Revalidated public source record

CISA Hardware Bill of Materials Framework for Supply Chain Risk Management

Source scope

Official framework providing repeatable component naming, attribute, and format concepts for hardware supply-chain transparency. HBOM completeness and applicability remain product- and contract-specific.

Publisher, edition, and currentness

Source identity and K03 revalidation
PublisherCybersecurity and Infrastructure Security Agency
Claim statusCURRENT TECHNICAL STANDARD
Version or editionSeptember 2023 framework
Publication statusOFFICIAL FRAMEWORK
Publication date2023-09-25
Official locationhttps://www.cisa.gov/resources-tools/resources/hardware-bill-materials-hbom-framework-supply-chain-risk-management
K03 revalidated2026-08-15T23:30:00Z
Currentness assessmentPoint-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.
Superseded byNo successor is assigned in the current source catalog.

Claim-level support

Each row records the precise proposition this corpus draws from an official section. The citation does not authorize broader conclusions than the stated proposition.

Exact sections and supported propositions
SectionProposition supported in this corpusOfficial location
Framework purposeThe framework provides consistent component naming and information structures for communicating hardware composition.Official section

How this source may be used

  • Confirm that the official edition, jurisdiction, and status remain current before high-stakes reliance.
  • Cite the exact section supporting the proposition rather than the publication title alone.
  • Keep technical conformance separate from factual truth, legal authority, moral status, and institutional operation.
  • Record retrieval, correction, supersession, and purpose qualification.

Limitations

An official source can still be irrelevant, incomplete, stale, disputed, or unsuitable for a named decision. A standard can define an interchange or security mechanism without resolving personhood, citizenship, sovereignty, consciousness, consent, legal competence, or factual truth. A statute can regulate systems without recognizing Machine Intelligence as a legal person.

Point-in-time review performed on 2026-08-15 against the cited official or first-party publication location. There is no public runtime monitor and no live-host observation. A reviewed publication does not decide facility applicability, legal interpretation, compliance, licensing, operational authority, or later currentness.

Corrections, contradictions, and supersession

  • No source-specific correction, contradiction, or supersession record is active.

Where this source is used

No related records are assigned in this release.

Authority boundary

Publication by Cybersecurity and Infrastructure Security Agency establishes source provenance and official status within the publisher’s scope. It does not transfer governance, registry, assurance, or legal authority to ᚲ.com. The source remains external; this page is a knowledge record and revalidation log.