Software Supply Chain Rules Begin to Bite
Attestation requirements and liability shifts are turning software provenance from a security topic into a commercial one.
Wikimedia Commons · CC BY-SA 4.0The paperwork era of software security has arrived, and it has teeth. Requirements for component inventories, provenance attestations, and secure development practices, phased in through procurement rules and sector regulation, are now conditions of sale into governments and regulated industries.
The commercial effect is the point. Vendors that cannot produce a credible bill of materials or attest to their build practices are losing deals they once won on features, and procurement teams report using supply chain requirements as a filter that conveniently shortens vendor lists.
The compliance burden falls unevenly. Large vendors absorb it into existing security programs; small ones face fixed costs that consolidate the market a little further. Tooling has commoditized the inventory problem, but the attestation of practices, being about how software is actually made, resists shortcuts.
Liability is the frontier to watch, as policymakers in several jurisdictions test frameworks that shift responsibility for defective software toward its makers. The software industry has historically disclaimed its way around that question; the disclaimer era, by most readings of the current direction, is closing.