Instrument 30 | D. CERT-In / Cybersecurity / AI Security

TECHNICAL PAPERTECHNICAL GUIDELINE

CERT-In - Technical Guidelines on SBOM, QBOM & CBOM, AIBOM & HBOM - Version 2.0

CERT-In / MeitY2025Technical GuidelineTechnology

AI / PRIVACY / CYBER RELEVANCE

AI BOM is directly relevant to model/dependency provenance, training/data components, vulnerability management and AI supply-chain assurance.

AI: Very HighPrivacy: HighCybersecurity: Very High

READ FIRST

  • AIBOM section
  • inventory of AI models/components/data sources
  • transparency and vulnerability management

PURVIEW

Addresses software- and component-transparency through bills of materials, including SBOM, QBOM, CBOM, AIBOM and HBOM concepts. Its relevance to AI regulation is substantial because AI systems increasingly depend on complex combinations of source code, packages, hardware, models, datasets and external components. An AIBOM-oriented approach can improve traceability of model and AI dependencies, while SBOM and related inventories support vulnerability management and incident response. For privacy and security, the document helps organisations know what components process or expose data, identify dependency risks and establish a defensible asset inventory for audits, patching and supply-chain assurance.

Classification and legal status. Technical guideline / supply-chain guidance; not a universal statute.

Open document Download PDF Copyright remains with the publishing authority. For informational purposes only.

Read the official document

This browser cannot display the PDF in the page. Open the document or download the PDF.

Keywords

SBOMAIBOMsupply chainprovenancevulnerability management

Source note

CERT-In Version 2.0, dated 09 July 2025, reviewed.

Legal status indicates whether this resource is legislation, delegated regulation, regulatory direction, guidance, policy, research or technical material. Inclusion in this library does not by itself make a document legally binding.

This tool provides research navigation only and does not constitute legal advice or a determination of legal applicability.

Back to the framework library