PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Compliance4 min readReviewed September 202610 sources

QBOM and post-quantum compliance: frameworks and timelines

Governments have converged on a similar shape: inventory now, migrate the highest-risk systems around 2030, finish around 2035. The details differ, and those details decide what your QBOM must show.

Key takeaways
  • NIST IR 8547 (still an initial public draft) proposes deprecation of 112-bit quantum-vulnerable algorithms after 2030 and disallowance of quantum-vulnerable algorithms after 2035.
  • The EU roadmap asks Member States to start by the end of 2026 and protect high-risk use cases by the end of 2030.
  • The UK NCSC sets milestones for 2028, 2031 and 2035; Canada's federal roadmap uses 2031 and 2035.
  • India's DST task force sets critical information infrastructure targets of 2027 to 2029 and enterprise targets of 2028 to 2033.
  • Every framework starts with a cryptographic inventory, which is the core of a QBOM.

The common pattern

Post-quantum guidance from different governments varies in detail but follows a similar sequence: discover and inventory quantum-vulnerable cryptography, prioritise systems that protect long-lived or critical data, migrate those first, then complete the transition. A QBOM is the record that shows where you are in that sequence.

Timelines compared

FrameworkScopeKey dates
NIST IR 8547 (initial public draft, November 2024)U.S. federal use of NIST-approved cryptography; widely used as a referenceQuantum-vulnerable algorithms at 112-bit security strength deprecated after 2030; quantum-vulnerable algorithms disallowed after 2035 [1]
NSA CNSA 2.0U.S. national security systemsNew acquisitions CNSA 2.0 compliant from 1 January 2027; non-supporting equipment phased out by 31 December 2030; CNSA 2.0 algorithms mandated by 31 December 2031; all NSS quantum-resistant by 2035 [2]
OMB M-23-02U.S. federal agenciesPrioritised inventory of quantum-vulnerable systems by 4 May 2023 and annually until 2035 [3]
Executive Order 14306 (June 2025)U.S. federal agenciesCISA list of PQC product categories due by 1 December 2025; TLS 1.3 or successor supported by 2 January 2030 [4]
EU Coordinated Implementation Roadmap (June 2025)EU Member States, with critical infrastructure in focusStart transitioning by end of 2026; high-risk use cases no later than end of 2030 [5]; as many systems as feasible by 2035 [6]
UK NCSC (March 2025)UK organisationsBy 2028 define goals, complete discovery and plan; by 2031 complete highest-priority migration; by 2035 complete migration [7]
Canada ITSM.40.001 (June 2025)Government of CanadaDepartmental plans by April 2026; high-priority systems by end of 2031; remaining systems by end of 2035 [8]
CERT-In BOM guidelines v2.0 (July 2025)Government, public sector and essential services in India, and their suppliersNo dates; recommends CBOM/QBOM in procurement, maintained inventories and tiered vendor PQC contract requirements [9]
India DST task force (February 2026)Critical information infrastructure and other enterprises in IndiaCII: foundations by 2027, high-priority migration by 2028, full adoption by 2029; others: 2028, 2030 and 2033 [10]

What regulators actually ask you to show

  • An inventory with data lifetime. M-23-02 asks for the algorithm, key length and how long data must be protected for each system [3]. NCSC's first milestone includes a full discovery exercise and a record of the data you hold, including its expected lifetime [7].
  • A plan with priorities. Canada requires departmental migration plans and annual progress reporting [8]; the NCSC expects a refined roadmap by 2031 [7].
  • Supplier transparency. CERT-In expects suppliers of cryptographic or quantum technologies to provide a CBOM and/or QBOM [9]; the DST task force recommends common procurement requirements with mandatory CBOMs [10].
  • Evidence of progress. CNSA 2.0's acquisition date means vendors must show algorithm support, not just intent [2].

How to use the table

Pick the framework that binds you (or your customers) and use its dates as policy in your QBOM. If several apply, use the earliest date for each asset class. A supplier to both U.S. defence and Indian CII, for example, would plan against CNSA 2.0 for firmware signing and the DST CII dates for services delivered in India.

Detailed articles: NIST IR 8547, CNSA 2.0, CERT-In QBOM requirements and quantum readiness for Indian enterprises. For the underlying algorithms, see NIST PQC standards.

How IntelliXBOM helps

IntelliXBOM maps cryptographic and quantum inventory to framework controls and produces timestamped evidence, so the same QBOM can be reported against several timelines. It validates BOMs against required-field policies, keeps version history to show progress between reporting periods, and runs self-hosted, including air-gapped. This article summarises public guidance and is not legal advice; confirm obligations with the issuing authority or your legal adviser.

Frequently asked questions

Is there a legal deadline for post-quantum migration?

For most private organisations, not yet in binding law. The dates in NIST, EU, NCSC and DST documents are guidance or government-wide targets, while CNSA 2.0 applies to U.S. national security systems and their suppliers. Contracts and sector regulators may impose their own requirements.

Which post-quantum timeline should an Indian company follow?

Start with CERT-In's BOM guidelines and the DST task force targets, which set 2029 for critical information infrastructure and 2033 for enterprise-wide adoption. If you supply U.S. or EU customers, their frameworks may impose earlier dates for specific product categories.

What do all post-quantum frameworks have in common?

They all begin with discovering and inventorying quantum-vulnerable cryptography and recording how long the protected data must remain confidential. That inventory, extended with readiness status, is what most organisations mean by a QBOM.

Sources

  1. NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  2. The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ (Ver. 2.1, December 2024)NSAmedia.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
  3. OMB M-23-02, Migrating to Post-Quantum Cryptography (November 2022)The White House, Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
  4. Executive Order 14306, Sustaining Select Efforts To Strengthen the Nation's Cybersecurity (6 June 2025)Federal Registerwww.federalregister.gov/documents/full_text/html/2025/06/11/2025-10804.html
  5. Post-Quantum Cryptography policy pageEuropean Commission, Shaping Europe's digital futuredigital-strategy.ec.europa.eu/en/policies/post-quantum-cryptography
  6. Roadmap for the Transition to Post-Quantum Cryptography (DG CONNECT presentation, June 2025)European Commission, hosted by ENISAwww.enisa.europa.eu/media/56885
  7. Timelines for migration to post-quantum cryptography (20 March 2025)UK National Cyber Security Centrewww.ncsc.gov.uk/guidance/pqc-migration-timelines
  8. Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)Canadian Centre for Cyber Securitywww.cyber.gc.ca/en/guidance/roadmap-migration-post-quantum-cryptography-government-canada-itsm40001
  9. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  10. Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related QBOM guides

Across the BOM Suite

Put your QBOM under governance.Quantum readiness with continuous correlation and timestamped evidence.