QBOM resources · 18 guides
QBOM & Post-Quantum Readiness Resources
Standards, timelines and practical steps for quantum readiness: how to inventory quantum-vulnerable cryptography, assess exposure and plan a migration you can evidence.
Fundamentals
Guide · 7 minWhat is a QBOM? The Quantum Bill of Materials explainedA QBOM (Quantum Bill of Materials) documents quantum and quantum-safe components. Learn CERT-In's minimum elements and how QBOMs support PQC migration.Explainer · 3 minHarvest now, decrypt later explainedHarvest now, decrypt later explained: what government agencies say about the threat, which data and cryptography it affects, and how a QBOM helps prioritise.
Tools & platforms
Guide · 4 minQBOM and PQC-readiness tools: open-source optionsOpen-source QBOM and PQC-readiness tools: CBOMkit, Sonar Cryptography, Open Quantum Safe liboqs and oqs-provider, OpenSSL 3.5, and what each one does.Guide · 4 minQBOM platforms: evaluation criteria for quantum-readiness inventoryHow to evaluate a QBOM platform: standards support, CERT-In field validation, discovery coverage, data-lifetime capture, migration tracking and evidence.
Operations
Guide · 3 minQBOM management and post-quantum migration trackingHow to manage a QBOM over time: ownership, update triggers, version history, migration status, vendor reporting, exceptions and audit-ready progress metrics.Guide · 4 minQuantum risk assessment: scoring exposure and data longevityHow to run a quantum risk assessment: Mosca's inequality, data longevity, exposure, cryptographic function and migration effort, plus a scoring model.
Comparisons
Compliance
Compliance · 4 minCERT-In QBOM requirements: Table 8 elements and recommendationsCERT-In QBOM requirements explained: the 11 Table 8 minimum elements, section 8.4 recommendations and best practices, and section 8.5 PQC guidance.Compliance · 3 minCNSA 2.0 algorithms and timelineNSA CNSA 2.0 explained: ML-KEM-1024, ML-DSA-87, LMS/XMSS, AES-256 and SHA-384, category deadlines from 2025 to 2033, and the 2027 acquisition date.Compliance · 3 minNIST IR 8547 transition timeline: 2030 and 2035 explainedNIST IR 8547 explained: which quantum-vulnerable algorithms are proposed for deprecation after 2030 and disallowance after 2035, and the draft's 2026 status.Explainer · 3 minNIST PQC standards: FIPS 203, 204, 205 and HQCNIST's post-quantum standards explained: ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205), the planned FN-DSA and HQC, and what to record in a QBOM.Compliance · 3 minPost-quantum procurement requirements for vendorsPost-quantum procurement requirements: what to ask vendors for, from CBOMs and QBOMs to PQC roadmaps and progress reports, based on CERT-In, CISA and NSA.Compliance · 4 minQBOM and post-quantum compliance: frameworks and timelinesPost-quantum compliance timelines compared: NIST IR 8547, CNSA 2.0, OMB M-23-02, the EU PQC roadmap, UK NCSC, CERT-In and India's DST task force targets.
Industries
Industry · 3 minQuantum readiness for Indian enterprisesQuantum readiness in India: CERT-In QBOM guidance, DST targets for 2029 and 2033, TEC's PQC report, RBI's Q-SAFE panel and the National Quantum Mission.Industry · 4 minQuantum readiness for banks and financial servicesQuantum readiness for banks: the G7 Cyber Expert Group roadmap, BIS Project Leap, RBI's Q-SAFE committee and how a QBOM helps plan PQC migration in finance.Industry · 3 minQuantum readiness for government and defenceQuantum readiness for government and defence: NSM-10, OMB M-23-02, CNSA 2.0, EO 14306, UK, EU, Canadian and Indian timelines, and the role of the QBOM.
How-to
How-to · 3 minHow to build a QBOM: a step-by-step guideHow to build a QBOM step by step: scope services, discover cryptography, record CERT-In elements, add data lifetime and exposure, then validate and version.Guide · 4 minPreparing for post-quantum cryptography: a migration planA practical post-quantum migration plan: discover, assess, prioritise, migrate with crypto-agility and govern, aligned with NIST, CNSA 2.0, NCSC and India.
See it on your own stack.Map your SBOM, CBOM, QBOM, AIBOM and HBOM coverage against the frameworks you report to.
Request a Demo