CBOM compliance: which frameworks expect a cryptographic inventory
Few rules use the word CBOM, but a growing number expect an inventory of cryptography. This is a map of the public frameworks that do, and what each asks for.
- CERT-In's Version 2.0 guidelines are the most explicit CBOM source for India, with minimum elements and procurement recommendations.
- SEBI's CSCRF FAQs expect regulated entities to inventory cryptographic assets and prioritise post-quantum migration by risk.
- In the US, the Quantum Computing Cybersecurity Preparedness Act and OMB M-23-02 require federal agencies to inventory quantum-vulnerable cryptography annually.
- The EU, UK NCSC, G7 Cyber Expert Group and India's DST all place cryptographic discovery at the start of their post-quantum roadmaps.
- One well-structured CBOM can serve several of these frameworks at once.
Why compliance now points at cryptography
Most security frameworks have long required "appropriate encryption". What is changing is the expectation that organisations can show which cryptography they use, where and how strong it is. The trigger is the post-quantum transition: a regulator cannot ask for a migration plan without first asking for an inventory. A Cryptographic Bill of Materials (CBOM) is the structured way to hold that inventory. For the basics, see what is a CBOM.
India
CERT-In Technical Guidelines, Version 2.0
CERT-In's guidelines of 9 July 2025 define CBOM minimum elements for algorithms, keys, protocols and certificates, and make a series of recommendations in Section 8.4.1 [1]. They include:
- Government, public sector and essential services organisations "shall require" a CBOM for cryptographic assets "in all related procurements, developments, and integrations" (8.4.1.1).
- Suppliers must provide a complete CBOM for delivered solutions involving cryptographic technologies (8.4.1.2).
- BOMs should use SPDX or CycloneDX (8.4.1.5); VEX documents should be issued when vulnerabilities are found (8.4.1.6).
- Periodic audits for completeness and accuracy (8.4.1.10), and scheduled reviews "at least quarterly" (best practice 8.4.2.8).
Field-level detail is in CERT-In CBOM requirements.
SEBI CSCRF
SEBI's FAQs on the Cybersecurity and Cyber Resilience Framework (11 June 2025) address how regulated entities should maintain an inventory of cryptographic assets for post-quantum migration. The inventory "shall describe what cryptography is used by which application for what purpose" and "shall include keys, certificates, algorithms, etc.", with migration prioritised by risk assessment, asset criticality, information sensitivity and exposure [2].
DST Task Force on quantum-safe migration
The Department of Science and Technology's task force report (February 2026) calls for CBOMs covering software, hardware, primitives, algorithms, libraries, protocols and dependencies, and recommends common procurement requirements in government RFPs with a compulsory bill of materials. It proposes timelines for critical information infrastructure (foundations by 2027, full adoption by 2029) and for other enterprises (foundations by 2028, full adoption by 2033), and names RBI, SEBI and other regulators as bodies to issue sector guidance [3].
United States
| Instrument | Inventory expectation |
|---|---|
| Quantum Computing Cybersecurity Preparedness Act (Public Law 117-260, 21 December 2022) | Each agency to "establish and maintain a current inventory of information technology in use by the agency that is vulnerable to decryption by quantum computers" [4] |
| OMB M-23-02 (18 November 2022) | Agencies to submit an inventory of CRQC-vulnerable cryptographic systems to ONCD and CISA by 4 May 2023 and annually thereafter until 2035, covering high-impact systems, High Value Assets and other likely-vulnerable systems [5] |
| NSA CNSA 2.0 | Quantum-resistant algorithms (ML-KEM-1024, ML-DSA-87, LMS/XMSS, AES-256, SHA-384/512) for national security systems [6], with category-specific dates; for example, software and firmware signing to use CNSA 2.0 exclusively by 2030 [7] |
| NIST IR 8547 (initial public draft) | Quantum-vulnerable public-key algorithms deprecated after 2030 at 112-bit strength and disallowed after 2035 [8] |
M-23-02 lists the fields agencies report, including system identifiers, the CRQC-vulnerable cryptography in use, the hosting environment and data lifecycle characteristics [5]. These map naturally onto CBOM assets linked to systems.
Europe and the UK
- EU coordinated roadmap (June 2025). Member States to take first steps by the end of 2026, including inventories that support cryptographic asset management and dependency maps; high-risk use cases migrated by the end of 2030; medium-risk by 2035 [9].
- UK NCSC (March 2025). Define migration goals and "carry out a full discovery exercise" by 2028; highest-priority migration by 2031; complete migration by 2035 [10].
Financial sector guidance
The G7 Cyber Expert Group's January 2026 roadmap for the financial sector calls for a "comprehensive inventory of cryptographic assets, communication protocols, and relevant third-party dependencies", with critical systems migrated in the 2030–2032 window and the sector by 2035 [11]. See CBOM for banks.
One inventory, many frameworks
| Need | Frameworks it serves |
|---|---|
| Four asset types with defined fields | CERT-In [1], SEBI FAQs [2] |
| Link each asset to a system and owner | M-23-02 [5], SEBI FAQs |
| Quantum-vulnerability flag and priority | M-23-02, NIST IR 8547, EU roadmap, NCSC, DST |
| Supplier CBOMs | CERT-In 8.4.1.2, DST procurement recommendation, G7 third-party dependencies |
| Quarterly review and history | CERT-In 8.4.2.8 |
How IntelliXBOM helps
IntelliXBOM validates CBOMs against required-field policies such as CERT-In's minimum elements, maps cryptographic inventory to framework controls, and produces timestamped evidence. Version history shows how the inventory changed between reviews, which helps organisations address periodic audit and reporting expectations.
This article summarises public guidance and is not legal advice; confirm how each framework applies to your organisation.
Frequently asked questions
Is a CBOM legally required?
Few instruments use the term CBOM, but several require or recommend a cryptographic inventory. US federal agencies are required by law and OMB M-23-02 to inventory quantum-vulnerable cryptography, while CERT-In recommends CBOMs for government, public sector and essential services procurement in India.
Does SEBI require a cryptographic inventory?
SEBI's June 2025 CSCRF FAQs state that the inventory of cryptographic assets should describe what cryptography is used by which application for what purpose and include keys, certificates and algorithms. Regulated entities should read the FAQs alongside the CSCRF circular.
What deadline applies to cryptographic discovery?
Deadlines differ by jurisdiction. The EU roadmap sets the end of 2026 for first steps including inventories, the UK NCSC sets 2028 for a full discovery exercise, and India's DST task force proposes foundations by 2027 for critical information infrastructure.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- FAQs on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs (11 June 2025)SEBIwww.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
- Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science and Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
- Public Law 117-260, Quantum Computing Cybersecurity Preparedness Act (21 December 2022)US Government Publishing Office (GovInfo)www.govinfo.gov/content/pkg/PLAW-117publ260/html/PLAW-117publ260.htm
- M-23-02, Migrating to Post-Quantum Cryptography (18 November 2022)US Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
- Announcing the Commercial National Security Algorithm Suite 2.0NSA Cybersecurity Advisorymedia.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
- CNSA 2.0: Complete Guide to NSA's PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/
- NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
- EU PQC Workstream publishes 'A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography'PQShieldpqshield.com/eu-pqc-workstream-publishes-a-coordinated-implementation-roadmap-for-the-transition-to-post-quantum-cryptography/
- Timelines for migration to post-quantum cryptography (20 March 2025)UK National Cyber Security Centrewww.ncsc.gov.uk/guidance/pqc-migration-timelines
- G7 Cyber Expert Group Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector (January 2026)US Department of the Treasury (G7 Cyber Expert Group)home.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.