← News

New US Executive Order Puts BOMs at the Center of Defense Supply Chains

On July 20, 2026, the White House signed the Executive Order Securing America's Defense Supply Chains and Ensuring Domestic Acquisition of Critical Materials. This is the most consequential Bill of Materials mandate since EO 14028 - and it comes from a different direction: where 14028 mandated cybersecurity SBOMs, this order arrives from the logistics and acquisition side. Defense contractors will be required to submit a complete indentured Bill of Materials tracing "all components, parts, equipment, software, and materials back to the origin of raw materials" - in a standard format, delivered under contract.

Four things make this order different from previous SBOM/xBOM guidance:

  • It explicitly includes software at every tier. The order defines a critical supply chain as all tiers of suppliers providing "goods, materials, systems, software, or services" essential to contract deliverables. Software vendors, cloud providers, and service providers several layers below the prime contractor are in scope - many of whom have never produced a per-release SBOM under contract before.
  • It fuses hardware and software into a single BOM. The indentured Bill of Materials is defined to cover "all the components, parts, equipment, software, and materials" in one traceable structure - effectively an SBOM and HBOM merged. The order's definition lists what must be traced; meeting it in practice will mean attaching supplier identity and material provenance to nodes throughout the tree. The hardware side has its own clock ticking: the restricted materials list under 10 U.S.C. 4872 covers rare-earth magnets, tungsten, tantalum, and molybdenum today, and adds gallium and germanium - foundational to modern semiconductors - in December 2027. Answering "which of our product releases contain a part built on covered-nation gallium?" requires hardware BOMs with the same rigor the industry has spent five years building for software.
  • It has contract-grade teeth. Starting January 1, 2027, waivers for restricted materials under 10 U.S.C. 4872 are sharply curtailed and require formal mitigation plans with a "strict projected timeline" for removing non-compliant components. Failure to qualify alternative sources is grounds for suspending task orders, declining contract options, or terminating contracts outright.
  • It creates an evidence workflow, not a one-time attestation. Contractors must maintain written supplier vetting procedures, notify the Department of War of significant supply chain risks within 15 days, submit corrective action plans within 45 days, file closeout reports, and sustain semi-annual implementation reporting through January 1, 2028 - with implementing regulations expected by April 2027 and flow-down demands from prime contractors likely to start much sooner.

ReARM's architecture maps directly onto what this order asks for. An accumulating pile of static BOM documents cannot answer the questions this order asks, but a release governance platform can: query your entire portfolio for components tied to a restricted material or supplier, diff releases over time to prove that non-compliant components were removed on the committed timeline, and keep mitigation plans, vetting records, and corrective action evidence attached to the exact releases they cover. And because ReARM treats HBOMs as first-class xBOMs alongside SBOMs, a product release can carry its hardware and software bills of materials side by side - the same queries, diffs, and evidence workflow apply whether the component in question is a code dependency or a magnet, a tantalum capacitor, or a gallium-based chip.

To be clear about what tooling can and cannot do here: tracing back to the origin of raw materials is first a data-acquisition problem that lives several tiers down your supply chain - no platform can derive provenance your suppliers never declared. What ReARM does is make that data queryable across your whole portfolio the moment suppliers do declare it, and - just as importantly for the mitigation-plan workflow - show you exactly which nodes in the tree still lack it. On formats: the order leaves the submission format to contract data requirement specifications, and its indentured BOM definition is rooted in provisioning technical data (the MIL-STD-31000 / GEIA-STD-0007 lineage) rather than cyber SBOM practice, so we will monitor what the actual deliverable will be. ReARM speaks CycloneDX, SPDX, and the OWASP Transparency Exchange API today - and whatever deliverable format the regulations land on, generating it will require the same underlying asset: complete, current, per-release BOM data.

For defense contractors and their suppliers, one more detail matters: ReARM CE is fully open source (AGPL-3.0) and self-hostable, and ReARM Pro can likewise be deployed entirely within your own environment, including air-gapped networks.

The implementing regulations are due around April 2027, but prime contractors bear the termination risk - which means BOM and vetting requirements will start appearing in subcontracts and supplier questionnaires well before the rules are final. If your releases might end up anywhere in a defense supply chain, now is the time to get your per-release BOM practice in order. We would love to help - reach out to discuss ReARM Pro or deploy ReARM CE today.