Federal SBOM delivery clauses are met, but nobody in the agency reads the SBOMs — how do you fix that?
answer
- Compliance met, capability absent
- Nobody owns the pipe between the parties
- Work backwards from one answerable question
- Delivery to a system, not an inbox
- Asking for the unusable is pure cost
basics
~20 sStop treating the clause as the goal. Name the question the documents were meant to answer, fund one owner accountable for answering it, then rewrite the clause to specify format, delivery target and refresh trigger.
solid answer
~50 sThe clause was satisfied and nothing was bought, which is the honest diagnosis: a procurement condition purchases a document, never an outcome. Start by naming the capability the mandate was reaching for — being able to say, within hours of a disclosure, whether a component is in anything you run — and accept that no contract language produces it without a funded owner. So first assign accountability and budget, because today the contracting officer owns the clause, security owns the consequence, and nobody owns consumption. Then fix what the clause asks for: a machine-readable format, delivery to a system endpoint rather than a shared mailbox, a stated trigger for a refreshed document per release, and an acceptance check that rejects unparseable submissions on receipt instead of at incident time. Scope by consequence — your highest-impact systems first — and be willing to demand less where you cannot consume it, since unread artifacts are pure cost imposed on suppliers.
go deeper
Understand the basic point: receiving a document is not the same as being able to use it, and a contract can require delivery but cannot require anyone to read what arrives.
Be able to say what makes a delivery clause enforceable — named format, machine-readability, a system endpoint rather than a mailbox, subject identification, a refresh trigger, and validation on receipt.
Show that you would start from one operational question you want answerable and design the intake backwards from it, including rejecting non-conforming submissions at delivery rather than during an incident.
Own the ownership and budget argument, the phased scope by consequence, the willingness to ask suppliers for less than the mandate allows, and an outcome metric that cannot be satisfied by a fuller mailbox.
## Name the failure correctly An agency writes a clause requiring an SBOM with every release. Suppliers comply. The documents arrive at a shared mailbox. Nobody opens them. Two years later the clause is still in every contract and the agency's ability to answer a question about a compromised component is exactly what it was before the mandate existed. The temptation is to call this a supplier problem or a tooling problem. It is neither. It is the predictable result of a **procurement condition standing in for a capability**. Contract language can compel an artifact to be produced and delivered. It cannot compel anyone on the receiving side to build the thing that consumes it, and mandates rarely arrive with the budget for that half. Saying this plainly is the answer's centre of gravity; a candidate who jumps straight to "we need a tool" has skipped the part that actually decides the outcome. ## Work backwards from one question Before changing a clause or buying anything, pin down what you want to be able to answer. The realistic one is: *a widely used component is disclosed as exploited this morning — is it in anything we run, and where?* That single question determines everything downstream: which products need documents, at what granularity, refreshed on what trigger, and what "good enough" looks like. Working backwards from one answerable question also lets you stop. An agency that can answer it for its twenty highest-consequence systems is materially better off than one that has documents for four hundred and can query none of them. (How the ingestion and query capability is built is its own discipline; the point here is that the procurement side must be designed around it existing, and must not be designed as if the document itself were the deliverable.) ## Fix the ownership before the clause The structural problem is that three parties each hold one third of this and none holds the outcome: - The **contracting officer** owns the clause and is measured on whether suppliers complied. They did. - The **security team** owns the consequence when a component is exploited, and has no authority over what the contract asked for. - **Nobody** owns the pipe between them. So the first move is organisational, not technical: one named owner, accountable for the capability rather than the paperwork, with a budget line and a metric that is about answering the question — time to determine where a named component runs — not about how many documents were received. Without that, every subsequent improvement decays back to a fuller mailbox. ## Then make the clause buy something usable Only once someone can consume the artifact is it worth strengthening what you ask for. A clause that says "provide an SBOM" is nearly unenforceable. A useful one specifies: - **Format and machine-readability**, naming the accepted standard formats rather than accepting a spreadsheet or a PDF. - **Delivery target** — a system endpoint or repository the agency controls, not a human inbox. Delivery to a mailbox is the design flaw, not an implementation detail. - **Identity of the subject** — which product and which version the document describes, so it can be keyed on arrival. - **A refresh trigger** — a new document per release, and on a rebuild that changes contents, so the file does not silently describe a version retired eighteen months ago. - **Acceptance criteria** — the submission is validated on receipt and rejected if it cannot be parsed or does not identify its subject. Failing at receipt, when the supplier is still engaged, is enormously cheaper than discovering it during an incident. Notice that every one of those is enforceable at delivery time. That is the test for whether a clause is real. ## Be willing to ask for less The uncomfortable judgment, and the one that separates a principal answer from a merely thorough one: **requirements you cannot consume are a cost you impose on suppliers for zero risk reduction**. They raise supplier prices, shrink the field of bidders — disproportionately excluding small vendors — and generate compliance work on both sides that protects nobody. If you can only consume documents for a subset of your estate this year, ask only that subset for them, and expand as capability grows. Similarly, demanding an exotic format or an artifact type most of your suppliers do not produce buys nothing except exceptions. There is a second-order effect worth naming: a mandate that is visibly ignored teaches suppliers that these clauses are theatre, which makes the next requirement harder to land. Protecting the credibility of the requirement is a real argument for asking for less, earlier, and enforcing it. ## How you would know it worked Set the measure before the programme, and make it about the outcome: how long it takes to determine whether a named component is present in the estate, and what fraction of covered products can be answered for at all. "Percentage of contracts containing the clause" and "documents received per month" are the metrics that produced the mailbox; do not reintroduce them under new names.
- The programme has no budget and no owner. What is the single first move?Get one named owner accountable for an outcome metric — time to determine whether a named component runs anywhere — rather than for document receipt. Ownership precedes tooling and clause changes, because both decay without it. If no owner can be funded, the honest recommendation is to narrow the clause to the systems you can actually cover instead of collecting more unread artifacts.
- How do you push back when leadership wants the clause extended to every contract immediately?Show the cost side: each covered supplier prices the obligation in, small vendors drop out of bidding, and none of it reduces risk while nothing consumes the output. Offer a phased alternative sequenced by consequence, with an outcome measure at each phase. Extending an unenforced clause also teaches suppliers these requirements are theatre, which raises the cost of the next one.
- A supplier sends a document that cannot be parsed. When should that surface?At receipt, as a failed acceptance check, while the supplier is still contractually engaged and the release is fresh. Discovering it during an incident means the one moment you needed the artifact is the moment you learn it was never usable. Acceptance validation is what converts a delivery obligation into something enforceable rather than decorative.
It is a smoke detector installed to pass inspection and wired to nothing. The inspection record is genuine; the building is exactly as safe as before.
saying these in an interview costs you the question
- Adds contract clauses without naming who consumes the output
- Blames suppliers for a gap the buyer never staffed
- Says compliance is met so nothing needs fixing
- Demands formats or artifacts most suppliers cannot produce
- Measures success by documents received per month