Hardware BOM — FPGA & C-SCRM | ESL SBOMator
Hardware BOM (HBOM) — FPGA & C-SCRM

Hardware Joins the Evidence Graph

The completed Xilinx MPSoC workflow connects programmable logic, processor subsystems, boot artifacts, and IP provenance to the same evidence model as software and firmware — producing nested CycloneDX HBOM and a C-SCRM evidence package. Available as an optional, separately licensed module.

Xilinx Zynq UltraScale+ MPSoC / RFSoC

One evidence graph spans every processing subsystem and the programmable-logic fabric.

PS-APU

Cortex-A53 running PetaLinux / Yocto.

PS-RPU

Cortex-R5 running FreeRTOS or bare metal.

PS-PMU

MicroBlaze running PMU firmware.

PL Fabric

HDL, IP cores, and bitstream.

Design Inputs → Evidence Outputs

Transform native Xilinx design and build artifacts into standards-aligned hardware assurance.

Design and Build Inputs

.xpr / .bd / .xci Vivado designs · .xsa / .hwh hardware handoff · BOOT.bin and .bit / .bin artifacts · HLS projects and VHDL entities · PetaLinux projects and A53/R5/PMU ELF files.

Evidence Outputs

CycloneDX 1.6 nested HBOM · CISA HBOM field taxonomy · NTIA minimum-element stamping · HTML HBOM tab and CISA spreadsheet · paired HBOM-VEX evidence · NIST SP 1305 / SP 800-161r1 C-SCRM package.

The Hardware Half of the C-SCRM Evidence Package

Discover, enrich, and package hardware provenance alongside software and firmware evidence.

Complete FPGA Inventory

Inventories FPGA part details, Vivado IP, HLS and custom HDL, APU/RPU/PMU software, boot partitions, and PL bitstreams.

Provenance Enrichment

Enriches each component with supplier, license, hash, subsystem, and country-of-origin evidence.

Archive Auto-Discovery

Point to a .zip or .rar — SBOMator extracts and auto-discovers .bit, .xpr, .xci, VHDL, HLS projects, and ELF files.

Unified Evidence Graph

Links hardware, firmware, software, and vulnerability evidence in a traceable package for C-SCRM review.

Scope. Xilinx MPSoC design and boot artifacts; board-level PCB BOM remains a separate workflow. Optional licensed module, separate from the base SBOMator license.

Add Hardware to Your Supply-Chain Evidence

Connect Xilinx MPSoC design provenance and boot artifacts to the same defensible evidence model as your software and firmware.