# Defense Primes Add SBOM Requirements

DFARS 252.204-7012 and CMMC do not universally require defense contractors to deliver a software bill of materials (SBOM), but prime contractors and customers may add SBOM obligations through contract terms, flowdowns, or vendor reviews. Contractors should check the documents incorporated into each contract and establish a release-specific SBOM process covering scope, format, validation, and controlled delivery; the signal identifies no specific solicitation, award, value, or deadline.

- Prime contractors and customers can make SBOM delivery a contractual or review expectation even when the cited baseline rules do not require it universally.
- Contractors should verify applicable SOWs and flowdowns and agree on SBOM scope, format, validation, and delivery controls before release.
- This is a defense software supply-chain and cybersecurity consideration, rather than a newly stated universal compliance mandate.

**Jurisdictions:** federal
**Industries:** Defense & Military, Information Technology
**Topics:** Cybersecurity
**Published:** September 29, 2026

### Government Entities
- National Institute of Standards and Technology (NIST)

### Sources
- [DFARS 7012 and CMMC don't formally require an SBOM. Primes are writing them into SOWs and flowdowns anyway, and "we don't have one" is a rough answer in a vendor review. What to include: https://t.co/ms3cHdYeu7 https://t.co/aIgJpvzA8F](https://x.com/secureframe/status/2104993907909984356) - twitter-regulatory