@techreport{nobuo-scitt-hardware-iot-cloud-use-cases-00, number = {draft-nobuo-scitt-hardware-iot-cloud-use-cases-00}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-nobuo-scitt-hardware-iot-cloud-use-cases/00/}, author = {Nobuo Aoki}, title = {{Applying SCITT to Hardware, IoT Device, and Cloud Compute Resource Supply Chains}}, pagetotal = 17, year = 2026, month = jul, day = 6, abstract = {This document describes how SCITT can be applied to supply chains that include hardware components, IoT devices, firmware, cloud compute resources, confidential-computing environments, accelerators, and related operational evidence. It gives use cases and scope guidance. It also explains how SCITT can work with RATS, COSE, TCG technologies, SBOM, HBOM, CBOM, and cloud attestation systems without replacing those technologies. This document is informational. It does not define hardware assurance rules, cloud assurance rules, device identity systems, manufacturing requirements, or payload formats. Its purpose is to show where SCITT statements and receipts can provide transparency for heterogeneous supply-chain evidence, and where other standards or domain profiles should remain responsible.}, }