Menu

Upcoming Federal Cybersecurity Guidance Likely to Address Software Supply Chain Concerns

The News: A top federal cybersecurity official recently indicated that the Office of Management and Budget is preparing new cybersecurity guidance for federal agencies to be released in the coming weeks. The forthcoming requirements seem likely to focus on software supply chain concerns. Read more from NextGov here.

Upcoming Federal Cybersecurity Guidance Likely to Address Software Supply Chain Concerns

Analyst Take: During a recent NextGov event, Steven Hernandez, a top federal cybersecurity official, revealed that a new mandate on software supply chain security is in the works at the Office of Management and Budget. The federal cybersecurity guidance will help agencies understand the provenance of any software that is used on government networks and hold vendors accountable for its security, Hernandez indicated. New guidelines are expected to be released within the next few weeks.

An executive order in May 2021 established the National Institute for Standards and Technology’s Secure Software Development Framework, which is likely to be strengthened and reinforced by the new federal cybersecurity policy guidelines. The framework aims to address software supply chain concerns by requiring key information from vendors, and upcoming guidance may include third-party verification of vendor information among other updates to existing federal cybersecurity practices.

Software Supply Chain Concerns in Federal Cybersecurity

In the wake of the 2020 SolarWinds hacking incident and recent attention to critical vulnerabilities in log4j, an open-source software library, federal cybersecurity concerns have driven an increase in new policies and requirements for agencies and their vendors. Cyber supply chain risk management is a key aspect of federal cybersecurity, and guidance has previously focused on ensuring the security of software through the supply chain by maintaining inventories of software programs and the provenance of the code contained within. This is known as the Software Bill of Materials (or SBoM), and future guidance is expected to require SBoM information from vendors in a machine-readable format to allow for streamlined responses to incidents or vulnerabilities.

Advancement in federal cybersecurity practices is always good news, as the ability for federal agencies to work quickly and securely is vital to national security. It’s safe to say that no one wants to see another SolarWinds incident or malicious data breach that compromises the functionality of our federal agencies or private firms. As technology advances, federal cybersecurity efforts must keep pace in identifying and eliminating vulnerabilities before they result in unforeseen consequences. I look forward to the release of the OMB’s new guidelines and will be following the story as it develops.

Disclosure: Futurum Research is a research and advisory firm that engages or has engaged in research, analysis, and advisory services with many technology companies, including those mentioned in this article. The author does not hold any equity positions with any company mentioned in this article.

Analysis and opinions expressed herein are specific to the analyst individually and data and other information that might have been provided for validation, not those of Futurum Research as a whole.

Other insights from Futurum Research:

Making Markets EP25: Poly CEO Dave Shull on Q3, Supply Chain Strain, Service Pivots and The Future of Collaboration

IBM Deepens Its Commitment To Blockchain As Part of New Supply Chain Partnership

The SolarWinds Hack, Clubhouse, Vulnerable Agora SDKs, Microsoft — Some Cybersecurity News You May Have Missed this Week – Futurum Tech Webcast

Image Credit: NextGov

Author Information

Shelly Kramer is a serial entrepreneur with a technology-centric focus. She has worked alongside some of the world’s largest brands to embrace disruption and spur innovation, understand and address the realities of the connected customer, and help navigate the process of digital transformation.

Related Insights
AWS re:Invent 2025: Wrestling Back AI Leadership
December 5, 2025

AWS re:Invent 2025: Wrestling Back AI Leadership

Futurum analysts share their insights on how AWS re:Invent 2025 redefines the cloud giant as an AI manufacturer. We analyze Nova models, Trainium silicon, and AI Factories as AWS moves...
Pure Storage Q3 FY 2026 Results Revenue Up 16% YoY, Guidance Raised
December 4, 2025

Pure Storage Q3 FY 2026 Results: Revenue Up 16% YoY, Guidance Raised

Futurum Research analyzes Pure Storage’s Q3 FY 2026 results, highlighting enterprise platform adoption, hyperscaler momentum, and Portworx-led modernization....
NetApp Q2 FY 2026 Earnings Mix Shift Lifts Margins, AI Momentum Builds
November 26, 2025

NetApp Q2 FY 2026 Earnings: Mix Shift Lifts Margins, AI Momentum Builds

Futurum Research analyzes NetApp’s Q2 FY 2026 results, highlighting AI data platform traction, first-party cloud storage growth, and all-flash mix that lifted margins, alongside raised FY EPS and margin guidance....
Commvault’s Strategic Shift Redefining Resilience as a Strategic Imperative
November 25, 2025

Commvault’s Strategic Shift: Redefining Resilience as a Strategic Imperative

Fernando Montenegro, VP and Practice Lead at Futurum, shares insights on Commvault Shift 2025, highlighting the new Cloud Unity platform and the strategic shift to ResOps to unify IT, security,...
Microsoft Ignite 2025 AI, Agent 365, Anthropic on Azure & Security Advances
November 21, 2025

Microsoft Ignite 2025: AI, Agent 365, Anthropic on Azure & Security Advances

Analysts Nick Patience, Mitch Ashley, Fernando Montenegro, and Keith Kirkpatrick share insights on Microsoft's shift to agent-centric architecture, cementing the role of Agent 365 as the operational control plane and...
Cisco Q1 FY 2026 AI Demand Lifts Outlook and Orders
November 14, 2025

Cisco Q1 FY 2026: AI Demand Lifts Outlook and Orders

Futurum Research analyzes Cisco’s Q1 FY 2026 results, highlighting AI infrastructure demand, campus refresh momentum, and a cloud-first security transition that lifts recurring revenue visibility into the second half of...

Book a Demo

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.