<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>EO 14028 | Haksung</title><link>https://haksungjang.github.io/en/tags/eo-14028/</link><description>Haksung Jang — Open Source Program Manager at SK telecom</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Sun, 09 Aug 2026 22:27:14 +0900</lastBuildDate><atom:link href="https://haksungjang.github.io/en/tags/eo-14028/index.xml" rel="self" type="application/rss+xml"/><item><title>Regulatory Trends</title><link>https://haksungjang.github.io/en/docs/sbom_guide/3-regulation/</link><pubDate>Sun, 09 Aug 2026 22:27:14 +0900</pubDate><guid>https://haksungjang.github.io/en/docs/sbom_guide/3-regulation/</guid><description>Summarizes the regulatory standing of SBOM across jurisdictions, and the US executive order and federal procurement pathway.</description><content:encoded>&lt;![CDATA[<p>The regulatory standing of SBOM differs by jurisdiction. The United States takes an executive-order
pathway that leverages federal procurement, the European Union takes a directly effective
legislative pathway, and most other countries remain at the stage of advisory guidelines. This
section covers the United States first, followed by the<a href="/en/docs/sbom_guide/3-regulation/1-eu-cra/">EU Cyber Resilience Act</a> and<a href="/en/docs/sbom_guide/3-regulation/2-global/">other jurisdictions such as India and Korea</a>.</p><h2 id="regulatory-standing-by-jurisdiction-at-a-glance">Regulatory Standing by Jurisdiction at a Glance</h2><table><thead><tr><th>Jurisdiction</th><th>Document/Legislation</th><th>Standing</th><th>SBOM Requirement</th></tr></thead><tbody><tr><td>United States</td><td>Executive Order 14028 (2021), CISA minimum elements</td><td>Federal procurement recommendation</td><td>SBOM provision for software delivered to the federal government</td></tr><tr><td>European Union</td><td>Cyber Resilience Act, Regulation (EU) 2024/2847</td><td>Legal obligation (with fines)</td><td>Annex I Part II, top-level dependencies, machine-readable</td></tr><tr><td>India</td><td>CERT-In Technical Guidelines (2024)</td><td>Voluntary recommendation</td><td>Best practices for government and essential services</td></tr><tr><td>Korea</td><td>Software Supply Chain Security Guideline 1.0 (2024)</td><td>Administrative recommendation</td><td>Recommended SBOM generation and review procedures</td></tr></tbody></table><p><strong>Table 1.</strong> SBOM regulatory standing in major jurisdictions<em>(source: primary source for each
item; collected June 14, 2026)</em></p><h2 id="united-states-leveraging-federal-procurement">United States: Leveraging Federal Procurement</h2><p>US SBOM policy originates from an executive order. On May 12, 2021, shortly after the SolarWinds
incident, Executive Order 14028 (&ldquo;Improving the Nation&rsquo;s Cybersecurity&rdquo;) was signed and published
in the Federal Register as 86 FR 26633. Section 10(j) of the order defined SBOM as &ldquo;a formal record
containing the details and supply chain relationships of various components used in building
software,&rdquo; and Section 4(f) directed the Secretary of Commerce, working with NTIA, to publish
minimum elements for an SBOM within 60 days. This was the moment SBOM was elevated from a
recommendation of the research community to a candidate requirement for federal procurement.</p><p>Under this mandate, NTIA published the minimum elements in July 2021, and responsibility for the
work subsequently moved to CISA. Under Office of Management and Budget (OMB) Memorandum M-22-18,
CISA holds the authority to update the NTIA minimum elements and has focused on tooling and
operationalization. The results are the 2024<em>Framing Software Component Transparency</em>, Third
Edition, and the 2025 draft revision of the minimum elements. Changes in the data fields between
the two documents are covered in<a href="/en/docs/sbom_guide/2-standards/1-minimum-elements/">Minimum Elements</a>.</p><p>It is important to understand the exact nature of the US pathway. Executive Order 14028 is the
basis for guidance requiring vendors that supply software to the federal government to provide an
SBOM; it is not a general statute that applies to all software. CISA&rsquo;s two documents themselves
state that they do not create new federal requirements. The normative standing remains that of a
procurement criterion and technical reference. Nonetheless, because the vast federal procurement
market operates on this basis, it functions as a de facto requirement for companies that supply
software to the US government.</p><p><img src="/docs/sbom_guide/3-regulation/us-policy-lineage-en.png" alt="The lineage of US SBOM policy, starting from Executive Order 14028 and the NTIA minimum elements in 2021, transferring to CISA, and branching into the 2024 Framing Third Edition and the 2025 draft revision of the minimum elements"/><p><strong>Figure 1.</strong> Lineage of US SBOM policy documents<em>(source: Executive Order 14028, NTIA 2021, CISA
2024 and 2025; collected June 14, 2026)</em></p><h2 id="sources">Sources</h2><p>The White House (2021).<em>Executive Order 14028 — Improving the Nation&rsquo;s Cybersecurity</em>, 86 FR
26633.<a href="https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity">https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity</a>.
OMB (2022).<em>M-22-18</em>.<a href="https://www.whitehouse.gov/wp-content/uploads/2022/09/M-22-18.pdf">https://www.whitehouse.gov/wp-content/uploads/2022/09/M-22-18.pdf</a>. CISA SBOM Resource Hub<a href="https://www.cisa.gov/sbom">https://www.cisa.gov/sbom</a>. (all accessed: June 14, 2026)</p>
]]></content:encoded></item></channel></rss>