PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry4 min readReviewed September 20266 sources

CBOM for Indian enterprises: CERT-In, SEBI, RBI and the national quantum-safe roadmap

Indian guidance on cryptographic inventory has moved quickly: a CERT-In field standard in 2025, SEBI expectations and a national quantum-safe roadmap in 2026. This is what it means for an enterprise building its first CBOM.

Key takeaways
  • CERT-In's Version 2.0 guidelines give Indian organisations a field-level CBOM standard across algorithms, keys, protocols and certificates.
  • SEBI's CSCRF FAQs expect regulated entities to inventory cryptographic assets by application and purpose.
  • The DST task force report proposes that enterprises outside critical information infrastructure lay foundations by 2028, complete high-priority migration by 2030 and fully adopt quantum-safe cryptography by 2033.
  • Software exporters and service providers may be asked for CBOMs by Indian public-sector clients and by overseas customers alike.
  • A CBOM built once in a standard format can serve CERT-In, sector regulators and customer requests.

The Indian landscape in 2026

SourceDateRelevance to CBOM
CERT-In Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, v2.09 July 2025Defines CBOM minimum elements; recommends CBOMs in government, public sector and essential services procurement [1]
SEBI CSCRF circular20 August 2024Cyber security framework for SEBI-regulated entities [3]
SEBI CSCRF FAQs11 June 2025Expect an inventory of cryptographic assets covering keys, certificates and algorithms [2]
DST Task Force report on a quantum-safe ecosystemFebruary 2026Calls for CBOMs and proposes national migration timelines [4]
RBI Deputy Governor, Global Fintech Fest11 September 2026Urges payment system providers to begin quantum-proofing; no timeline set [5]

CERT-In: the field standard

For most Indian organisations, CERT-In's guidelines are the practical definition of a CBOM. Table 9 lists minimum elements for four asset types, algorithms, keys, protocols and certificates, and Section 8.4.1 sets recommendations on supplier CBOMs, standard formats (SPDX or CycloneDX), VEX, integration with CERT-In advisories and threat intelligence, periodic audits and secure storage [1]. The guidelines also recommend reviews "at least quarterly". Field detail is in CERT-In CBOM requirements.

Sector expectations

Capital markets. SEBI's FAQs say the inventory of cryptographic assets "shall describe what cryptography is used by which application for what purpose" and "shall include keys, certificates, algorithms, etc.", with migration prioritised by risk, criticality, sensitivity and exposure [2].

Banking and payments. RBI has signalled direction rather than set rules: Deputy Governor Shirish Chandra Murmu told the Global Fintech Fest that it was time for payment system providers and network operators "to begin work moving towards quantum proofing" [5]. See CBOM for banks.

Other regulators. The DST task force names RBI, SEBI and CERC among bodies expected to issue sector-specific guidance [4].

The DST timelines

PhaseCritical information infrastructureOther enterprises
Foundations20272028
High-priority migration20282030
Full adoption20292033

These are the task force's proposals [4]. For a private enterprise, "foundations" in practice means a CBOM, a cryptographic policy, owners and a migration plan.

Exporters and service providers

CERT-In's guidelines are also relevant to software export and services organisations. An Indian IT services company or product firm may receive CBOM requests from an Indian public-sector client under CERT-In's procurement recommendations [1] and, separately, from overseas customers working to their own national PQC roadmaps. Producing CBOMs in CycloneDX, whose schema carries algorithm, certificate, protocol and related-crypto-material assets [6], lets one artefact answer both.

A 90-day starting plan

  1. Weeks 1–3: agree scope (critical applications first), owners and the CERT-In field set as your template.
  2. Weeks 3–6: scan internet-facing and internal TLS and SSH; export HSM, KMS and certificate data.
  3. Weeks 6–9: run code scanners on in-house applications; request CBOMs from critical suppliers.
  4. Weeks 9–12: merge into one CycloneDX CBOM, validate required fields, test against a written policy and flag quantum-vulnerable algorithms.
  5. Then: set a quarterly review cycle and report progress to the board.

See CBOM generation and preparing for post-quantum cryptography.

Common gaps to plan for

  • Vendor-managed platforms where the enterprise holds no source code and must rely on supplier CBOMs, which CERT-In recommends suppliers provide (8.4.1.2) [1].
  • Keys without owners in shared HSMs, especially after application migrations.
  • Internal TLS and SSH left on older defaults because only the perimeter was ever scanned.
  • Treating the CBOM as sensitive data: CERT-In recommends encryption, access control and integrity protection for CBOM data (8.4.1.12) [1].

How IntelliXBOM helps

IntelliXBOM validates CBOMs against CERT-In's minimum elements and other required-field policies, and maps the inventory to frameworks including CERT-In and SEBI CSCRF with timestamped evidence. It keeps version history for quarterly reviews and can be self-hosted on-premise, in a private cloud or air-gapped.

Frequently asked questions

Is there an Indian standard for CBOM fields?

CERT-In's Technical Guidelines, Version 2.0 (July 2025), define minimum CBOM elements for algorithms, keys, protocols and certificates. They are the most detailed Indian reference for CBOM content.

What is India's post-quantum migration timeline?

The DST task force report of February 2026 proposes foundations by 2027, high-priority migration by 2028 and full adoption by 2029 for critical information infrastructure. For other enterprises it proposes 2028, 2030 and 2033 respectively.

Which format should Indian enterprises use for a CBOM?

CERT-In recommends recognised formats such as SPDX or CycloneDX. CycloneDX 1.6 and later include dedicated structures for cryptographic assets, which makes it the usual choice for CBOMs.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. FAQs on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs (11 June 2025)SEBIwww.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
  3. Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities (20 August 2024)SEBIwww.sebi.gov.in/legal/circulars/aug-2024/cybersecurity-and-cyber-resilience-framework-cscrf-for-sebi-regulated-entities-res-_85964.html
  4. Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science and Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
  5. RBI asks payment operators to start quantum-proofing at GFF 2026 (September 2026)MediaNamawww.medianama.com/2026/09/223-rbi-payment-operators-quantum-proofing-gff-2026/
  6. CycloneDX v1.6 JSON Reference (bom-1.6 schema)OWASP CycloneDXcyclonedx.org/docs/1.6/json/

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related CBOM guides

Across the BOM Suite

Put your CBOM under governance.Cryptographic visibility with continuous correlation and timestamped evidence.