CBOM vs QBOM: cryptographic and quantum bills of materials compared
CERT-In treats the CBOM and QBOM together, but they record different things. The CBOM is the inventory of cryptography in use; the QBOM covers quantum technologies and quantum-safe components.
- CERT-In describes the CBOM as an inventory of cryptographic assets and the QBOM as focused on components related to quantum computing and quantum-safe cryptography.
- CBOM minimum elements are organised by asset type; QBOM minimum elements describe a system: model, vendor, licence, cryptographic asset, protocol, hardware, dependencies, vulnerabilities and attestations.
- For most enterprises the CBOM comes first: it shows where quantum-vulnerable algorithms such as RSA and ECC are used.
- CycloneDX can record quantum-relevant strength directly on algorithm assets through the nistQuantumSecurityLevel property.
Definitions from CERT-In
Section 8 of CERT-In's Technical Guidelines, Version 2.0, covers the "Crypto & Quantum BOM" together [1]. The CBOM is an inventory of cryptographic assets, algorithms, keys, protocols, certificates and dependencies, with metadata such as usage and expiration. The QBOM "focuses on components related to quantum computing and quantum-safe cryptography. It includes quantum algorithms, security frameworks, and related technologies" [1]. For the full QBOM picture, see what is a QBOM.
Put simply: the CBOM describes the cryptography you run today, whatever its type; the QBOM describes quantum and quantum-safe systems and components that you build, buy or integrate.
Minimum elements compared
| CBOM (Table 9) | QBOM (Table 8) | |
|---|---|---|
| Structure | Per cryptographic asset, grouped into four types | Per system or model |
| Elements | Algorithms: Name, Asset Type, Primitive, Mode, Crypto Functions, Classical security level, OID, List. Keys: Name, Asset Type, id, state, size, Creation Date, Activation Date. Protocols: Name, Asset Type, Version, Cipher Suites, OID. Certificates: Name, Asset Type, Subject Name, Issuer Name, validity dates, Signature Algorithm Reference, Subject Public Key Reference, Certificate Format, Certificate Extension | Model Name, Version, Vendor & Origin Information, License Information, Cryptographic Asset, Communication Protocol, Hardware, Software Dependencies, Environmental Impact, Vulnerabilities, Attestations |
| Typical subject | A banking application, a TLS gateway, an HSM cluster | A quantum key distribution system, a PQC-enabled product or module |
| Primary question | What cryptography is in use, and is it acceptable? | What quantum or quantum-safe technology is present, from whom, and with what assurance? |
Both lists are from CERT-In's guidelines [1]. Note that the QBOM includes a "Cryptographic Asset" element: a QBOM for a system points to that system's cryptography, which is the CBOM's territory.
How they work together in PQC migration
- CBOM: find the exposure. CERT-In notes that public-key systems using RSA, ECC, Diffie–Hellman and DSA are vulnerable to Shor's algorithm (8.5.1) [1]. The CBOM shows where they are used. NIST IR 8547 (draft) proposes deprecating these at the 112-bit level after 2030 and disallowing them after 2035 [2].
- Prioritise. Rank CBOM entries by the lifetime of the data they protect and by exposure.
- Select replacements. NIST's FIPS 203 (ML-KEM) [3] and FIPS 204 (ML-DSA) [4] are the primary standards for key establishment and signatures.
- QBOM: record what you adopt. As PQC-enabled products and quantum technologies arrive, the QBOM records their vendors, versions, dependencies, vulnerabilities and attestations.
- CBOM again: confirm the change. New CBOM versions should show ML-KEM or hybrid key exchange where RSA or ECDH used to be.
India's DST task force report frames the CBOM as a structured inventory of primitives, algorithms, libraries, protocols and dependencies that underpins quantum-safe migration [6]. See preparing for post-quantum cryptography.
Recording quantum strength in a CBOM
You do not need a QBOM to record whether an algorithm is quantum-safe. CycloneDX algorithm properties include classicalSecurityLevel in bits and nistQuantumSecurityLevel, the NIST security strength category from 0 to 6, where 0 means none of the categories are met [5]. Populating both lets a single CBOM answer "which of our algorithms are quantum-vulnerable?".
Which to start with
For most organisations, the CBOM. Every enterprise already runs cryptography, while relatively few operate quantum technologies. CERT-In's recommendations apply to both, suppliers of systems involving cryptographic or quantum technologies must provide "a complete CBOM and/or QBOM" (8.4.1.2) [1]so include both in procurement templates, and let the QBOM grow as PQC-enabled products are adopted.
How IntelliXBOM helps
IntelliXBOM generates and ingests CBOMs and QBOMs in CycloneDX and validates them against required-field policies such as CERT-In's Table 8 and Table 9 elements. Version history and diffs show migration progress from one CBOM to the next, and the inventory can be mapped to framework controls with timestamped evidence.
Frequently asked questions
What is the difference between a CBOM and a QBOM?
A CBOM inventories cryptographic assets in use: algorithms, keys, protocols and certificates. A QBOM, as CERT-In defines it, focuses on components related to quantum computing and quantum-safe cryptography, including quantum algorithms, security frameworks and related technologies.
Do I need a QBOM to prepare for post-quantum cryptography?
The first step is usually a CBOM, which shows where quantum-vulnerable algorithms such as RSA and ECC are used. A QBOM becomes relevant as you adopt quantum technologies or PQC-enabled products and need to record their vendors, dependencies and attestations.
Can a CBOM show whether an algorithm is quantum-safe?
Yes. CycloneDX algorithm assets can carry a NIST quantum security category alongside the classical security level, so a CBOM can flag quantum-vulnerable algorithms directly.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
- FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)NISTcsrc.nist.gov/pubs/fips/203/final
- FIPS 204, Module-Lattice-Based Digital Signature Standard (ML-DSA)NISTcsrc.nist.gov/pubs/fips/204/final
- CycloneDX v1.6 JSON Reference (bom-1.6 schema)OWASP CycloneDXcyclonedx.org/docs/1.6/json/
- Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science and Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.