New Defense Order Expands Supply-Chain Transparency to Software Components
An executive order signed on July 20 adds software to the Pentagon’s required “indentured bill of materials,” demanding full traceability of code and its origins.
On July 20, President Donald Trump signed an executive order that broadens the Pentagon’s supply-chain security focus to include software. The rule requires contractors to provide an “indentured bill of materials” (iBOM) that maps every component, down to raw-material origins, and now extends that mapping to all software code and third-party libraries. The aim is to ensure that no part of a defense system relies on vendors with foreign ownership, control or influence that could pose a security risk.
Although the Department of Defense will issue detailed instructions later, manufacturers are advised to evaluate their existing software bill of materials capabilities, confirm the provenance of external code, devise concrete mitigation actions, and maintain continuously updated records. This requirement builds on existing procurement policies that already demand visibility into critical parts, reinforcing a trend toward greater transparency as a safeguard against supply-chain disruptions.
Companies that already maintain comprehensive SBOMs will be better positioned to meet the forthcoming regulations and demonstrate proactive risk management to the government. The order signals that full, traceable supply-chain information will become a prerequisite for future Pentagon contracts.
Why it matters
It forces defense firms to reveal every software piece they use, reducing hidden foreign risks in critical military systems.
In this story