PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 20267 sources

CBOM for banks and financial services

Financial institutions run some of the densest cryptography of any sector, across payments, HSMs, digital channels and counterparties. A CBOM brings it into one view as regulators and standard-setters turn to post-quantum readiness.

Key takeaways
  • Banking cryptography spans digital channels, payment switches, HSMs, card and token systems, market connectivity and inter-bank links.
  • SEBI's CSCRF FAQs expect regulated entities to inventory keys, certificates and algorithms and prioritise post-quantum migration by risk.
  • The G7 Cyber Expert Group and the BIS both treat cryptographic inventory as a foundation for the financial sector's quantum transition.
  • In September 2026 an RBI Deputy Governor said it was time for payment system providers to begin quantum-proofing, without setting a timeline.
  • Third-party and vendor cryptography is a large share of a bank's exposure, so supplier CBOMs matter.

Why finance is different

A bank's cryptography is unusually dense and unusually shared. Internet and mobile banking terminate TLS at scale. Payment switches and card systems rely on HSMs for PIN and key operations. Market connectivity, inter-bank messaging and API partnerships add links whose cryptography is negotiated with counterparties. Much of this runs on vendor platforms whose internals the bank cannot inspect. Long-lived records, account data, loan documents, identity data, raise the stakes of the "harvest now, decrypt later" concern behind post-quantum planning.

A Cryptographic Bill of Materials gives this estate a single, structured inventory. For the basics, see what is a CBOM.

What regulators and standard-setters are saying

SEBI

SEBI's FAQs on the Cybersecurity and Cyber Resilience Framework (June 2025) state that regulated entities' inventory of cryptographic assets "shall describe what cryptography is used by which application for what purpose" and "shall include keys, certificates, algorithms, etc.". Migration should be prioritised by risk assessment, asset criticality, the sensitivity of the information protected and exposure to threats [1].

RBI

At the Global Fintech Fest on 11 September 2026, RBI Deputy Governor Shirish Chandra Murmu said "the time has therefore come for Indian payment system providers and network operators to begin work moving towards quantum proofing our payment systems". Press coverage noted that no timeline, standard or compliance date was set [4]. India's DST task force report names RBI and SEBI among the regulators expected to issue sector-specific migration guidance [5].

International

  • The G7 Cyber Expert Group's January 2026 roadmap calls for a "comprehensive inventory of cryptographic assets, communication protocols, and relevant third-party dependencies", with critical systems migrated in 2030–2032 and the sector by 2035. It highlights limited transparency from vendors as a barrier [2].
  • The Bank for International Settlements' July 2025 paper on quantum-readiness identifies broad awareness and cryptographic inventory as critical foundations for the financial system's transition [3].

Where to look in a bank

AreaCryptographic assets to capture
Digital channelsTLS protocols and cipher suites, server certificates, token-signing keys and algorithms for mobile and API authentication
Payments and cardsHSM-held keys with algorithm, size and state; key hierarchies; algorithms used for PIN and message protection
Core and data platformsDatabase and storage encryption algorithms and modes, key management integration
Partner and market connectivitymTLS certificates, VPN and IPsec configurations, message-signing algorithms
Internal infrastructureSSH host keys and algorithms, internal PKI, code and firmware signing
Vendor productsSupplier CBOMs for core banking, payment and trading platforms

Priorities for a first CBOM

  1. Internet-facing channels: fast to scan and highly exposed. Check against baselines such as NIST SP 800-131A Rev. 2 [7].
  2. HSM and key inventory: export key metadata and link each key to a business service.
  3. Systems holding long-lived sensitive data: the first candidates for post-quantum migration.
  4. Critical vendors: request CBOMs and PQC roadmaps. CERT-In's guidelines provide field definitions and recommend supplier CBOMs in procurement [6]; see CBOM procurement requirements.

Governance

Put the CBOM under the same governance as other risk registers: named owners per asset, a written cryptographic policy, exceptions with expiry dates, and periodic reporting to the board or IT strategy committee. Keep version history so migration progress can be shown over the multi-year horizon the G7 roadmap describes [2]. See CBOM management and preparing for post-quantum cryptography.

How IntelliXBOM helps

IntelliXBOM generates and ingests CBOMs, including supplier CBOMs, and correlates cryptographic assets with vulnerabilities, end-of-life data and the business services they support. It maps the inventory to framework controls such as SEBI CSCRF and produces timestamped evidence, and can be deployed on-premise, in a private cloud or air-gapped.

Frequently asked questions

Do Indian banks need a CBOM?

In September 2026 an RBI Deputy Governor urged payment system providers to begin quantum-proofing, although press reports noted that no timeline or standard had been set. SEBI's CSCRF FAQs expect regulated entities to inventory cryptographic assets. A CBOM is a practical way to meet both expectations.

What should a bank's CBOM include first?

Start with internet-facing channels and HSM-held keys, then systems holding long-lived sensitive data. Add supplier CBOMs for core banking, payment and trading platforms, which often hold a large share of cryptographic exposure.

What timeline applies to post-quantum migration in finance?

The G7 Cyber Expert Group's roadmap targets 2030–2032 for critical systems and 2035 for the financial sector overall. Indian regulators have not set sector deadlines, though the DST task force proposes timelines for critical information infrastructure and other enterprises.

Sources

  1. FAQs on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs (11 June 2025)SEBIwww.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
  2. G7 Cyber Expert Group Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector (January 2026)US Department of the Treasury (G7 Cyber Expert Group)home.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf
  3. BIS Papers No 158, Quantum-readiness for the financial system: a roadmap (July 2025)Bank for International Settlementswww.bis.org/publ/bppdf/bispap158.pdf
  4. RBI asks payment operators to start quantum-proofing at GFF 2026 (September 2026)MediaNamawww.medianama.com/2026/09/223-rbi-payment-operators-quantum-proofing-gff-2026/
  5. Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science and Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
  6. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  7. SP 800-131A Rev. 2, Transitioning the Use of Cryptographic Algorithms and Key Lengths (March 2019)NISTcsrc.nist.gov/pubs/sp/800/131/a/r2/final

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related CBOM guides

Across the BOM Suite

Put your CBOM under governance.Cryptographic visibility with continuous correlation and timestamped evidence.