How to build a QBOM: a step-by-step guide
A useful first QBOM covers a small number of critical services well rather than the whole estate badly. This is the sequence that gets you there.
- Start with ten or so critical business services and expand once the process works.
- Combine code, binary, container, network and PKI discovery; each finds cryptography the others miss.
- Record CERT-In's Table 8 elements for quantum-related components and CBOM fields for every cryptographic asset.
- Add business context: data type, confidentiality lifetime, owner and whether a vendor controls the implementation.
- Validate, sign and version the QBOM so it can serve as evidence.
Before you start
Decide which definition you are building to. CERT-In's QBOM documents components related to quantum computing and quantum-safe cryptography [1]; most migration programmes also need a quantum-exposure view of their existing cryptography. The steps below produce both. For background, read What is a QBOM?
Step 1: Scope by business service
Choose a manageable set of critical services: internet banking, citizen portals, payment messaging, firmware update pipelines. The CISA, NSA and NIST factsheet recommends prioritising high-impact systems, industrial control systems and assets with long-term confidentiality needs [2]. For each service, list the applications, infrastructure, devices and third-party services it depends on. Your SBOM and HBOM supply much of this.
Step 2: Discover cryptography
Use several discovery methods, because each has blind spots:
- Source code scanning for cryptographic API calls (for example the Sonar Cryptography plugin, which outputs a CycloneDX CBOM [3]).
- Images and file systems for certificates, keys and library configuration (for example CBOMkit-theia [4]).
- Network scanning of TLS, SSH and VPN endpoints for protocols and cipher suites.
- PKI, HSM and KMS exports for key types, sizes and certificate hierarchies.
- Suppliers for appliances and SaaS you cannot scan: request their CBOM or QBOM.
Tool options are compared in QBOM tools.
Step 3: Record the CERT-In elements
For quantum-related and quantum-safe components, capture the Table 8 elements: model name, version, vendor and origin, licence information, cryptographic asset, communication protocol, hardware, software dependencies, environmental impact, vulnerabilities and attestations [1]. For every cryptographic asset, capture the CBOM fields CERT-In lists for algorithms, keys, protocols and certificates [1]. Field-by-field guidance is in CERT-In QBOM requirements.
Step 4: Represent it in CycloneDX or SPDX
CERT-In recommends SPDX or CycloneDX [1]. In CycloneDX 1.6, a cryptographic asset is a component of type cryptographic-asset with cryptoProperties. Its assetType is one of algorithm, certificate, protocol or related-crypto-material, and algorithm properties include primitive, parameterSetIdentifier, cryptoFunctions, classicalSecurityLevel and nistQuantumSecurityLevel [5]. An ML-KEM-768 key-establishment entry might carry "primitive": "kem", "parameterSetIdentifier": "768" and "cryptoFunctions": ["keygen", "encapsulate", "decapsulate"]. Link each asset to the software component that uses it through dependencies, which is how the CBOM connects to the SBOM [6].
Step 5: Add exposure and business context
Scanners cannot supply this. For each system, record:
| Field | Source |
|---|---|
| Data types and how long they need protection | Data owners; OMB M-23-02 asks for this per system [7] |
| Internet or partner exposure | Network architecture |
| Implementation owner (in-house, vendor, cloud) | Procurement and architecture records |
| Quantum-vulnerable (yes/no) and target algorithm | Policy mapped to NIST IR 8547 or CNSA 2.0 |
| Migration status | Engineering plan |
Scoring is covered in Quantum risk assessment.
Step 6: Validate, sign and version
Validate the document against the schema and against your required-field policy, and report gaps rather than hiding them. Sign it, since attestations are a CERT-In QBOM element [1]. Store it with access control, as CERT-In asks for encryption, access control and integrity protection for CBOM/QBOM data [1], and keep every version so progress can be shown over time.
Step 7: Hand over to operations
A QBOM that is not updated goes stale quickly. Assign owners, define update triggers and track migration status; see QBOM management.
How IntelliXBOM helps
IntelliXBOM generates and ingests CycloneDX and SPDX BOMs, validates them against required-field policies such as CERT-In's QBOM and CBOM elements, and reports missing fields. It keeps each version with diffs and correlates cryptographic assets with software components, hardware, vulnerabilities and business services.
Frequently asked questions
How long does it take to build a first QBOM?
It depends on the size of the estate and on how much supplier data is available. Scoping a small set of critical services first keeps the initial effort bounded and tests the process before scaling it.
Can a QBOM be generated automatically?
Discovery and format conversion can be largely automated, and CERT-In recommends automation. Business context such as data lifetime and ownership must still come from people, and vendor-controlled cryptography needs supplier input.
What is the minimum I need for a useful QBOM?
For each critical service: the cryptographic assets with algorithm and key size, what data they protect and for how long, who controls the implementation, and the migration status. Add CERT-In's Table 8 elements for quantum-related and quantum-safe components.
Sources
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- Quantum-Readiness: Migration to Post-Quantum Cryptography (August 2023)CISA, NSA and NISTwww.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf
- Sonar Cryptography PluginPQCA on GitHubgithub.com/PQCA/sonar-cryptography
- CBOMkit-theiaPQCA on GitHubgithub.com/cbomkit/cbomkit-theia
- CycloneDX 1.6 JSON schema (cryptoProperties)OWASP CycloneDX on GitHubgithub.com/CycloneDX/specification/blob/1.6/schema/bom-1.6.schema.json
- Cryptography Bill of Materials (CBOM)OWASP CycloneDXcyclonedx.org/capabilities/cbom/
- OMB M-23-02, Migrating to Post-Quantum Cryptography (November 2022)The White House, Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.