A man in military uniform uses a laptop. Per a new executive order, the Pentagon has instituted stricter requirements on software purchases, making vendors account for supply chains through “indentured bills of materials” (iBOMs). (Shutterstock/chainarong06)
Enter the iBOM: What the New Defense Supply Chain Order Means for Software
President Donald Trump’s executive order on July 20 is mostly about metals and magnets. But America’s defense contractors will also need to up their game on software transparency.
On July 20, President Donald Trump signed an executive order on securing America’s defense supply chains. Most of the coverage focused on physical materials: rare-earth magnets, tungsten, tantalum, molybdenum, and soon gallium and germanium, all metals concentrated in defense electronics, magnets, and munitions where adversary sourcing has quietly persisted for years.
However, the order also includes software as part of that “critical supply chain.” These software components must be organized and transmitted to the Department of Defense in an “indentured bill of materials,” or iBOM.
What Is an “Indentured Bill of Materials”?
“Indentured” is a common term in the defense community meaning “nested.” An indentured list breaks a finished product into a hierarchy reflecting its assemblies, each assembly into its sub-assemblies, and so on.
For the iBOM, this means that each product sold to the Pentagon must include a list of its subcomponents and materials, tier by tier, all the way down to where the raw materials originate. The result is a complete, hierarchical map of everything inside a product and where each piece came from. The intent is to ensure that the software comes from trusted sources at all levels, and does not rely at any point on a suspect vendor with potential ties to America’s adversaries.
Supply Chain Clarity: A Familiar Direction, Accelerated
For years, defense procurement has been slowly strengthening its requirements for greater transparency in the supply chain, reflecting a growing understanding of the ways that supply chain disruption could imperil national security. Existing procurement rules, including internal Department policies as well as federal law, require contractors to understand the origin of their mission-critical components and protect them from sabotage and disruption, and to share information about how they manage those risks with the Department. The recent executive order builds on that requirement, specifying both the types of risks they must consider—financial, foreign ownership, control, or influence, and manufacturing and supply—as well as significantly greater detail about the supply chain itself.
What should manufacturers make of the decision to include “software” within the iBOM? While specific requirements will be detailed in forthcoming guidance from the Department, we can expect that software, like physical materials, must be traced back to its “origin.” That means that manufacturers will need to account not just for their own code, but also any third-party components included in their product, along with whether the originator of that code exercises “foreign ownership, control, or influence.” We are also likely to see stricter requirements about the contents of the software bill of materials (SBOM), as well as efforts by the Department to evaluate contractor submissions for completeness.
What Product Manufacturers Should Do Today
Even without specific implementation details, the executive order makes the strategic goal clear: manufacturers must know, and be able to clearly communicate, what is in their products. Accordingly, they should take steps to answer four questions starting today:
- What are your current SBOM capabilities? Can you produce a complete accounting of all software components, including third-party software? Can you break those down into subcomponents?
- Do you know the origin of external software in your product? Have you vetted suppliers to assess the supply chain risks defined in the executive order?
- How will you mitigate risk? The executive order requires specific, time-bound mitigation actions for supply chain risks.
- Is your documentation current? Can you document and keep that information up to date across all your products, every time you make an update, release a new feature, or partner with a new supplier?
For the Pentagon, Transparency Is Preparedness
This executive order is the latest example of a clear trend in government procurement: increased transparency in order to head off unexpected disruptions in a time of crisis. A manufacturer cannot entirely eliminate risk, of course, but the government is increasingly expecting manufacturers to communicate the nature of the risks they are managing. Manufacturers must do more than attest to their approach to risk management; they must identify the underlying risks, develop specific mitigations, and allow the government to evaluate the sufficiency of their approach.
This gives a clear advantage to companies that already know what software is inside their products. Those companies will need to be able to produce an SBOM, with evidence to show that it is comprehensive. This will demonstrate the practice of proactive risk management that the recent executive order is trying to encourage, and it will show that companies are prepared to respond quickly to minimize the impact of emerging risks, such as new software vulnerabilities.
The direction is clear, even if additional details will continue to emerge. Full, traceable supply-chain transparency is becoming a condition of selling to the Pentagon, including an accurate, always-updated SBOM. Companies with that capability now will be better prepared for the government guidance and regulations coming next year.
About the Author: Doc McConnell
Doc McConnell is head of policy and compliance at Finite State, where he advises manufacturers on supply-chain and cybersecurity regulations. Before joining Finite State, he led strategic policy development for federal cybersecurity at the Cybersecurity and Infrastructure Security Agency (CISA), helping shape national approaches to securing critical infrastructure and technology supply chains.
The post Enter the iBOM: What the New Defense Supply Chain Order Means for Software appeared first on The National Interest.