QBOM and post-quantum compliance: frameworks and timelines
Governments have converged on a similar shape: inventory now, migrate the highest-risk systems around 2030, finish around 2035. The details differ, and those details decide what your QBOM must show.
- NIST IR 8547 (still an initial public draft) proposes deprecation of 112-bit quantum-vulnerable algorithms after 2030 and disallowance of quantum-vulnerable algorithms after 2035.
- The EU roadmap asks Member States to start by the end of 2026 and protect high-risk use cases by the end of 2030.
- The UK NCSC sets milestones for 2028, 2031 and 2035; Canada's federal roadmap uses 2031 and 2035.
- India's DST task force sets critical information infrastructure targets of 2027 to 2029 and enterprise targets of 2028 to 2033.
- Every framework starts with a cryptographic inventory, which is the core of a QBOM.
The common pattern
Post-quantum guidance from different governments varies in detail but follows a similar sequence: discover and inventory quantum-vulnerable cryptography, prioritise systems that protect long-lived or critical data, migrate those first, then complete the transition. A QBOM is the record that shows where you are in that sequence.
Timelines compared
| Framework | Scope | Key dates |
|---|---|---|
| NIST IR 8547 (initial public draft, November 2024) | U.S. federal use of NIST-approved cryptography; widely used as a reference | Quantum-vulnerable algorithms at 112-bit security strength deprecated after 2030; quantum-vulnerable algorithms disallowed after 2035 [1] |
| NSA CNSA 2.0 | U.S. national security systems | New acquisitions CNSA 2.0 compliant from 1 January 2027; non-supporting equipment phased out by 31 December 2030; CNSA 2.0 algorithms mandated by 31 December 2031; all NSS quantum-resistant by 2035 [2] |
| OMB M-23-02 | U.S. federal agencies | Prioritised inventory of quantum-vulnerable systems by 4 May 2023 and annually until 2035 [3] |
| Executive Order 14306 (June 2025) | U.S. federal agencies | CISA list of PQC product categories due by 1 December 2025; TLS 1.3 or successor supported by 2 January 2030 [4] |
| EU Coordinated Implementation Roadmap (June 2025) | EU Member States, with critical infrastructure in focus | Start transitioning by end of 2026; high-risk use cases no later than end of 2030 [5]; as many systems as feasible by 2035 [6] |
| UK NCSC (March 2025) | UK organisations | By 2028 define goals, complete discovery and plan; by 2031 complete highest-priority migration; by 2035 complete migration [7] |
| Canada ITSM.40.001 (June 2025) | Government of Canada | Departmental plans by April 2026; high-priority systems by end of 2031; remaining systems by end of 2035 [8] |
| CERT-In BOM guidelines v2.0 (July 2025) | Government, public sector and essential services in India, and their suppliers | No dates; recommends CBOM/QBOM in procurement, maintained inventories and tiered vendor PQC contract requirements [9] |
| India DST task force (February 2026) | Critical information infrastructure and other enterprises in India | CII: foundations by 2027, high-priority migration by 2028, full adoption by 2029; others: 2028, 2030 and 2033 [10] |
What regulators actually ask you to show
- An inventory with data lifetime. M-23-02 asks for the algorithm, key length and how long data must be protected for each system [3]. NCSC's first milestone includes a full discovery exercise and a record of the data you hold, including its expected lifetime [7].
- A plan with priorities. Canada requires departmental migration plans and annual progress reporting [8]; the NCSC expects a refined roadmap by 2031 [7].
- Supplier transparency. CERT-In expects suppliers of cryptographic or quantum technologies to provide a CBOM and/or QBOM [9]; the DST task force recommends common procurement requirements with mandatory CBOMs [10].
- Evidence of progress. CNSA 2.0's acquisition date means vendors must show algorithm support, not just intent [2].
How to use the table
Pick the framework that binds you (or your customers) and use its dates as policy in your QBOM. If several apply, use the earliest date for each asset class. A supplier to both U.S. defence and Indian CII, for example, would plan against CNSA 2.0 for firmware signing and the DST CII dates for services delivered in India.
Detailed articles: NIST IR 8547, CNSA 2.0, CERT-In QBOM requirements and quantum readiness for Indian enterprises. For the underlying algorithms, see NIST PQC standards.
How IntelliXBOM helps
IntelliXBOM maps cryptographic and quantum inventory to framework controls and produces timestamped evidence, so the same QBOM can be reported against several timelines. It validates BOMs against required-field policies, keeps version history to show progress between reporting periods, and runs self-hosted, including air-gapped. This article summarises public guidance and is not legal advice; confirm obligations with the issuing authority or your legal adviser.
Frequently asked questions
Is there a legal deadline for post-quantum migration?
For most private organisations, not yet in binding law. The dates in NIST, EU, NCSC and DST documents are guidance or government-wide targets, while CNSA 2.0 applies to U.S. national security systems and their suppliers. Contracts and sector regulators may impose their own requirements.
Which post-quantum timeline should an Indian company follow?
Start with CERT-In's BOM guidelines and the DST task force targets, which set 2029 for critical information infrastructure and 2033 for enterprise-wide adoption. If you supply U.S. or EU customers, their frameworks may impose earlier dates for specific product categories.
What do all post-quantum frameworks have in common?
They all begin with discovering and inventorying quantum-vulnerable cryptography and recording how long the protected data must remain confidential. That inventory, extended with readiness status, is what most organisations mean by a QBOM.
Sources
- NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
- The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ (Ver. 2.1, December 2024)NSAmedia.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
- OMB M-23-02, Migrating to Post-Quantum Cryptography (November 2022)The White House, Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
- Executive Order 14306, Sustaining Select Efforts To Strengthen the Nation's Cybersecurity (6 June 2025)Federal Registerwww.federalregister.gov/documents/full_text/html/2025/06/11/2025-10804.html
- Post-Quantum Cryptography policy pageEuropean Commission, Shaping Europe's digital futuredigital-strategy.ec.europa.eu/en/policies/post-quantum-cryptography
- Roadmap for the Transition to Post-Quantum Cryptography (DG CONNECT presentation, June 2025)European Commission, hosted by ENISAwww.enisa.europa.eu/media/56885
- Timelines for migration to post-quantum cryptography (20 March 2025)UK National Cyber Security Centrewww.ncsc.gov.uk/guidance/pqc-migration-timelines
- Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)Canadian Centre for Cyber Securitywww.cyber.gc.ca/en/guidance/roadmap-migration-post-quantum-cryptography-government-canada-itsm40001
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.