K07 · evidence-bundled critical-infrastructure assurance
Software Bill of Materials
Direct answer
Software Bill of Materials provides bounded component or provenance evidence and must be combined with authenticity, installed-state, vulnerability, custody, and recovery evidence.
Authority and evidence boundary. K07 publishes knowledge architecture, bounded reference records, procurement structures, local validation tools, signed synthetic fixtures, and point-in-time source review. It does not certify a facility, award a contract, authorize an operation, prove truth, establish deployment, or claim current operation.
Artifact class
| Stable ID | SCA-K07-001 |
|---|---|
| Artifact type | SBOM |
Required fields
- supplier
- component name
- version
- unique identifier
- dependency relationship
- author or generator
- timestamp
- format and schema version
Validation expectations
- schema parse
- unique component identity
- dependency closure where available
- artifact hash
- creation-tool identity
- update cadence
Limitations
- does not prove absence of vulnerability
- does not prove installed state
- does not prove authenticity unless separately signed and verified
Source relationships
- NTIA — The Minimum Elements for a Software Bill of Materials — National Telecommunications and Information Administration; July 12, 2021 report; OFFICIAL GUIDANCE. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
- NIST SP 800-161 Revision 1 Update 1 — Cybersecurity Supply Chain Risk Management Practices — National Institute of Standards and Technology; Revision 1 Update 1; FINAL. Exact claim-support entries: 1. Revalidated 2026-08-15T23:30:00Z.
Assurance boundary
Inventory, signature, attestation, supplier status, vulnerability status, and installed configuration remain separate evidence properties. This record does not certify a product or prove that a deployed asset matches its declared bill of materials.