The policy change to record

M-26-05 directs agencies to maintain software and hardware inventories and develop assurance policies matching mission risk. Agencies may choose to use the existing Secure Software Development Attestation Form and may adopt SBOM-on-request terms. Its footnote recommends specifying a runtime production-environment SBOM for cloud platforms when such a term is adopted.

Source: OMB · M-26-05, January 23, 2026.

Earlier summaries of M-22-18 and M-23-16 should be treated as policy history. Executive Order 14028 is important background to the development of SBOM and secure-development guidance, but historical background cannot substitute for the currently controlling agency policy and acquisition terms.

Attestation, inventory and process evidence

Artifact or frameworkQuestion it addressesBuyer implication
Development attestationWhat does the producer assert about its development practices?Check the agency’s current request and accepted form.
SBOMWhat components are described for a release or environment?Specify scope, format, version and delivery.
NIST SSDFWhat secure development practices are being used?Ask for implementation evidence relevant to product risk.
Other assurance artifactsWhat tests, provenance or security evidence is requested?Match each request to the solicitation and mission need.

One artifact does not replace all the others. An inventory is not a development-process attestation, and a signed attestation does not provide a usable component graph.

NIST SSDF status

SP 800-218 SSDF version 1.1 remains the final baseline identified in this build. Version 1.2, SP 800-218 Rev. 1, is listed as an initial public draft dated December 17, 2025. Its comment period is closed; that does not make it final.

Source: NIST · SSDF 1.1, SP 800-218.

Source: NIST · SSDF 1.2, SP 800-218 Rev. 1.

When writing acquisition requirements, state the intended edition and how changes will be handled. Avoid silently upgrading a contractual reference to a draft or assuming a platform can demonstrate secure development merely by exporting an SBOM.

Questions for the actual procurement

  1. Which agency policy and solicitation provisions control this acquisition?
  2. Is an SBOM requested at award, release, incident or another event?
  3. Which software, cloud environment and versions are covered?
  4. Who can receive and process the data, including authorized contractors?
  5. What quality profile, format/version and correction process apply?
  6. Which attestation or additional assurance evidence is requested?
  7. Who resolves a conflict between solicitation terms and supplier standard terms?

Record the answers with document references. Suppliers should obtain clarification from the contracting channel when terms are ambiguous. A general web guide cannot determine the obligations of a specific award.

Translate SBOM-on-request into a workable clause

Define “current” relative to a release, supported version or production snapshot. Specify how rapidly a requested artifact should be delivered, who authenticates the requester, and how exceptions or unavailable information are reported.

For cloud services, avoid a file that describes a development repository while the request concerns production. Agree on the environment boundary and timestamp. High-frequency releases need a delivery cadence and retrieval mechanism the receiving agency can operate.

Require correction tracking and accessible historical evidence where the use case needs it. Establish an incident contact and an inventory-to-product mapping so a component query can produce an actionable answer.

Evidence before supplier selection

Ask for a controlled delivery demonstration. Request the inventory for an identified product version, validate it, inspect its scope and export the result. Confirm that a corrected revision can be linked to the original.

If a vendor advertises “federal compliance,” require the exact policy, clause, product and evidence behind that claim. Federal assurance is shaped by current agency requirements; the presence of an SBOM export button is not a universal certification.

Primary sources