<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Supply Chain Security Roadmap | Haksung</title><link>https://haksungjang.github.io/en/tags/supply-chain-security-roadmap/</link><description>Haksung Jang — Open Source Program Manager at SK telecom</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Wed, 24 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://haksungjang.github.io/en/tags/supply-chain-security-roadmap/index.xml" rel="self" type="application/rss+xml"/><item><title>A Look at the 2026 Software Supply Chain Security Roadmap</title><link>https://haksungjang.github.io/en/research/2026-sw-supply-chain-roadmap/</link><pubDate>Wed, 24 Jun 2026 00:00:00 +0000</pubDate><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Haksung Jang</dc:creator><guid>https://haksungjang.github.io/en/research/2026-sw-supply-chain-roadmap/</guid><description>An analysis of the software supply chain security roadmap the government released on June 24, 2026. Covers the SBOM transparency management model, testbeds and consulting, pilot certification, a rapid detection-and-response system, and burden reduction for small and medium-sized enterprises, and their practical impact on exporting, public-sector, and small and medium-sized software companies.</description><content:encoded>&lt;![CDATA[<div class="alert alert-info" role="alert"><p>This article was written with Claude Code, and the key facts cited here were cross-checked against primary sources.</p></div><blockquote><p><strong>Citation and Commentary Notice.</strong> This article cites and comments on the<em>Software Supply Chain Security Roadmap for the Age of Everyday AI</em> (2026-06-24), publicly published by the Ministry of Science and ICT, the National Intelligence Service, and the Korea Internet &amp; Security Agency, with attribution under Article 28 of the Copyright Act. The tables and diagrams in the original are not reproduced; the narrative and diagrams here are original work based on external primary sources. Attribution: Ministry of Science and ICT, National Intelligence Service, Korea Internet &amp; Security Agency,<em>Software Supply Chain Security Roadmap for the Age of Everyday AI</em>, 2026-06-24.</p></blockquote><blockquote><p><strong>Summary</strong>
On June 24, 2026, the government released a roadmap outlining software supply chain security policy for the next three years. At its core are a transparency management model centered on the Software Bill of Materials (SBOM), a testbed and consulting program to help companies check their security, pilot certification to identify high-performing companies, and a rapid detection-and-response system. Notably, the roadmap places burden reduction for small and medium-sized enterprises throughout, reflecting an industry structure in which 81% of all software companies have fewer than 10 employees. Because the U.S. Food and Drug Administration (FDA)&rsquo;s medical device approval process and the EU Cyber Resilience Act (CRA) have already made SBOMs a condition of market entry, this roadmap bears directly on the practical work of exporting companies, public-sector software vendors, and small and medium-sized software companies.</p></blockquote><h2 id="1-nature-of-the-roadmap-and-background-to-the-announcement">1. Nature of the Roadmap and Background to the Announcement</h2><p>On June 24, 2026, the government released the<em>Software Supply Chain Security Roadmap for the Age of Everyday AI</em> at the Supply Chain Security Workshop held at the aT Center in Yangjae, Seoul<a id="a1-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="b-news-zdnet-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b-news-zdnet">B-news-zdnet</a>. The Ministry of Science and ICT, the National Intelligence Service, and the Korea Internet &amp; Security Agency (KISA) prepared it jointly with related ministries, and KISA is the publisher<a id="a1-ref-2"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. Rather than a law or notice, it is an administrative planning document setting out policy direction for the next three years; many of its individual tasks will gain normative force only after legal and institutional reform, guideline publication, and certification-system reorganization<a id="a1-ref-3"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><p>The announcement followed an already-signaled path. When the government released the<em>SW Supply Chain Security Guideline 1.0</em> in 2024, it stated that it would form a joint industry-academia-research task force in the second half of the year to discuss the direction of institutionalization and then prepare a roadmap<a id="d6-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#d6">D6</a>; after the Ministry of Science and ICT and the National Intelligence Service agreed on December 24, 2025 to build a government-wide cooperation framework<a id="b-news-etnews-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b-news-etnews">B-news-etnews</a>, that process led to this announcement. The government has consistently described 2027 as its target for institutionalization<a id="b-news-zdnet-ref-2"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b-news-zdnet">B-news-zdnet</a>.</p><p>The roadmap declares its vision as &ldquo;securing cyber resilience through a transition to a safe and responsible supply chain security system,&rdquo; converging this into three pillars: prevention, recovery, and foundation<a id="a1-ref-4"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. Beneath these sit three implementation strategies and nine detailed tasks.</p><p><img src="/research/2026-sw-supply-chain-roadmap/strategy-structure-en.png" alt="Under the vision of securing software supply chain cyber resilience sit the three strategies of prevention, recovery, and foundation, each populated with core tasks such as a secure development methodology, integrated public-sector SBOM management, and pilot certification"/><p><strong>Figure 1.</strong> The vision, the three strategies, and each strategy&rsquo;s core tasks<em>(compiled for this report; see §5 for external sources).</em></p><h2 id="2-prevention--building-in-security-and-sbom-transparency">2. Prevention — Building In Security and SBOM Transparency</h2><p>The prevention strategy starts from establishing standards and guidance that build security into the software lifecycle as a whole. The roadmap presents a &ldquo;secure SW development methodology&rdquo; that draws on the National Institute of Standards and Technology (NIST)&rsquo;s Secure Software Development Framework (SSDF, SP 800-218), and states that it will place activities such as defining security requirements, secure coding, vulnerability re-verification, and code signing at each stage — planning and design, development, testing, and deployment<a id="a1-ref-6"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="b5-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b5">B5</a>. Its predecessor, the<em>SW Supply Chain Security Guideline 1.0</em>, will be upgraded to a practically usable 2.0. The direction is to broaden open source management, which had centered on licensing, to cover security as well; to extend development security, which had focused on self-developed code, across the full supply chain; and to newly add the use of automated security compliance tools<a id="a1-ref-7"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="a2-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a2">A2</a>.</p><p>SBOM is the core instrument of the transparency task. An SBOM is a specification that describes information about a software&rsquo;s components; domestically it is also called a &ldquo;software component specification,&rdquo; among other names. The roadmap identifies exporting companies and high-impact sectors as the priority targets for applying the SBOM management model<a id="a1-ref-8"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. For exporting companies, the direct drivers are the U.S. FDA&rsquo;s medical device approval process, the U.S. Department of Commerce&rsquo;s SBOM management obligation for connected vehicles, and the EU CRA&rsquo;s SBOM obligation for products with digital elements<a id="a1-ref-9"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="b7-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b7">B7</a>·<a id="b1-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b1">B1</a>; high-impact sectors include security software, socially foundational software such as finance and transportation, and software handling sensitive information such as health and medical data<a id="a1-ref-10"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><p>The data format is effectively already settled. The International Organization for Standardization (ISO) standardized the Linux Foundation&rsquo;s SPDX as ISO/IEC 5962:2021<a id="c4-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#c4">C4</a>, and OWASP&rsquo;s CycloneDX was standardized as ECMA-424, published in December 2025<a id="c5-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#c5">C5</a>. The roadmap&rsquo;s statement that it will &ldquo;derive the minimum SBOM items so they do not function as dual regulation,&rdquo; made with an eye to the National Telecommunications and Information Administration (NTIA)&rsquo;s<em>The Minimum Elements For a Software Bill of Materials</em> (2021) and the CRA&rsquo;s requirements, is a design aimed at aligning with this international format<a id="a1-ref-11"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="c1-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#c1">C1</a>. Format compatibility is only the starting point; the roadmap itself names verifying SBOM trustworthiness and safely distributing the vulnerability information it contains as remaining tasks<a id="a1-ref-12"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. An SBOM raises transparency but can also reveal to attackers which components carry which vulnerabilities, so designing the right balance between generation and sharing is the key question for the follow-on guidelines<a id="a1-ref-13"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><h2 id="3-recovery--rapid-detection-risk-management-and-reducing-the-burden-on-companies">3. Recovery — Rapid Detection, Risk Management, and Reducing the Burden on Companies</h2><p>The detection-and-response strategy centers on expanding the scope of KISA&rsquo;s security vulnerability reward program (bug bounty), which it has run since October 2012<a id="d2-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#d2">D2</a>, and on progressively expanding Coordinated Vulnerability Disclosure (CVD) and a Vulnerability Disclosure Policy (VDP)<a id="a1-ref-14"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. To introduce security condition inspections for Internet of Things (IoT) appliances such as robot vacuums and IP cameras and for network-connected devices such as solar inverters, the government is pursuing an amendment to the Act on Promotion of Information and Communications Network Utilization and Information Protection, etc. (Network Act)<a id="a1-ref-15"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><p>The risk management system is split into public and private sectors. In the public sector, the government will develop an SBOM management framework that includes Vulnerability Exploitability eXchange (VEX) information at the reliability-assurance stage, and will build an integrated public-sector SBOM management system and a vulnerability information database in stages<a id="a1-ref-16"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. In the private sector, it will establish a standing management framework for high-risk vulnerabilities, and set a goal of shortening the response period &ldquo;from an average of more than four months to within three days&rdquo; through a cleaning service (C-Clean) that, once a vulnerability is found, requests a patch from the manufacturer and performs a mass removal via antivirus software<a id="a1-ref-17"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><p>The support companies actually feel is concentrated in inspection and diagnosis and in the distribution of tools and personnel. The roadmap states that it will expand testbeds where companies can use SBOM generation and vulnerability inspection tools, drawing on existing facilities such as the Development Security Hub and the National Cyber Security Center (NCSC) in Pangyo, and will add checks against global regulations such as medical device approval and the EU CRA to the menu<a id="a1-ref-18"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. For small and medium-sized software development companies, it has placed consulting to analyze and diagnose development infrastructure and management systems starting in 2026, and the distribution of cloud-based development environments and security solutions starting in 2027<a id="a1-ref-19"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. A defining feature of the roadmap overall is that it explicitly states the industry structure — 81% of all software companies have fewer than 10 employees (2023 Software Industry Survey, a total of 43,932 companies by employee-size bracket) — and designs its support accordingly<a id="a1-ref-20"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="d1-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#d1">D1</a>.</p><h2 id="4-foundation--policy-framework-pilot-certification-and-global-cooperation">4. Foundation — Policy Framework, Pilot Certification, and Global Cooperation</h2><p>In the foundation-building strategy, the Ministry of Science and ICT and the National Intelligence Service will jointly chair a (tentatively named) government-wide SW Supply Chain Security Council, organized into five subcommittees: medical devices, automobiles, public information systems, finance, and security<a id="a1-ref-21"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. Pilot certification sits at the center of legal and institutional reform. The government states that it will verify software supply chain security management and issue certificates recognizing high-performing companies (tentatively named SSS Verified, Software Supply-Chain Security Verified), pursue Mutual Recognition Agreements (MRA) with countries that have institutionalized similar systems, and formally institutionalize the framework by incorporating supply chain security testing and evaluation elements into the Information Security Management System certification (ISMS), the Cloud Security Assurance Program (CSAP), and IoT security certification<a id="a1-ref-22"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. It is notable that the government chose to build on existing systems rather than create a separate new certification.</p><p>The changes on the public procurement side are also clear. SBOM submission and vulnerability response procedures, along with a supply chain cybersecurity risk management procedure document, have been added as tasks for informatization projects, and security conformity assessment will widen its scope in consideration of the National Network Security Framework (N2SF) while combining it with confirmation of SBOM submission<a id="a1-ref-23"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="d3-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#d3">D3</a>. N2SF is a multi-tier security approach that applies differentiated security levels according to the importance of the work and data involved; its formal Security Guideline 1.0 was published on September 30, 2025, and reflected in the 2026 cybersecurity assessment<a id="d3-ref-2"/><a href="/en/research/2026-sw-supply-chain-roadmap/#d3">D3</a>·<a id="d-news-boan-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#d-news-boan">D-news-boan</a>.</p><p>The global cooperation task connects to two multilateral bodies. The Global Cybersecurity Labelling Initiative (GCLI), a coalition that discusses mutual recognition of IoT security certification labels and the establishment of a single standard, launched with 11 founding members at Singapore International Cyber Week on October 23, 2025, with Korea&rsquo;s Ministry of Science and ICT and KISA participating as founding members<a id="a10-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a10">A10</a>. Alongside this, the roadmap presents cooperation with the Global Government Expert Forum (GGEF), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the European Commission&rsquo;s Directorate-General for Communications Networks, Content and Technology (DG CONNECT), and the UK Department for Science, Innovation and Technology (DSIT) as channels for supporting global expansion<a id="a1-ref-24"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><p><img src="/research/2026-sw-supply-chain-roadmap/global-to-domestic-en.png" alt="The correspondence between four overseas regimes facing exporting companies and the four domestic tasks the roadmap sets against them. The axis running from the FDA and the EU CRA, which directly mandate SBOM submission, to the SBOM management model sits at the center"/><p><strong>Figure 2.</strong> The correspondence between the global regimes the roadmap references and its policy tasks<em>(compiled for this report; see §5 for external sources).</em></p><p>The roadmap separates its response to emerging technologies into a distinct research task. It places research on a supply chain security model that responds to the everyday normalization of emerging technologies such as AI as a task for 2027 and beyond<a id="a1-ref-25"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>, and the data layer of an SBOM for AI (training data, model weights, and the like) falls outside the direct scope of this roadmap, which centers on the general software supply chain.</p><h2 id="5-the-background-shaped-by-global-regulation">5. The Background Shaped by Global Regulation</h2><p>Behind the roadmap&rsquo;s choice of SBOM, pilot certification, and mutual recognition as its core instruments lies the overseas regulation exporting companies face. A company interview the roadmap quotes shows this plainly. A digital medical device manufacturer struggled to respond to SBOM requirements during the FDA approval process; a security company that had entered the U.S. market was notified, while supplying software to the federal government, that failing to meet SBOM management requirements would make it ineligible for next year&rsquo;s contract; and an AI solution developer lost a contract during preparations to supply a global financial company because it failed to meet cybersecurity requirements<a id="a1-ref-26"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><p><img src="/research/2026-sw-supply-chain-roadmap/regulation-timeline-en.png" alt="A timeline from the U.S. Executive Order 14028 in 2021 to the full application of the EU Cyber Resilience Act in 2027. The period following the domestic roadmap’s announcement in June 2026 overlaps with these regulatory deadlines"/><p><strong>Figure 3.</strong> The overseas regulation behind the roadmap and the deadlines ahead<em>(compiled for this report; see §7 for sources).</em></p><p>Most of these regulations were finalized between 2021 and 2024. The EU Cyber Resilience Act (Regulation (EU) 2024/2847) is a regulation that imposes horizontal cybersecurity requirements on products with digital elements, and it entered into force on December 10, 2024<a id="b1-ref-2"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b1">B1</a>·<a id="b2-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b2">B2</a>. The Article 14 reporting obligation applies from September 11, 2026, and the essential obligations as a whole, including conformity assessment and CE marking, apply from December 11, 2027<a id="b2-ref-2"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b2">B2</a>. Manufacturers bear the obligation to produce an SBOM for products with digital elements, to handle vulnerabilities across the full lifecycle, and to issue an early warning within 24 hours and notify within 72 hours of becoming aware of an actively exploited vulnerability or a severe incident<a id="b1-ref-3"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b1">B1</a>. Penalties for violation run up to €15 million or 2.5% of worldwide annual turnover, whichever is higher<a id="b1-ref-4"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b1">B1</a>. The roadmap&rsquo;s recurring &ldquo;scheduled for &lsquo;27.12 implementation&rdquo; refers to this date of full application<a id="a1-ref-27"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><p>U.S. supply chain regulation began with Executive Order 14028 (Improving the Nation&rsquo;s Cybersecurity), signed on May 12, 2021, which led to institutionalizing SBOM as a federal procurement requirement and directed NIST to draw up the SSDF<a id="b3-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b3">B3</a>·<a id="b5-ref-2"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b5">B5</a>. CISA finalized the Secure Software Development Attestation Common Form on March 11, 2024<a id="b4-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b4">B4</a>. Medical device regulation began when Section 3305 of the 2022 Consolidated Appropriations Act added a new Section 524B to the Federal Food, Drug, and Cosmetic Act (FD&amp;C Act); the amended provision took effect on March 29, 2023<a id="b7-ref-2"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b7">B7</a>. Manufacturers filing a premarket submission must submit a postmarket vulnerability management plan, secure-by-design documentation, and an SBOM covering commercial, open source, and off-the-shelf components<a id="b7-ref-3"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b7">B7</a>. In the consumer IoT space, the U.S. Federal Communications Commission (FCC) adopted a voluntary labeling program (the U.S. Cyber Trust Mark) on March 14, 2024<a id="b8-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b8">B8</a>, and the UK brought the Product Security and Telecommunications Infrastructure Act 2022 (PSTI) into force on April 29, 2024<a id="b9-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b9">B9</a>. These are the &ldquo;U.S. Cyber Trust Mark&rdquo; and &ldquo;UK PSTI (effective &lsquo;24.4)&rdquo; the roadmap cites in its post-market management task<a id="a1-ref-28"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><h2 id="6-implications-and-considerations">6. Implications and Considerations</h2><h3 id="61-exporting-companies--sbom-is-already-a-market-entry-condition">6.1 Exporting Companies — SBOM Is Already a Market Entry Condition</h3><p>With the FDA&rsquo;s medical device approval process and the EU CRA having effectively made SBOM management a condition of market entry, the government&rsquo;s inspection support and its push for mutual recognition offer direct value to exporting companies<a id="a1-ref-29"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="b1-ref-5"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b1">B1</a>·<a id="b7-ref-4"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b7">B7</a>. Because the EU CRA&rsquo;s reporting obligation begins September 11, 2026, and full application begins December 11, 2027<a id="b2-ref-3"/><a href="/en/research/2026-sw-supply-chain-roadmap/#b2">B2</a>, exporting companies are safer preparing their SBOM generation and vulnerability reporting systems ahead of time on the CRA&rsquo;s own schedule, rather than waiting for Korea&rsquo;s MRA to be concluded. An MRA requires the counterpart country to recognize Korean certification as equivalent, and the roadmap itself only describes the MRA as being &ldquo;pursued,&rdquo; without offering a timeline for agreement<a id="a1-ref-30"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><h3 id="62-public-sector-software-vendors--sbom-submission-becomes-a-standing-requirement">6.2 Public-Sector Software Vendors — SBOM Submission Becomes a Standing Requirement</h3><p>In the public sector, SBOM submission and vulnerability response procedures for informatization projects have been explicitly set as tasks, and confirmation of SBOM submission is combined with security conformity assessment and the transition to N2SF<a id="a1-ref-31"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="d3-ref-3"/><a href="/en/research/2026-sw-supply-chain-roadmap/#d3">D3</a>. Companies supplying software to the public sector need to prepare by integrating SBOM generation into their build pipeline. Since the policy is to derive public-sector SBOM items at a minimum so they do not become dual regulation<a id="a1-ref-32"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>, it is practically useful to check the follow-on guidelines for how alignment with overseas requirements is actually designed.</p><h3 id="63-small-and-medium-sized-software-companies--whether-support-is-sufficient-is-the-question">6.3 Small and Medium-Sized Software Companies — Whether Support Is Sufficient Is the Question</h3><p>In an industry structure where 81% of all software companies have fewer than 10 employees<a id="a1-ref-33"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>·<a id="d1-ref-2"/><a href="/en/research/2026-sw-supply-chain-roadmap/#d1">D1</a>, it is difficult for these companies to bear on their own the tools and personnel needed for SBOM generation and vulnerability management. The roadmap places consulting and the distribution of cloud-based development environments and security solutions as its support measures, but no figures are given for whether the scale of distribution and the budget will actually cover the majority of the roughly 40,000 companies involved<a id="a1-ref-34"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. Whether the support is sufficient is an area that future budget allocation will decide.</p><h3 id="64-remaining-risks">6.4 Remaining Risks</h3><p>There is a risk from dependence on external infrastructure. The contract between MITRE, which operates the U.S. Common Vulnerabilities and Exposures (CVE) program, and CISA came within a day of expiring on April 16, 2025, before an 11-month extension patched things over, and the CVE Board confirmed on January 21, 2026 that &ldquo;there will be no March funding cliff&rdquo;<a id="e6-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#e6">E6</a>·<a id="f-news-cso-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#f-news-cso">F-news-cso</a>. The immediate crisis was averted, but the structural instability of a global vulnerability identification system that depends on the U.S. government&rsquo;s budget remains unchanged, which makes the roadmap&rsquo;s inclusion of finding an alternative program as a task a reasonable precaution<a id="a1-ref-35"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>.</p><p>The readiness of the development field is another variable. According to Black Duck&rsquo;s survey of the state of DevSecOps, conducted among 1,001 professionals worldwide in July and August 2025, 45.56% still handle putting new code through security testing manually<a id="h1-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#h1">H1</a>. Speed has become the standard while security automation has not kept pace, and this gap overlaps with the problem the roadmap identifies in its plan to shift from human-centered manual response to an AI-centered autonomous system<a id="a1-ref-36"/><a href="/en/research/2026-sw-supply-chain-roadmap/#a1">A1</a>. If SBOM generation and vulnerability inspection are not integrated into an automated pipeline, mandating them risks becoming, on the ground, an added burden of manual work.</p><p>As a side note, the estimate of global damage from supply chain attacks that the roadmap attributes to &ldquo;Gartner (&lsquo;24.6)&rdquo; — $46 billion in 2023, projected to reach $138 billion by 2031 — is actually a Cybersecurity Ventures estimate<a id="e4-ref-1"/><a href="/en/research/2026-sw-supply-chain-roadmap/#e4">E4</a>.</p><hr><h2 id="7-references">7. References</h2><p>This section lists the items cited in the text as<code>[A1]</code> and similar. All URLs were accessed on 2026-06-24. Government and institutional sites sometimes return a bot block to automated crawling tools; these are not dead links, and such items were cross-checked using existing verification assets or WebSearch.</p><h3 id="subject-of-analysis-and-domestic-prior-documents">Subject of Analysis and Domestic Prior Documents</h3><p><a id="a1"/><strong>A1.</strong> Ministry of Science and ICT, National Intelligence Service, and Korea Internet &amp; Security Agency, joint (2026).<em>Software Supply Chain Security Roadmap for the Age of Everyday AI</em>. Published by the Korea Internet &amp; Security Agency (Naju), 1st edition, 1st printing, 2026-06-24. 30 pages, CC BY-NC-ND 2.0 KR. Released on the day of the announcement (2026-06-24, Supply Chain Security Workshop, aT Center, Yangjae); a fixed direct PDF link was not yet available, but it can be found via the Ministry of Science and ICT press release (<a href="https://www.msit.go.kr/bbs/list.do?sCode=user&amp;mId=307&amp;mPid=208">https://www.msit.go.kr/bbs/list.do?sCode=user&mId=307&mPid=208</a>) and the KISA resource library. —<em>Use: the publicly released government roadmap that is the subject of this article&rsquo;s citation and commentary. Cited with attribution; the original&rsquo;s tables and diagrams are not reproduced.</em><a href="#a1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a2"/><strong>A2.</strong> Ministry of Science and ICT, National Intelligence Service, and Presidential Committee on Digital Platform Government (2024).<em>SW Supply Chain Security Guideline 1.0</em> (summary, 2024-05-13). Published in the KISA resource library.<a href="https://www.kisa.or.kr/2060204/form?postSeq=15">https://www.kisa.or.kr/2060204/form?postSeq=15</a> (accessed 2026-06-24; publishing entity and SSDF, SBOM, and stage-by-stage inspection content cross-checked via WebSearch). —<em>Use: the direct predecessor document the roadmap states it will upgrade to 2.0.</em><a href="#a2-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="a10"/><strong>A10.</strong> Cyber Security Agency of Singapore et al. (2025).<em>Joint Statement on the Global Cybersecurity Labelling Initiative (GCLI)</em>. Launched 2025-10-23.<a href="https://www.csa.gov.sg/news-events/press-releases/joint-statement-on-the-global-cybersecurity-labelling-initiative/">https://www.csa.gov.sg/news-events/press-releases/joint-statement-on-the-global-cybersecurity-labelling-initiative/</a> (accessed 2026-06-24; launch date, 11 founding members, and Korea&rsquo;s participation cross-checked via WebSearch). —<em>Use: confirms the GCLI&rsquo;s launch, composition, and Korea&rsquo;s participation.</em><a href="#a10-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="primary-texts-of-global-laws-and-regulations">Primary Texts of Global Laws and Regulations</h3><p><a id="b1"/><strong>B1.</strong> European Parliament and Council (2024).<em>Regulation (EU) 2024/2847 — Cyber Resilience Act</em>. Official Journal of the EU, OJ L, 2024/2847, 20.11.2024.<a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng">https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng</a> (accessed 2026-06-24; reconfirmed against the<code>eu-cra-vulnerability-reporting</code> workspace verification asset). —<em>Use: primary basis for the CRA&rsquo;s SBOM and vulnerability obligations, reporting deadlines (24h/72h), penalties, and effective dates.</em><a href="#b1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b2"/><strong>B2.</strong> European Commission, DG CNECT (2026).<em>Cyber Resilience Act — Shaping Europe&rsquo;s digital future</em>.<a href="https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act">https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act</a> (accessed 2026-06-24). —<em>Use: primary confirmation of the implementation schedule (entry into force 2024-12-10, reporting obligation 2026-09-11, full application 2027-12-11).</em><a href="#b2-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b3"/><strong>B3.</strong> The White House (2021).<em>Executive Order 14028 — Improving the Nation&rsquo;s Cybersecurity</em>. Federal Register, 86 FR 26633, 2021-05-17.<a href="https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity">https://www.federalregister.gov/documents/2021/05/17/2021-10460/improving-the-nations-cybersecurity</a> (accessed 2026-06-24, 200 OK). —<em>Use: primary basis for making SBOM a federal procurement requirement and directing NIST to draw up the SSDF.</em><a href="#b3-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b4"/><strong>B4.</strong> CISA (2024).<em>Secure Software Development Attestation Common Form</em> (Final). Released 2024-03-11.<a href="https://www.cisa.gov/secure-software-attestation-form">https://www.cisa.gov/secure-software-attestation-form</a> (accessed 2026-06-24; cisa.gov returned a bot block, release date cross-checked via WebSearch). —<em>Use: the U.S. federal procurement SSDF self-attestation obligation. The roadmap&rsquo;s &ldquo;&lsquo;23.6~&rdquo; notation refers to when the policy was discussed; the form itself was released in 2024-03.</em><a href="#b4-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b5"/><strong>B5.</strong> NIST — Souppaya, M., Scarfone, K., Dodson, D. (2022).<em>Secure Software Development Framework (SSDF) Version 1.1</em>. NIST SP 800-218. DOI: 10.6028/NIST.SP.800-218.<a href="https://csrc.nist.gov/pubs/sp/800/218/final">https://csrc.nist.gov/pubs/sp/800/218/final</a> (accessed 2026-06-24). —<em>Use: the framework the roadmap&rsquo;s &ldquo;secure SW development methodology&rdquo; directly references.</em><a href="#b5-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b7"/><strong>B7.</strong> U.S. Food and Drug Administration / Federal Register (2023).<em>Cybersecurity in Medical Devices: Quality System Considerations and Content of Premarket Submissions</em> (FD&amp;C Act §524B, added by §3305 of the 2022 Consolidated Appropriations Act, effective 2023-03-29).<a href="https://www.federalregister.gov/documents/2023/09/27/2023-20955/cybersecurity-in-medical-devices-quality-system-considerations-and-content-of-premarket-submissions">https://www.federalregister.gov/documents/2023/09/27/2023-20955/cybersecurity-in-medical-devices-quality-system-considerations-and-content-of-premarket-submissions</a> (accessed 2026-06-24, 200 OK). —<em>Use: primary basis for the FDA&rsquo;s medical device SBOM requirement.</em><a href="#b7-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b8"/><strong>B8.</strong> Federal Communications Commission (2024).<em>Cybersecurity Labeling for Internet of Things — Report and Order (FCC 24-26)</em> (U.S. Cyber Trust Mark). Adopted 2024-03-14.<a href="https://www.federalregister.gov/documents/2024/03/25/2024-06249/cybersecurity-labeling-for-internet-of-things">https://www.federalregister.gov/documents/2024/03/25/2024-06249/cybersecurity-labeling-for-internet-of-things</a> (accessed 2026-06-24, 200 OK). Program hub:<a href="https://www.fcc.gov/CyberTrustMark">https://www.fcc.gov/CyberTrustMark</a>. —<em>Use: primary basis for the U.S. voluntary IoT labeling program.</em><a href="#b8-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b9"/><strong>B9.</strong> UK Government / DSIT (2022/2024).<em>Product Security and Telecommunications Infrastructure (PSTI) Act 2022, Part 1</em> (effective 2024-04-29).<a href="https://www.gov.uk/government/publications/the-uk-product-security-and-telecommunications-infrastructure-product-security-regime">https://www.gov.uk/government/publications/the-uk-product-security-and-telecommunications-infrastructure-product-security-regime</a> (accessed 2026-06-24; effective date and penalty cap cross-checked via WebSearch). —<em>Use: primary basis for the UK&rsquo;s mandatory PSTI regulation.</em><a href="#b9-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="standards-and-guidance">Standards and Guidance</h3><p><a id="c1"/><strong>C1.</strong> U.S. Department of Commerce / NTIA (2021).<em>The Minimum Elements For a Software Bill of Materials (SBOM)</em>. 2021-07-12.<a href="https://www.ntia.gov/files/ntia/publications/sbom_minimum_elements_report.pdf">https://www.ntia.gov/files/ntia/publications/sbom_minimum_elements_report.pdf</a> (accessed 2026-06-24; ntia.gov blocked the crawler, reconfirmed against the<code>sbom-guide</code> and<code>g7-sbom-for-ai</code> workspace verification assets). —<em>Use: the baseline for the roadmap&rsquo;s &ldquo;deriving minimum SBOM items.&rdquo;</em><a href="#c1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="c4"/><strong>C4.</strong> The Linux Foundation / SPDX Project.<em>SPDX Specifications</em> (current version SPDX 3.0, standardized as ISO/IEC 5962:2021).<a href="https://spdx.dev/use/specifications/">https://spdx.dev/use/specifications/</a> (accessed 2026-06-24, 200 OK, verified against<code>sbom-guide</code>). —<em>Use: an SBOM standard format. Basis for global compatibility.</em><a href="#c4-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="c5"/><strong>C5.</strong> OWASP Foundation / Ecma International (2025).<em>CycloneDX Specification / ECMA-424</em> (published 2025-12-10).<a href="https://cyclonedx.org/specification/overview/">https://cyclonedx.org/specification/overview/</a> (accessed 2026-06-24, 200 OK, verified against<code>sbom-guide</code>). —<em>Use: an SBOM standard format.</em><a href="#c5-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="domestic-institutions-and-statistics">Domestic Institutions and Statistics</h3><p><a id="d1"/><strong>D1.</strong> Ministry of Science and ICT and the Korea Association for ICT Promotion (KAIT) (2024).<em>2023 Software Industry Survey</em> (a nationally approved statistic). Statistics portal SWSTAT:<a href="https://stat.spri.kr/">https://stat.spri.kr/</a> (accessed 2026-06-24; publishing body and the nature of the statistic confirmed via WebSearch). —<em>Use: basis for the publishing framework behind the roadmap&rsquo;s statistic that &ldquo;81% of software companies have fewer than 10 employees (43,932 companies in total).&rdquo; The 81% figure and the 43,932 count are attributed to the roadmap&rsquo;s citation, as direct comparison against the survey&rsquo;s original tables was not completed.</em><a href="#d1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="d2"/><strong>D2.</strong> Korea Internet &amp; Security Agency (KISA) / KrCERT (2012–).<em>Security Vulnerability Reward Program (Bug Bounty)</em>.<a href="https://www.krcert.or.kr/kr/bbs/list.do?menuNo=205027">https://www.krcert.or.kr/kr/bbs/list.do?menuNo=205027</a> (accessed 2026-06-24; October 2012 program start and quarterly evaluation cross-checked via WebSearch). —<em>Use: basis for the existing program the roadmap&rsquo;s detection-and-response task expands.</em><a href="#d2-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="d3"/><strong>D3.</strong> National Intelligence Service · National Cyber Security Center (2025).<em>National Network Security Framework (N2SF) Security Guideline</em>, formal edition 1.0 (published 2025-09-30).<a href="https://www.nis.go.kr/CM/1_4/view.do?seq=373">https://www.nis.go.kr/CM/1_4/view.do?seq=373</a> (accessed 2026-06-24; publication date and tiered security-level system cross-checked via WebSearch). —<em>Use: basis for the roadmap&rsquo;s expansion of the scope of security conformity assessment (N2SF).</em><a href="#d3-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="d6"/><strong>D6.</strong> Presidential Committee on Digital Platform Government (2024).<em>Government Announces &lsquo;SW Supply Chain Security Guideline 1.0&rsquo;</em> (press release, 2024-05-13).<a href="https://www.dpg.go.kr/DPG/contents/DPG02020000.do?schM=view&amp;id=20240513105420991857&amp;schBcid=press">https://www.dpg.go.kr/DPG/contents/DPG02020000.do?schM=view&id=20240513105420991857&schBcid=press</a> (accessed 2026-06-24; the announcement date of 2024-05-13 and the text&rsquo;s plan for &ldquo;preparing a roadmap through a government-wide joint task force in the second half of the year&rdquo; cross-checked via WebSearch). —<em>Use: primary announcement of the background to Guideline 1.0&rsquo;s release and the &ldquo;plan to prepare a roadmap through a second-half joint task force.&rdquo;</em><a href="#d6-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="original-sources-of-statistics-cited-by-the-roadmap">Original Sources of Statistics Cited by the Roadmap</h3><p><a id="e4"/><strong>E4.</strong> Cybersecurity Ventures (2024).<em>Software Supply Chain Attacks To Cost The World $60 Billion By 2025</em>.<a href="https://cybersecurityventures.com/software-supply-chain-attacks-to-cost-the-world-60-billion-by-2025/">https://cybersecurityventures.com/software-supply-chain-attacks-to-cost-the-world-60-billion-by-2025/</a> (accessed 2026-06-24; the $46 billion figure for 2023 and $138 billion for 2031 confirmed via WebSearch). —<em>Use: the actual original source of the roadmap&rsquo;s supply chain damage statistic. The roadmap&rsquo;s attribution to &ldquo;Gartner (&lsquo;24.6)&rdquo; is inaccurate and is corrected here to Cybersecurity Ventures.</em><a href="#e4-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="e6"/><strong>E6.</strong> MITRE / CISA (2025). Background on the CVE program&rsquo;s contract expiration and extension. Cybersecurity Dive (2025-04):<a href="https://www.cybersecuritydive.com/news/cisa-extend-funding-cve/745531/">https://www.cybersecuritydive.com/news/cisa-extend-funding-cve/745531/</a> (accessed 2026-06-24; the $57.8 million contract, 2025-04-16 expiration, 11-month extension, and the founding of the CVE Foundation confirmed via WebSearch). Program site:<a href="https://www.cve.org/">https://www.cve.org/</a>. —<em>Use: background for the roadmap&rsquo;s task of finding an alternative to the CVE program. Supplementary press source.</em><a href="#e6-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="news-and-industry-coverage">News and Industry Coverage</h3><p><a id="b-news-etnews"/><strong>B-news-etnews.</strong> ETNews (2025-12-24).<em>Ministry of Science and ICT and National Intelligence Service Join Hands on SW Supply Chain Security… Build Government-Wide Cooperation Framework</em>.<a href="https://www.etnews.com/20251224000334">https://www.etnews.com/20251224000334</a> (accessed 2026-06-24). —<em>Use: confirms the timing of the government-wide cooperation agreement (2025-12-24).</em><a href="#b-news-etnews-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="b-news-zdnet"/><strong>B-news-zdnet.</strong> ZDNet Korea (2026-06-16).<em>Government to Release SW Supply Chain Security Roadmap on the 24th</em>.<a href="https://zdnet.co.kr/view/?no=20260616111556">https://zdnet.co.kr/view/?no=20260616111556</a> (accessed 2026-06-24). —<em>Use: primary confirmation of the announcement date (2026-06-24), the responsible bodies (Ministry of Science and ICT, National Intelligence Service), the location (aT Center, Yangjae), and the 2027 institutionalization target.</em><a href="#b-news-zdnet-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="d-news-boan"/><strong>D-news-boan.</strong> Boannews (2026).<em>From NIS Security Conformity Assessment to N2SF… What&rsquo;s Changed in the Paradigm?</em>.<a href="https://m.boannews.com/html/detail.html?tab_type=1&amp;idx=140209">https://m.boannews.com/html/detail.html?tab_type=1&idx=140209</a> (accessed 2026-06-24). —<em>Use: coverage of the transition from security conformity assessment to N2SF and its incorporation into the 2026 cybersecurity assessment.</em><a href="#d-news-boan-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><p><a id="f-news-cso"/><strong>F-news-cso.</strong> CSO Online (2026).<em>CVE program funding secured, easing fears of repeat crisis</em>.<a href="https://www.csoonline.com/article/4142600/cve-program-funding-secured-easing-fears-of-repeat-crisis.html">https://www.csoonline.com/article/4142600/cve-program-funding-secured-easing-fears-of-repeat-crisis.html</a> (accessed 2026-06-24). —<em>Use: confirms the CVE Board&rsquo;s January 21, 2026 statement of &ldquo;no March funding cliff.&rdquo;</em><a href="#f-news-cso-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p><h3 id="development-field-trends">Development-Field Trends</h3><p><a id="h1"/><strong>H1.</strong> Black Duck (2025).<em>Balancing AI Usage and Risk in 2025: The Global State of DevSecOps</em> (October 2025). The survey was conducted by Censuswide among 1,001 professionals worldwide in July–August 2025. —<em>Use: the security automation gap in the development field (45.56% still handled manually).</em><a href="#h1-ref-1" onclick="event.preventDefault(); history.back(); return false;" title="Back to text">↩</a></p>
]]></content:encoded></item></channel></rss>