SBOM and NIST CSF 2.0: How Component Visibility Maps to the Updated Cybersecurity Framework

NIST released Cybersecurity Framework version 2.0 in March 2024, the first major update since the framework's creation in 2014. The update adds a new sixth function — Govern — and significantly expands the coverage of supply chain cybersecurity risk. For organizations that use the CSF as their security governance framework, understanding how SBOM programs map to the updated controls is essential for demonstrating and communicating supply chain security maturity.

The New Govern Function

CSF 2.0's new Govern function addresses organizational context, risk management strategy, and supply chain risk management at the governance level. Govern category GV.SC (Cybersecurity Supply Chain Risk Management) contains eight subcategories that directly address software supply chain practices. GV.SC-04 requires that suppliers' cybersecurity practices be assessed during acquisition — creating a governance requirement that SBOM-based vendor assessment directly supports. GV.SC-06 requires that software and hardware suppliers are evaluated for their security practices prior to selection — mapping to SBOM-as-procurement-requirement programs.

Identify Function: Asset Management and SBOM

The ID.AM (Asset Management) subcategories in the Identify function require maintaining an accurate inventory of hardware, software, and data assets. ID.AM-02 specifically addresses software assets: "Software assets are inventoried." This maps directly to SBOM generation and maintenance. An SBOM program that generates and stores SBOMs for every application and service in your portfolio provides the evidence base for ID.AM-02 compliance.

Protect and Detect: Vulnerability Management

PR.PS-02 (Software is maintained, replaced, and removed commensurate with risk) and DE.CM-09 (Vulnerabilities in assets are identified and disclosed) map to the vulnerability scanning and alerting functions of an SCA/SBOM program. Continuous SBOM monitoring that alerts when new CVEs affect deployed components directly addresses the detect function's requirements for timely vulnerability identification.

Communicating CSF Maturity with SBOM Data

CSF maturity assessments increasingly include questions about software supply chain security practices. Organizations with mature SBOM programs can provide concrete evidence for multiple CSF categories — asset inventories, vulnerability management metrics, and supply chain risk assessment records — that organizations without SBOM programs must address through manual, harder-to-validate processes.

// Recommended Tool

Map Your SBOM Program to NIST CSF 2.0 with Fossity

Fossity — Fossity provides the asset inventory, vulnerability management, and supply chain security capabilities that map to NIST CSF 2.0's Govern, Identify, Protect, and Detect functions. Build a defensible, auditable security posture aligned with the updated framework.

Visit Fossity.com →
// Author: Esteban C.