
- Editable IBOM template to comply with Executive Order (EO) 14415.
- Enables a company to trace all components, parts, equipment, software and materials back to the origin of raw materials.
- Leverages industry-recoginized practices for SBOMs, HBOMs & CBOMs to populate the IBOM.
- Contains instructions and a consolidated data dictionary that maps every field to its source practice.
Don't Write An IBOM From Scratch.
According to Executive Order (EO) 14415 Section 3(b)(i), “Contractors must submit to the Department of War a complete indentured Bill of Materials that traces all components, parts, equipment, software, and materials back to the origin of raw materials in their supply chains.” The IBOM template from ComplianceForge provides a feasible method to comply with that requirement - this is all part of broader Supply Chain Risk Management (SCRM) practices by the US Government.
EO 14415 Section 3 contains the key IBOM components, where contractors must:
- Establish and implement written procedures to proactively vet all suppliers and subcontractors supporting the critical supply chain, screening at a minimum for financial risk, FOCI risk, and manufacturing and supply risk (Section 3(b)(ii)); and
- Not utilize covered material supplied by an unreliable foreign supplier in their supply chains, subject to limited exceptions (Section 3(b)(iii)).
What Is An Indentured Bill of Materials (IBOM)?
The IBOM required by EO 14415 is a multi-level (indented) Bill of Materials (BOM) whose nodes may be hardware assemblies, software components, cryptographic assets, materials or raw materials, each carrying provenance, supplier and risk data.
According to the US Government’s Warfighting Acquisition University (WAU), “Indentured BOMs show the relationship of components to sub-assemblies, sub-assemblies to assemblies, and assemblies to the entire system (parent/child relationships). The indentured format is preferred for Diminishing Manufacturing Sources and Material Shortages (DMSMS) management because it provides a broader picture for identifying, assessing the impact of, and weighing resolution options for issues.”
The "Indentured" term is not new. DoW provisioning and logistics practice has long used indentured parts lists, in which each line item is indented under its next-higher assembly to express parent/child relationships. GEIA-STD-0007 (the successor to MIL-STD-1388-2B) carries this forward as logistics product data, including an explicit indenture code that shows the relationship between assemblies and parts. EO 14415's IBOM definition is rooted in this provisioning and logistics lineage rather than in cybersecurity SBOM practice, which is why it includes logistics data elements (e.g., maintenance planning, reliability and maintainability, cost, cataloging) that no SBOM standard addresses.
No Software To Install
The IBOM is a one-time purchase of editable Microsoft Excel-based template. There is no software to install, no agent to deploy, no account to provision, and no cloud environment to configure. If your organization can open and edit Microsoft Excel files (or compatible tools like OpenOffice and Google Workspace), you can use the IBOM template.
Microsoft Excel
Delivered as a fully editable .xlsx file. Compatible with Microsoft 365, OpenOffice, LibreOffice and Google Sheets.
Email Delivery
Documentation is delivered via email download link within 1-2 business days of purchase.
One-Time Purchase
A single-entity license is included with purchase. There is no recurring subscription requirement, although an optional update subscription is available to stay current as frameworks evolve.

This deployment model is intentional. Cybersecurity documentation benefits from being in the organization's own hands, inside the organization's own version control and document management systems, rather than locked inside a vendor's SaaS tool.
What Problems Does The IBOM Solve?
Most organizations face one or more of the following documentation challenges. The IBOM was designed specifically to address them:
Lack Of In-House Security Experience
Writing security documentation is a skill that many good cybersecurity professionals simply are not proficient at and avoid the task at all cost - especially with specialized documentation requirements like an IBOM. Tasking your security analysts and engineers to write comprehensive documentation means you are actively taking them away from protecting and defending your network, which is not a wise use of their time.
Compliance Requirements
The IBOM is designed with compliance in mind, since it focuses on leading security frameworks to address EO 14415 Section 3(b)(i) for contractors to trace "all components, parts, equipment, software, and materials back to the origin of raw materials in their supply chains.”
Audit Failures
EO 14415 specifically calls out False Claims Act (FCA) liability for contractors. It is advisable to be proactive, rather than reactive by waiting for an audit failure to do what is required. The IBOM's structure provides mapping to leading security practices to show you exactly what is required to both stay compliant.
Vendor Requirements
EO 14415 requires prime contractors to govern their supply chain, so all levels of the supply chain will need to provide an IBOM that supports the main contract requirements. The IBOM is evidence that will be required.
How Does The IBOM Solve These Problems?
The IBOM addresses each challenge above with specific, measurable outcomes:
Alignment With Leading Practices
The IBOM template aligns with leading practices to address SBOM, HBOM and CBOM components to address EO 14415 requirements for an IBOM.
Time Savings
The IBOM can provide your organization with an editable IBOM template that allows you to hit the ground running.
What Is Included With The IBOM?
The IBOM is one of the simplest products we sell, where it is delivered as an Microsoft Excel spreadsheet with a "start here" instruction guide in PDF. There is no software to install, just an Excel spreadsheet that is formatted to address EO 14415 requirements.
Cost Savings Estimate
When you look at the costs associated with either (1) hiring an external consultant to write cybersecurity documentation for you or (2) tasking your internal staff to write it, the cost comparisons paint a clear picture that buying from ComplianceForge is the logical option. Compared to hiring a consultant, you can save months of wait time and tens of thousands of dollars. Whereas, compared to writing your own documentation, you can potentially save hundreds of work hours and the associated cost of lost productivity. Purchasing the IBOM from ComplianceForge offers these fundamental advantages when compared to the other options for obtaining quality cybersecurity documentation:
Internal Staff Cost
For your internal staff to generate comparable documentation, it would take them an estimated 900 internal staff work hours, which equates to a cost of approximately $1,000 in staff-related expenses. This is about 1-2 weeks of development time where your staff would be diverted from other work.
The IBOM is approximately 20% of the cost for your internal staff to generate equivalent documentation.
External Consultant Cost
If you hire a consultant to generate this documentation, it would take them an estimated 800 consultant work hours, which equates to a cost of approximately $1,300. This is about 1 week of development time for a contractor to provide you with the deliverable.
The IBOM is approximately 15% of the cost for an external consultant to generate equivalent documentation.

Product Example
Given the nature of the IBOM template, we are unable to provide a PDF example. The reason is that a screenshot of the Excel spreadsheet would give away the overall structure and content that could be copied.

How Much Customization Remains?
ComplianceForge did the heavy lifting creating the template. The remaining work is to work with your internal stakeholders to fill in the details to populate the spreadsheet. These are answers that only your Subject Matter Experts (SME) can answer.
ComplianceForge provides a filled in example of an IBOM that can be used for instructional purposes. Between the instructions and examples, internal staff can properly fill out the IBOM template without professional services.
Professional Services
ComplianceForge offers optional professional services to customize purchased documentation. Professional services are not required to customize ComplianceForge documentation. However, some clients want our subject matter expertise to help customize documentation to meet their specific business needs. If you have any questions about our professional services, please contact us at:
We offer the following professional service bundles:
5-Hour Bundle
This includes five (5) hours of professional services, which may be beneficial for companies that need some guidance on getting started with how to tailor their documentation.
10-Hour Bundle
This includes ten (10) hours of professional services, which may be beneficial for companies that need additional guidance on tailoring their documentation to meet their compliance requirements.
20-Hour Bundle
This includes twenty (20) hours of professional services, which may be beneficial for companies that need robust services, beyond just 10 hours, to assist in tailoring their documentation to meet their compliance requirements.
Purchased professional service hours expire 120 days (4 months) from the time of purchase if unused. Hours are intended to supplement, not replace, your own customization work, since only your organization knows the exact details to tailor your documentation. For questions regarding scoping a professional services engagement or configuring a custom package, contact ComplianceForge directly through the Contact Us page.



