Mark RadarMARK RADAR
About
EN
Sign in

U.S. Banks Press Tech Vendors for Software Ingredient Lists

1 reports · First detected 2026-08-03 · Last active 2026-08-03

U.S. banks rely heavily on outside providers for core processing, payments and digital services, leaving them exposed when a vulnerability appears deep inside a vendor’s software supply chain. A Software Bill of Materials, or SBOM, functions like an ingredient label by identifying components, versions, suppliers and dependencies. That visibility can help banks determine whether newly disclosed flaws affect their systems, prioritize patches and assess vendors before signing or renewing contracts.

The Cybersecurity and Infrastructure Security Agency published updated minimum SBOM elements on Aug. 22, 2025. The guidance calls for an SBOM with every software version or update, coverage of all components and transitive dependencies, and explicit disclosure of unknown, incomplete or redacted information. Banks are expected to add those questions to procurement reviews, increasing pressure on major financial-technology suppliers including FIS and Fiserv to provide machine-readable, regularly updated software inventories. CISA announced no spending threshold or dollar mandate.

All Coverage

1 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)