PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert

QBOM · Quantum readiness

Quantum readiness you can inventory and evidence

Maintain a Quantum Bill of Materials aligned with CERT-In's minimum elements, linked to your cryptographic inventory and mapped to NIST, CNSA 2.0 and national timelines.

RSAECCDHCrypto inventoryMigration readinessPQCCNSA 2.0NIST PQC
qbom · Migration pathIllustrative
  1. Current cryptographyRSA-2048 · ECDSA P-256 · DH
  2. Quantum riskScored by exposure & data lifetime
  3. Migration planPrioritised backlog with owners
  4. Post-quantum readyML-KEM (FIPS 203) · ML-DSA (FIPS 204)

Why QBOM

Quantum Bill of Materials

Public-key algorithms such as RSA, elliptic-curve cryptography and Diffie-Hellman are vulnerable to a future quantum computer running Shor's algorithm, and data captured today could be decrypted later. CERT-In's July 2025 guidelines define the QBOM for components related to quantum computing and quantum-safe cryptography, while NIST, NSA and national roadmaps set migration dates from 2027 to 2035. A QBOM shows which systems are exposed, how long their data must stay protected and how far migration has progressed.

What QBOM tracks

Quantum-vulnerable usageEvery RSA, ECDSA, ECDH and DH instance, by asset
Data longevityWeight systems by how long their data must stay confidential
Migration prioritisationRank by exposure, criticality and dependency on vendors
PQC adoptionTrack ML-KEM and ML-DSA adoption and hybrid deployments
Crypto-agilityWhere algorithms are hard-coded versus configurable
Programme reportingReadiness by business unit and framework timeline

Capabilities

What IntelliXBOM does with your QBOM.

One governed inventory, correlated with the rest of your BOMs, the risks they carry and the controls they support.

CERT-In field validation

Check QBOMs against the 11 Table 8 minimum elements and CBOMs against Table 9 asset fields, and report exactly which fields are missing.

CycloneDX and SPDX

Generate and ingest BOMs in both formats, including CycloneDX 1.6 cryptographic properties such as parameter set and quantum security level.

One inventory, many sources

Bring together output from source-code, container, network and supplier discovery so each cryptographic asset is recorded once.

Correlation with services

Link cryptographic assets to software, hardware, vulnerabilities, known-exploited lists, end-of-life data and the business services that depend on them.

Version history and diffs

Keep every BOM version and see what changed between releases, such as a move from classical to hybrid key exchange.

Framework evidence

Map inventory to controls in CERT-In, NIST and CNSA 2.0 guidance and export timestamped evidence, self-hosted or air-gapped.

How it works

From collection to evidence.

The same five-step loop runs continuously, so the QBOM never becomes yesterday’s inventory.

  1. 01Discover

    Import cryptographic findings from open-source scanners, PKI exports and supplier CBOMs in CycloneDX or SPDX.

  2. 02Validate

    Check each BOM against CERT-In's QBOM and CBOM required fields and flag gaps for owners to fill.

  3. 03Correlate

    Connect cryptographic assets to components, hardware, vulnerabilities and business services to see where exposure sits.

  4. 04Track

    Compare versions over time to show which quantum-vulnerable assets have been replaced and which remain.

  5. 05Evidence

    Map the inventory to framework controls and export timestamped evidence for auditors, regulators and customers.

Use cases

The questions QBOM answers.

Each question resolves to a governed, versioned record, and to the frameworks that record helps provide evidence for.

Which of our services still use quantum-vulnerable key exchange on internet-facing paths?

Query the correlated inventory for RSA, ECDH or DH key-establishment assets linked to externally exposed services, then prioritise those that protect long-lived data.

Does this supplier's QBOM meet CERT-In's minimum elements?

Validate the submitted QBOM against Table 8 and the embedded cryptographic assets against Table 9, and return a list of missing fields to the supplier.

What changed in our cryptography since the last audit?

Diff the current and previous BOM versions to see added, removed or changed algorithms, key sizes and certificates by service.

Can we show progress against CNSA 2.0 or NIST IR 8547 dates?

Map assets to the relevant framework controls and export timestamped evidence showing current status against each category or date.

NIST PQC (FIPS 203 / 204 / 205)CNSA 2.0CERT-In BOM guidelinesSee compliance mapping →

QBOM questions, answered

What is a QBOM?

A QBOM, or Quantum Bill of Materials, documents components related to quantum computing and quantum-safe cryptography. CERT-In's July 2025 guidelines list 11 minimum elements, including cryptographic asset, communication protocol, hardware and attestations. In migration practice it also records the quantum exposure and readiness of an organisation's cryptography.

What is the difference between a QBOM and a CBOM?

A CBOM inventories cryptographic assets such as algorithms, keys, protocols and certificates. A QBOM covers quantum-related and quantum-safe components and includes the cryptographic asset as one of its elements, so the CBOM is its foundation. Most organisations build the CBOM first and extend it.

Is a QBOM required in India?

CERT-In's guidelines recommend that government, public sector and essential services organisations require CBOMs and QBOMs in related procurements, and that suppliers provide them. India's DST task force also recommends mandatory CBOMs in procurement. Applicability depends on your sector, contracts and regulator.

What are the post-quantum migration deadlines?

NIST's draft IR 8547 proposes deprecating 112-bit quantum-vulnerable algorithms after 2030 and disallowing them after 2035. NSA's CNSA 2.0 requires compliant new acquisitions for U.S. national security systems from 1 January 2027. The UK, EU and India's DST have published their own milestones between 2026 and 2035.

Which format should a QBOM use?

CERT-In recommends recognised formats such as SPDX or CycloneDX. CycloneDX 1.6 includes native cryptographic asset fields, such as primitive, parameter set and NIST quantum security level, that map closely to CERT-In's CBOM fields.

Does a QBOM make our systems quantum-safe?

No. A QBOM documents components, exposure and migration status so you can plan and evidence the transition. The migration itself means replacing quantum-vulnerable algorithms with standards such as ML-KEM and ML-DSA in software, hardware and supplier products.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  3. The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ (Ver. 2.1, December 2024)NSAmedia.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
  4. NIST Releases First 3 Finalized Post-Quantum Encryption Standards (13 August 2024)NISTwww.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
  5. Timelines for migration to post-quantum cryptography (20 March 2025)UK National Cyber Security Centrewww.ncsc.gov.uk/guidance/pqc-migration-timelines
  6. Post-Quantum Cryptography policy pageEuropean Commission, Shaping Europe's digital futuredigital-strategy.ec.europa.eu/en/policies/post-quantum-cryptography
  7. Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
  8. CycloneDX 1.6 JSON schema (cryptoProperties)OWASP CycloneDX on GitHubgithub.com/CycloneDX/specification/blob/1.6/schema/bom-1.6.schema.json
  9. Quantum-Readiness: Migration to Post-Quantum Cryptography (August 2023)CISA, NSA and NISTwww.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

The rest of the BOM Suite

See it on your own stack.Map your SBOM, CBOM, QBOM, AIBOM and HBOM coverage against the frameworks you report to.
Request a Demo