Why Hardware Provenance Demands a New Bill of Materials

▶ Watch (0:03)

Friedman opened by taking credit for the SBOM movement and then pivoted to hardware. A single pallet of pagers intercepted before reaching southern Lebanon made the existential case. Counterfeits, vulnerabilities with names like Rowhammer, and active supply-chain tampering are real. The Senate Armed Services Committee spent a year cataloging counterfeits in the DoD supply chain. He summarized: “Step one is we’re going to have to start paying a lot more attention.”

Regulatory Drivers Are Already on the Books

▶ Watch (6:56)

The Bureau of Industry and Security published a rule that no car sold in the US after 2029 can contain any Chinese components. “Does anyone think that we will be able to build a car in 2029 without anything from China? No,” Friedman said. Section 5949 restricts telecom equipment. Congress just passed a law on outbound chip controls. Friedman argued that countries are not good predictors of risk; tracking ownership and jurisdiction is more important. He said “We need a better way” and called for a data layer that separates transparency from risk.

HBOM vs. SBOM: Similar Goals, Harder Problems

▶ Watch (8:44)

HBOM rhymes with SBOM: both separate data from risk, both need to work across diverse sectors from CI/CD pipelines to the A10’s 1970s avionics. But hardware supply chains are longer and more chaotic. Counterfeit chips and shortages force buyers to pay market-cornering prices or rewire PCBs. Verification is expensive. Friedman predicted a growing market for hardware verification startups. He also noted that HBOM must include who touched the physical goods, since a hash of a DIMM is not possible. Different use cases require different levels of assurance, from consumer IoT to aerospace.

Compliance Will Be the Primary Driver

▶ Watch (14:53)

“If you think the US government will not pass a law about country of origin for physical supply chain in the next 6 years and you can convince me, I’ll find another project,” Friedman said. He argued that the security community must front-run regulation by telling policymakers how to implement it efficiently. The CISA framework published in 2023 provides basic roles and taxonomy but no implementation. He listed five target sectors: defense, critical infrastructure, telecom, automotive, and medical devices. Gaps remain, especially linking hardware and software and auditing across third parties.

Next Steps: Institution, Funding, and AI

▶ Watch (23:01)

No single standard can solve the problem today. Friedman suggested using large language models to link heterogeneous data. He called for an institutional home, international participation (HBOM is already in the EU Cyber Resilience Act and Korea’s strategy), and funding. “It’s not going to be brought to you by your friends in the government right now,” he noted. He directed the audience to hbomb.org to join the effort.

Notable Quotes

If you’ve ever heard of an SBOM, there’s a decent chance that’s my fault. If you’ve ever had to make an SBOM, that probably was my fault. Allan Friedman · ▶ 0:08

It’s one thing to say, “My wine’s got grapes.” It’s another thing to say, “My wine’s made with Chardonnay grapes.” Allan Friedman · ▶ 4:00

No car sold in the United States starting in 2029 can have any Chinese components. Allan Friedman · ▶ 8:07

If you think the US government or other major governments will not pass a law about country of origin for physical supply chain in the next 6 years and you can convince me I’ll find another project. Allan Friedman · ▶ 15:02

We’re frontrunning regulation. Allan Friedman · ▶ 15:37

Key Takeaways

  • Hardware supply chains are opaque; HBOMs provide the transparency layer.
  • Multiple regulations (BIS car ban, Section 5949) will force adoption by 2029.
  • The security community must shape HBOM standards before mandates lock in bad policy.

About the Speaker(s)

Allan Friedman is internationally recognized for leading the global Software Bill of Materials (SBOM) movement, transforming it from a niche idea into a widely adopted pillar of cybersecurity policy and practice. Over his decade in public service, Friedman held senior roles at CISA and NTIA, where he built and led groundbreaking efforts on SBOM, coordinated vulnerability disclosure, and IoT security. He has partnered with governments and regulators in Europe and Asia, and continues to advise public- and private-sector organizations on building trust and resilience into the systems that matter most. Before his time in government, Friedman spent over a decade as a researcher and technologist, holding positions at Harvard University’s Computer Science department, the Brookings Institution, and George Washington University’s Engineering School.