Post-quantum procurement requirements for vendors
Much of an organisation's cryptography is built and run by suppliers. Procurement is where quantum readiness becomes an obligation someone else has to meet.
- CERT-In recommends that suppliers of cryptographic or quantum technologies provide a complete CBOM and/or QBOM.
- CERT-In also recommends tiered vendor PQC contract terms: documented implementations, quarterly progress reports with C-level attestation, penalty clauses and proofs of concept before renewal.
- CISA, NSA and NIST advise asking vendors for quantum-readiness roadmaps and contract terms for PQC in new and upgraded products.
- CISA's product categories list advises acquiring only PQC-capable products in listed categories.
- For U.S. national security systems, new acquisitions must be CNSA 2.0 compliant from 1 January 2027.
Why procurement matters
You cannot migrate cryptography you do not control. Appliances, HSMs, SaaS platforms, operating systems and network equipment all embed cryptography that only the supplier can change. The G7 Cyber Expert Group identifies obtaining detailed vendor roadmaps for cloud and cryptographic services as a barrier for financial institutions [1]. Procurement terms are how you close that gap.
What guidance says
| Source | Procurement guidance |
|---|---|
| CERT-In (July 2025) | Suppliers of software, systems or devices involving cryptographic or quantum technologies should provide a complete CBOM and/or QBOM [2] |
| CERT-In, section 8.5 | "Implement tiered vendor Post-Quantum Cryptography (PQC) contractual requirements": document all cryptographic implementations, provide quarterly migration progress reports with C-level executive attestation, establish penalty clauses for non-compliance, and demonstrate quantum-safe alternatives through proofs of concept before contract renewal [2] |
| CISA, NSA and NIST factsheet (August 2023) | Ask vendors about their quantum-readiness roadmaps, timelines for testing PQC, integration plans, and contract terms ensuring PQC in new and upgraded products [3] |
| CISA product categories list (January 2026) | Organisations should acquire only PQC-capable products within the listed categories when planning procurements [4][5] |
| NSA CNSA 2.0 FAQ | By 1 January 2027 all new acquisitions for national security systems are required to be CNSA 2.0 compliant unless otherwise noted [6] |
| India DST task force (February 2026) | Common procurement requirements with a mandatory CBOM [7] |
A requirements checklist
Adapt these to the risk tier of the purchase:
- Inventory. The supplier provides a CBOM, and a QBOM where quantum-related or quantum-safe components are involved, in CycloneDX or SPDX, covering the CERT-In minimum elements [2]. It is updated with every release.
- Current state. The supplier discloses every quantum-vulnerable algorithm used for key establishment, encryption and signatures, including in firmware and management interfaces.
- Roadmap. A written PQC roadmap with dates per product line and the NIST standards targeted (ML-KEM, ML-DSA, SLH-DSA) [8].
- Crypto-agility. Algorithms can be changed by configuration or update without hardware replacement; see crypto-agility.
- Hybrid support. Where the buyer's policy calls for hybrid key exchange during transition, the product supports it.
- Timeline alignment. Commitment to meet the buyer's applicable timeline (for example CNSA 2.0 categories, or DST targets for CII).
- Progress reporting. Quarterly migration progress reports with executive attestation, as CERT-In suggests [2].
- Vulnerability handling. VEX statements for vulnerabilities in cryptographic components.
- Proof. Proof-of-concept or test evidence of quantum-safe operation before renewal [2].
- Remedies. Penalty or exit clauses if commitments are missed.
Tiering suppliers
CERT-In's word "tiered" is useful. Apply the full checklist to suppliers whose products protect long-lived data, sit on internet-facing paths or anchor trust (HSMs, PKI, firmware signing, VPNs). Apply a lighter set, such as a CBOM and a roadmap, to lower-risk purchases. Record each supplier's tier and commitments in the QBOM against the systems they support, so a missed date shows up as risk on a business service. See QBOM management.
Evaluating responses
- Is the CBOM machine-readable and complete, or a spreadsheet summary?
- Does the roadmap name parameter sets and dates, or only intent?
- Are claims of "quantum-safe" backed by named standards and test evidence?
- Does the supplier depend on its own suppliers' roadmaps, and are those disclosed?
How IntelliXBOM helps
IntelliXBOM ingests supplier CBOMs and QBOMs in CycloneDX or SPDX and validates them against required-field policies, so incomplete submissions are flagged at intake. It keeps version history across supplier releases, records VEX decisions and produces timestamped evidence mapped to framework controls. This article summarises public guidance and is not legal advice; involve your legal and procurement teams in drafting contract terms.
Frequently asked questions
What should I ask a vendor about post-quantum readiness?
Ask for a machine-readable CBOM, disclosure of quantum-vulnerable algorithms, a dated PQC roadmap naming target standards, crypto-agility and hybrid support, and periodic progress reports. The CISA, NSA and NIST factsheet and CERT-In's guidelines both recommend this kind of engagement.
What are CERT-In's tiered vendor PQC contract requirements?
CERT-In recommends that service providers document all cryptographic implementations, provide quarterly migration progress reports with C-level executive attestation, accept penalty clauses for non-compliance and demonstrate quantum-safe alternatives through proofs of concept before contract renewals.
Does CISA require buying post-quantum products?
CISA's product categories list, published in January 2026 under Executive Order 14306, advises that organisations should acquire only PQC-capable products within the listed categories. It is aimed at U.S. federal agencies but is a useful reference for others.
Sources
- Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector (January 2026)G7 Cyber Expert Group, via U.S. Treasuryhome.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- Quantum-Readiness: Migration to Post-Quantum Cryptography (August 2023)CISA, NSA and NISTwww.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf
- CISA Releases List of Post-Quantum Cryptography Product CategoriesInfosecurity Magazinewww.infosecurity-magazine.com/news/cisa-post-quantum-cryptography/
- Product Categories for Technologies That Use Post-Quantum Cryptography StandardsCISAwww.cisa.gov/resources-tools/resources/product-categories-technologies-use-post-quantum-cryptography-standards
- The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ (Ver. 2.1, December 2024)NSAmedia.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
- Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards (13 August 2024)NISTwww.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.