congress and the Biden administration are pushing mandates on federal agencies to require SBOMs for all software products these agencies purchase. Last year, President Joe Biden issued<a href=\"https:\/\/www.whitehouse.gov\/briefing-room\/presidential-actions\/2021\/05\/12\/executive-order-on-improving-the-nations-cybersecurity\/\"> Executive Order (EO) 14028<\/a>, \u201cImproving the Nation\u2019s Cybersecurity,\u201d which required the Department of Commerce\u2019s National Telecommunications and Information Administration to identify the minimum elements an SBOMs should include.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then, the EO required the National Institute of Standards and Technology to issue \u201cguidance identifying practices that enhance the security of the software supply chain,\u201d including providing consumers with SBOMs. Lastly, the OMB was to mandate federal agencies use this guidance. Last month, it completed this final step, issuing a <a href=\"https:\/\/www.whitehouse.gov\/wp-content\/uploads\/2022\/09\/M-22-18.pdf\">memorandum<\/a> stating that agencies may require SBOMs in solicitation requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In parallel, Congress is exploring updates to federal acquisition regulations to require government contractors to provide SBOMs. The Senate\u2019s <a href=\"https:\/\/subscriber.politicopro.com\/f\/?id=00000183-cca0-dcd6-af9f-fcfead930000&#038;source=email\">draft<\/a> of fiscal 2023 <a href=\"https:\/\/www.congress.gov\/bill\/117th-congress\/senate-bill\/4543\">National Defense Authorization Act<\/a> authorizes the Secretary of Defense to require SBOMs for \u201call noncommercial software created for or acquired by the Department of Defense.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Senate draft also directs the Secretary to develop a plan for receiving SBOMs accompanying commercial software. Congress wants the Pentagon to \u201cunderstand promptly the cybersecurity risks to Department capabilities posed by discoveries of vulnerabilities and compromises in commercial and open source software.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These are essential steps to add transparency and security to the software supply chain, but federal agencies still have no guidance on how to use an SBOM once they receive one.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">\u2018Nutrition labels\u2019 for software<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The problem is that SBOMs are not as easy to read as nutrition labels. Food labels do not list the origin of each food item or the farmer who handled the components. They do not list the breed of chicken that laid the egg. As a result, consumers cannot go to a restaurant, look at the menu, and assess if their eggs come from a trustworthy farm.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SBOMs, on the other hand, are complex\u2014which makes sense because there\u2019s a lot more risk associated with bad software than with a bad egg. Imagine a jar of salsa, which instead of simply listing \u201cdiced tomatoes,\u201d would list the variety of tomatoes used, the farm where the tomatoes were harvested, the farm\u2019s owner, the farmhands that picked the tomatoes, and the fertilizers and pesticides used.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SBOMs are like that \u2013 they can list components and subcomponents (dependencies), author(s), build or version number, license terms, technical debt, time series analysis, and maintenance patterns. To be most effective as a tool for risk management, SBOMs must be continuously updated to reflect every time developers change the software.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Today\u2019s consumer understands how to read a nutrition label to assess things like sodium levels and allergens. However, OMB\u2019s memo does not explain to federal agencies how to read the \u201cSBOM label.\u201d The NIST guidance mandated by the OMB memorandum does briefly mention SBOMs in the Secure Software Development Framework as an example of an artifact used to collect, safeguard, maintain, and share provenance data for software components.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, the Software Development Framework does not explain how federal agencies should understand the information. Software consumers will need to establish processes to use SBOMs to identify, for example, component pieces developed by a particular entity in a specific location, such as in an adversarial foreign nation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Multiple vendors means multiple SBOMs<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Federal agencies will receive multiple SBOMs from vendors, contractors, and internal software development teams. They will need a process to validate, analyze, store, manage, and integrate multiple SBOMs to make informed decisions based on risk acceptance and security requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, a diabetic consumer at the grocery store understands that buying a pint of ice cream might be safe if consumed in quantities amenable to their total daily allowance. However, purchasing and consuming cookies, cakes, and candies may surpass the daily limit of allowable sugar intake, which could be too risky for their health.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Federal agencies need an analogous understanding of the totality of their software and its dependencies to make informed decisions based on the information contained in multiple SBOMs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They also need more guidance to understand how SBOMs contribute to and integrate into existing enterprise processes around acquisitions, risk management, asset management, and defensive cyber operations. That guidance can come from OMB, but much of the expertise about SBOM use resides in the private sector. Thus, federal agencies should leverage <a href=\"https:\/\/www.nsa.gov\/Press-Room\/News-Highlights\/Article\/Article\/3146465\/nsa-cisa-odni-release-software-supply-chain-guidance-for-developers\/\">existing<\/a> public-private partnerships around software supply chain assurance to minimize costs and maximize private sector expertise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SBOMs can play an important role in cybersecurity, adding transparency and security to the software supply chain. But receiving an SBOM is pointless if an organization does not know how to use it effectively.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><i>Dr. Georgianna Shea is the chief technologist of the <\/i><a href=\"https:\/\/www.fdd.org\/projects\/center-on-cyber-and-technology-innovation\/\"><i>Center on Cyber and Technology Innovation<\/i><\/a> <i>(CCTI) at the Foundation for Defense of Democracies. Annie Fixler is CCTI deputy director and an FDD research fellow. FDD is a Washington, D.C.-based, nonpartisan research institute focusing on national security and foreign policy.<\/i><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Software Bill of Materials are machine-readable inventories of software components designed to reduce cost and security risk.<\/p>\n","protected":false},"author":7,"featured_media":60967,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_canonical":"","_acf":"","_yoast_wpseo_primary_category":10,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","_smg_distribution_targets":[]},"categories":[6,10,29,13,16],"tags":[],"coauthors":[3641,5846],"class_list":["post-24679","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-artificial-intelligence","category-cyber","category-home","category-industry","category-it-networks"],"acf":{"subheadline":"","legacy_arc_id":"SKBEBKS5ZJGIDJUFFHM7FEA5D4","arc_canonical_url":"\/it-networks\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/","remove_feature_photo":false,"is_sponsored":false,"subtype":"","redirect_url":"","disable_inline_ads":false,"native_logo_pretext":"Presented By:"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>\u2018SBOM\u2019 disclosure rules loom for federal software procurement - C4ISRNet<\/title>\n<meta name=\"description\" content=\"Software Bill of Materials are machine-readable inventories of software components designed to reduce cost and security risk.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"\u2018SBOM\u2019 disclosure rules loom for federal software procurement\" \/>\n<meta property=\"og:description\" content=\"Software Bill of Materials are machine-readable inventories of software components designed to reduce cost and security risk.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/\" \/>\n<meta property=\"og:site_name\" content=\"C4ISRNet\" \/>\n<meta property=\"article:published_time\" content=\"2022-10-24T10:14:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-08-08T05:01:41+00:00\" \/>\n<meta name=\"author\" content=\"Georgianna Shea, Annie Fixler\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Georgianna Shea, Annie Fixler\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\n\t    \"@context\": \"https:\\\/\\\/schema.org\",\n\t    \"@graph\": [\n\t        {\n\t            \"@type\": \"Article\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/#article\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/\"\n\t            },\n\t            \"author\": {\n\t                \"name\": \"migration\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\"\n\t            },\n\t            \"headline\": \"\u2018SBOM\u2019 disclosure rules loom for federal software procurement\",\n\t            \"datePublished\": \"2022-10-24T10:14:00+00:00\",\n\t            \"dateModified\": \"2026-08-08T05:01:41+00:00\",\n\t            \"mainEntityOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/\"\n\t            },\n\t            \"wordCount\": 1054,\n\t            \"commentCount\": 0,\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyRansomare.jpg.jpg\",\n\t            \"articleSection\": [\n\t                \"AI &amp; ML\",\n\t                \"Cyber\",\n\t                \"Home\",\n\t                \"Industry\",\n\t                \"IT and Networks\"\n\t            ],\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"CommentAction\",\n\t                    \"name\": \"Comment\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/#respond\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebPage\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/\",\n\t            \"name\": \"\u2018SBOM\u2019 disclosure rules loom for federal software procurement - C4ISRNet\",\n\t            \"isPartOf\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\"\n\t            },\n\t            \"primaryImageOfPage\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/#primaryimage\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/#primaryimage\"\n\t            },\n\t            \"thumbnailUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyRansomare.jpg.jpg\",\n\t            \"datePublished\": \"2022-10-24T10:14:00+00:00\",\n\t            \"dateModified\": \"2026-08-08T05:01:41+00:00\",\n\t            \"description\": \"Software Bill of Materials are machine-readable inventories of software components designed to reduce cost and security risk.\",\n\t            \"breadcrumb\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/#breadcrumb\"\n\t            },\n\t            \"inLanguage\": \"en-US\",\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"ReadAction\",\n\t                    \"target\": [\n\t                        \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/\"\n\t                    ]\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"ImageObject\",\n\t            \"inLanguage\": \"en-US\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/#primaryimage\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyRansomare.jpg.jpg\",\n\t            \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/GettyRansomare.jpg.jpg\"\n\t        },\n\t        {\n\t            \"@type\": \"BreadcrumbList\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/2022\\\/10\\\/24\\\/sbom-disclosure-rules-loom-for-federal-software-procurement\\\/#breadcrumb\",\n\t            \"itemListElement\": [\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 1,\n\t                    \"name\": \"Home\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t                    \"ad_zone\": \"home\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 2,\n\t                    \"name\": \"Cyber\",\n\t                    \"item\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/cyber\\\/\",\n\t                    \"ad_zone\": \"cyber\"\n\t                },\n\t                {\n\t                    \"@type\": \"ListItem\",\n\t                    \"position\": 3,\n\t                    \"name\": \"\u2018SBOM\u2019 disclosure rules loom for federal software procurement\"\n\t                }\n\t            ]\n\t        },\n\t        {\n\t            \"@type\": \"WebSite\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#website\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"description\": \"Media for the Intelligence-Age Military | C4ISRNET\",\n\t            \"publisher\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\"\n\t            },\n\t            \"potentialAction\": [\n\t                {\n\t                    \"@type\": \"SearchAction\",\n\t                    \"target\": {\n\t                        \"@type\": \"EntryPoint\",\n\t                        \"urlTemplate\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/?s={search_term_string}\"\n\t                    },\n\t                    \"query-input\": {\n\t                        \"@type\": \"PropertyValueSpecification\",\n\t                        \"valueRequired\": true,\n\t                        \"valueName\": \"search_term_string\"\n\t                    }\n\t                }\n\t            ],\n\t            \"inLanguage\": \"en-US\"\n\t        },\n\t        {\n\t            \"@type\": \"Organization\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#organization\",\n\t            \"name\": \"C4ISRNet\",\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/\",\n\t            \"logo\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\",\n\t                \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"contentUrl\": \"https:\\\/\\\/one.sightlinemg.com\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/c4isrnet-logo-white.png\",\n\t                \"caption\": \"C4ISRNet\"\n\t            },\n\t            \"image\": {\n\t                \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/logo\\\/image\\\/\"\n\t            }\n\t        },\n\t        {\n\t            \"@type\": \"Person\",\n\t            \"@id\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/#\\\/schema\\\/person\\\/cc76c831bb37a926738c8391fca7a3b1\",\n\t            \"name\": \"migration\",\n\t            \"image\": {\n\t                \"@type\": \"ImageObject\",\n\t                \"inLanguage\": \"en-US\",\n\t                \"@id\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec\",\n\t                \"url\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"contentUrl\": \"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g\",\n\t                \"caption\": \"migration\"\n\t            },\n\t            \"url\": \"https:\\\/\\\/one.sightlinemg.com\\\/c4isrnet\\\/author\\\/migration\\\/\"\n\t        }\n\t    ]\n\t}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"\u2018SBOM\u2019 disclosure rules loom for federal software procurement - C4ISRNet","description":"Software Bill of Materials are machine-readable inventories of software components designed to reduce cost and security risk.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/one.sightlinemg.com\/federaltimes\/it-networks\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/","og_locale":"en_US","og_type":"article","og_title":"\u2018SBOM\u2019 disclosure rules loom for federal software procurement","og_description":"Software Bill of Materials are machine-readable inventories of software components designed to reduce cost and security risk.","og_url":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/","og_site_name":"C4ISRNet","article_published_time":"2022-10-24T10:14:00+00:00","article_modified_time":"2026-08-08T05:01:41+00:00","author":"Georgianna Shea, Annie Fixler","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Georgianna Shea, Annie Fixler","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/#article","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/"},"author":{"name":"migration","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1"},"headline":"\u2018SBOM\u2019 disclosure rules loom for federal software procurement","datePublished":"2022-10-24T10:14:00+00:00","dateModified":"2026-08-08T05:01:41+00:00","mainEntityOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/"},"wordCount":1054,"commentCount":0,"publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyRansomare.jpg.jpg","articleSection":["AI &amp; ML","Cyber","Home","Industry","IT and Networks"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/","name":"\u2018SBOM\u2019 disclosure rules loom for federal software procurement - C4ISRNet","isPartOf":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website"},"primaryImageOfPage":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/#primaryimage"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/#primaryimage"},"thumbnailUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyRansomare.jpg.jpg","datePublished":"2022-10-24T10:14:00+00:00","dateModified":"2026-08-08T05:01:41+00:00","description":"Software Bill of Materials are machine-readable inventories of software components designed to reduce cost and security risk.","breadcrumb":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/#primaryimage","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyRansomare.jpg.jpg","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyRansomare.jpg.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/2022\/10\/24\/sbom-disclosure-rules-loom-for-federal-software-procurement\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/","ad_zone":"home"},{"@type":"ListItem","position":2,"name":"Cyber","item":"https:\/\/one.sightlinemg.com\/c4isrnet\/cyber\/","ad_zone":"cyber"},{"@type":"ListItem","position":3,"name":"\u2018SBOM\u2019 disclosure rules loom for federal software procurement"}]},{"@type":"WebSite","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#website","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","name":"C4ISRNet","description":"Media for the Intelligence-Age Military | C4ISRNET","publisher":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/one.sightlinemg.com\/c4isrnet\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#organization","name":"C4ISRNet","url":"https:\/\/one.sightlinemg.com\/c4isrnet\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/","url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","contentUrl":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/06\/c4isrnet-logo-white.png","caption":"C4ISRNet"},"image":{"@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/one.sightlinemg.com\/c4isrnet\/#\/schema\/person\/cc76c831bb37a926738c8391fca7a3b1","name":"migration","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=gcf4cb6ee0ec29e49e7a963234e4340ec","url":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9e8d47be443ce94ce7fc357677b5f9c70235bb1f59e7267a102a74af58c04f59?s=96&d=mm&r=g","caption":"migration"},"url":"https:\/\/one.sightlinemg.com\/c4isrnet\/author\/migration\/"}]}},"jetpack_featured_media_url":"https:\/\/one.sightlinemg.com\/wp-content\/uploads\/2026\/08\/GettyRansomare.jpg.jpg","jetpack_sharing_enabled":true,"distributor_meta":false,"distributor_terms":false,"distributor_media":false,"distributor_original_site_name":"C4ISRNet","distributor_original_site_url":"https:\/\/one.sightlinemg.com\/c4isrnet","push-errors":false,"_links":{"self":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/24679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/comments?post=24679"}],"version-history":[{"count":1,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/24679\/revisions"}],"predecessor-version":[{"id":24682,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/posts\/24679\/revisions\/24682"}],"wp:attachment":[{"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/media?parent=24679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/categories?post=24679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/tags?post=24679"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/one.sightlinemg.com\/c4isrnet\/wp-json\/wp\/v2\/coauthors?post=24679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}