CBOM for government and the public sector
Governments are both large operators of cryptography and the authors of the rules that now require an inventory of it. This article covers what public bodies are asked to do and how to organise a public-sector CBOM effort.
- CERT-In recommends that government, public sector and essential services organisations require CBOMs in cryptography-related procurements, developments and integrations.
- India's DST task force proposes common procurement requirements across government RFPs, with a compulsory bill of materials and crypto-agile, PQC-compliant assets.
- US federal agencies must inventory quantum-vulnerable cryptography annually under OMB M-23-02 and the Quantum Computing Cybersecurity Preparedness Act.
- EU and UK timelines put cryptographic discovery at 2026 and 2028 respectively.
- Public bodies depend heavily on suppliers, so supplier CBOMs and contract clauses are central.
The public-sector challenge
Government systems combine long-lived sensitive data, identity, tax, health, defence, land records, with estates that are old, federated across departments and largely built and run by suppliers. Cryptography sits in citizen portals, inter-departmental data exchanges, identity and signing infrastructure, and embedded in operational technology. Few departments can say today where RSA or elliptic-curve cryptography is used, which is the first question every post-quantum roadmap asks.
India
CERT-In Technical Guidelines v2.0
CERT-In's guidelines are addressed in part to government, public sector and essential services organisations. Recommendation 8.4.1.1 states that such organisations "shall require a comprehensive Bill of Materials (BOM), specifically a Cryptographic BOM (CBOM) for cryptographic assets and a Quantum BOM (QBOM) for quantum systems in all related procurements, developments, and integrations" [1]. Recommendation 8.5.4 goes further on post-quantum contracting, proposing tiered vendor PQC requirements: service providers to document all cryptographic implementations, provide quarterly migration progress reports with C-level attestation, accept penalty clauses, and demonstrate quantum-safe alternatives through proofs of concept before contract renewals [1].
DST Task Force report
The Department of Science and Technology's report on implementing a quantum-safe ecosystem (February 2026) recommends "common procurement requirements across all government RFPs" to ensure "crypto-agile and PQC-compliant assets, along with compulsory Bill of Materials". For critical information infrastructure it proposes foundations by 2027, high-priority migration by 2028 and full adoption by 2029 [2].
United States
The Quantum Computing Cybersecurity Preparedness Act requires each agency to maintain a current inventory of IT "vulnerable to decryption by quantum computers" [4]. OMB M-23-02 sets the mechanics: an inventory submitted to ONCD and CISA by 4 May 2023 and annually thereafter, covering high-impact systems, High Value Assets and other likely-vulnerable systems, with fields including system identifiers, the vulnerable cryptography in use, hosting environment and data lifecycle [3]. CISA's September 2024 strategy supports this with automated cryptography discovery and inventory tools, supplemented by manual collection [5]. For national security systems, NSA's CNSA 2.0 specifies quantum-resistant algorithms [6] with category-specific transition dates culminating in 2035 [7].
Europe and the UK
| Jurisdiction | Discovery milestone | Later milestones |
|---|---|---|
| EU Member States (coordinated roadmap, June 2025) | First steps including cryptographic inventories and dependency maps by end-2026 | High-risk use cases by end-2030; medium-risk by 2035 [8] |
| UK (NCSC, March 2025) | Full discovery exercise by 2028 | Highest-priority migration by 2031; complete by 2035 [9] |
Organising a public-sector CBOM effort
- Set scope by criticality. Start with systems that hold long-lived sensitive data or are designated critical. M-23-02's focus on high-impact systems and High Value Assets is a useful model [3].
- Use a common template. Adopt CERT-In's four asset types and fields [1] and a standard format (CycloneDX) across departments so inventories can be aggregated.
- Write CBOM clauses into procurement. Require supplier CBOMs at delivery and on each major release, and PQC roadmaps for critical products. See CBOM procurement requirements.
- Combine discovery methods. Network scans, code analysis for in-house systems, key store exports and supplier CBOMs; see CBOM generation.
- Protect the inventory. A consolidated government CBOM is sensitive. CERT-In recommends encryption, access control and integrity mechanisms for CBOM data (8.4.1.12) [1]; self-hosted or air-gapped storage may be appropriate.
- Report on a cycle. Review at least quarterly as CERT-In recommends [1], and keep history to show migration progress.
How IntelliXBOM helps
IntelliXBOM ingests supplier and internally generated CBOMs, validates them against required-field policies such as CERT-In's minimum elements, and keeps version history across reporting cycles. It maps the inventory to framework controls with timestamped evidence and can be deployed on-premise or fully air-gapped for sensitive environments.
Frequently asked questions
Does CERT-In require CBOMs for government procurement?
CERT-In's Version 2.0 guidelines state that government, public sector and essential services organisations shall require a CBOM for cryptographic assets in all related procurements, developments and integrations. They are technical guidelines, so departments should confirm how they are applied in their procurement rules.
What do US federal agencies have to report about cryptography?
Under OMB M-23-02, agencies submit an annual inventory of cryptographic systems vulnerable to a cryptographically relevant quantum computer to ONCD and CISA. The first was due by 4 May 2023, with reports annually thereafter until 2035.
When should public bodies complete cryptographic discovery?
The EU roadmap asks Member States to complete first steps including inventories by the end of 2026, the UK NCSC sets 2028 for a full discovery exercise, and India's DST task force proposes foundations by 2027 for critical information infrastructure.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science and Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
- M-23-02, Migrating to Post-Quantum Cryptography (18 November 2022)US Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
- Public Law 117-260, Quantum Computing Cybersecurity Preparedness Act (21 December 2022)US Government Publishing Office (GovInfo)www.govinfo.gov/content/pkg/PLAW-117publ260/html/PLAW-117publ260.htm
- Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools (September 2024)CISAwww.cisa.gov/resources-tools/resources/strategy-migrating-automated-post-quantum-cryptography-discovery-and-inventory-tools
- Announcing the Commercial National Security Algorithm Suite 2.0NSA Cybersecurity Advisorymedia.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF
- CNSA 2.0: Complete Guide to NSA's PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/
- EU PQC Workstream publishes 'A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography'PQShieldpqshield.com/eu-pqc-workstream-publishes-a-coordinated-implementation-roadmap-for-the-transition-to-post-quantum-cryptography/
- Timelines for migration to post-quantum cryptography (20 March 2025)UK National Cyber Security Centrewww.ncsc.gov.uk/guidance/pqc-migration-timelines
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.