PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Comparison3 min readReviewed September 20266 sources

CBOM vs QBOM: cryptographic and quantum bills of materials compared

CERT-In treats the CBOM and QBOM together, but they record different things. The CBOM is the inventory of cryptography in use; the QBOM covers quantum technologies and quantum-safe components.

Key takeaways
  • CERT-In describes the CBOM as an inventory of cryptographic assets and the QBOM as focused on components related to quantum computing and quantum-safe cryptography.
  • CBOM minimum elements are organised by asset type; QBOM minimum elements describe a system: model, vendor, licence, cryptographic asset, protocol, hardware, dependencies, vulnerabilities and attestations.
  • For most enterprises the CBOM comes first: it shows where quantum-vulnerable algorithms such as RSA and ECC are used.
  • CycloneDX can record quantum-relevant strength directly on algorithm assets through the nistQuantumSecurityLevel property.

Definitions from CERT-In

Section 8 of CERT-In's Technical Guidelines, Version 2.0, covers the "Crypto & Quantum BOM" together [1]. The CBOM is an inventory of cryptographic assets, algorithms, keys, protocols, certificates and dependencies, with metadata such as usage and expiration. The QBOM "focuses on components related to quantum computing and quantum-safe cryptography. It includes quantum algorithms, security frameworks, and related technologies" [1]. For the full QBOM picture, see what is a QBOM.

Put simply: the CBOM describes the cryptography you run today, whatever its type; the QBOM describes quantum and quantum-safe systems and components that you build, buy or integrate.

Minimum elements compared

CBOM (Table 9)QBOM (Table 8)
StructurePer cryptographic asset, grouped into four typesPer system or model
ElementsAlgorithms: Name, Asset Type, Primitive, Mode, Crypto Functions, Classical security level, OID, List. Keys: Name, Asset Type, id, state, size, Creation Date, Activation Date. Protocols: Name, Asset Type, Version, Cipher Suites, OID. Certificates: Name, Asset Type, Subject Name, Issuer Name, validity dates, Signature Algorithm Reference, Subject Public Key Reference, Certificate Format, Certificate ExtensionModel Name, Version, Vendor & Origin Information, License Information, Cryptographic Asset, Communication Protocol, Hardware, Software Dependencies, Environmental Impact, Vulnerabilities, Attestations
Typical subjectA banking application, a TLS gateway, an HSM clusterA quantum key distribution system, a PQC-enabled product or module
Primary questionWhat cryptography is in use, and is it acceptable?What quantum or quantum-safe technology is present, from whom, and with what assurance?

Both lists are from CERT-In's guidelines [1]. Note that the QBOM includes a "Cryptographic Asset" element: a QBOM for a system points to that system's cryptography, which is the CBOM's territory.

How they work together in PQC migration

  1. CBOM: find the exposure. CERT-In notes that public-key systems using RSA, ECC, Diffie–Hellman and DSA are vulnerable to Shor's algorithm (8.5.1) [1]. The CBOM shows where they are used. NIST IR 8547 (draft) proposes deprecating these at the 112-bit level after 2030 and disallowing them after 2035 [2].
  2. Prioritise. Rank CBOM entries by the lifetime of the data they protect and by exposure.
  3. Select replacements. NIST's FIPS 203 (ML-KEM) [3] and FIPS 204 (ML-DSA) [4] are the primary standards for key establishment and signatures.
  4. QBOM: record what you adopt. As PQC-enabled products and quantum technologies arrive, the QBOM records their vendors, versions, dependencies, vulnerabilities and attestations.
  5. CBOM again: confirm the change. New CBOM versions should show ML-KEM or hybrid key exchange where RSA or ECDH used to be.

India's DST task force report frames the CBOM as a structured inventory of primitives, algorithms, libraries, protocols and dependencies that underpins quantum-safe migration [6]. See preparing for post-quantum cryptography.

Recording quantum strength in a CBOM

You do not need a QBOM to record whether an algorithm is quantum-safe. CycloneDX algorithm properties include classicalSecurityLevel in bits and nistQuantumSecurityLevel, the NIST security strength category from 0 to 6, where 0 means none of the categories are met [5]. Populating both lets a single CBOM answer "which of our algorithms are quantum-vulnerable?".

Which to start with

For most organisations, the CBOM. Every enterprise already runs cryptography, while relatively few operate quantum technologies. CERT-In's recommendations apply to both, suppliers of systems involving cryptographic or quantum technologies must provide "a complete CBOM and/or QBOM" (8.4.1.2) [1]so include both in procurement templates, and let the QBOM grow as PQC-enabled products are adopted.

How IntelliXBOM helps

IntelliXBOM generates and ingests CBOMs and QBOMs in CycloneDX and validates them against required-field policies such as CERT-In's Table 8 and Table 9 elements. Version history and diffs show migration progress from one CBOM to the next, and the inventory can be mapped to framework controls with timestamped evidence.

Frequently asked questions

What is the difference between a CBOM and a QBOM?

A CBOM inventories cryptographic assets in use: algorithms, keys, protocols and certificates. A QBOM, as CERT-In defines it, focuses on components related to quantum computing and quantum-safe cryptography, including quantum algorithms, security frameworks and related technologies.

Do I need a QBOM to prepare for post-quantum cryptography?

The first step is usually a CBOM, which shows where quantum-vulnerable algorithms such as RSA and ECC are used. A QBOM becomes relevant as you adopt quantum technologies or PQC-enabled products and need to record their vendors, dependencies and attestations.

Can a CBOM show whether an algorithm is quantum-safe?

Yes. CycloneDX algorithm assets can carry a NIST quantum security category alongside the classical security level, so a CBOM can flag quantum-vulnerable algorithms directly.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  3. FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)NISTcsrc.nist.gov/pubs/fips/203/final
  4. FIPS 204, Module-Lattice-Based Digital Signature Standard (ML-DSA)NISTcsrc.nist.gov/pubs/fips/204/final
  5. CycloneDX v1.6 JSON Reference (bom-1.6 schema)OWASP CycloneDXcyclonedx.org/docs/1.6/json/
  6. Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science and Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related CBOM guides

Across the BOM Suite

Put your CBOM under governance.Cryptographic visibility with continuous correlation and timestamped evidence.