PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Industry3 min readReviewed September 202612 sources

Quantum readiness for government and defence

Governments hold secrets with the longest lifetimes and run equipment for decades. They were first to require cryptographic inventories, and their rules now shape what suppliers must provide.

Key takeaways
  • U.S. agencies have submitted annual inventories of quantum-vulnerable systems under OMB M-23-02 since 2023, with data lifetime as a required field.
  • CNSA 2.0 requires new national security system acquisitions to be compliant from 1 January 2027.
  • The UK, EU and Canada target completion around 2035, with high-priority systems around 2030 to 2031.
  • CERT-In recommends that government, public sector and essential services organisations require CBOMs, and that suppliers provide CBOMs and QBOMs.
  • Defence platforms with long service lives make firmware signing and hardware roots of trust early priorities.

Why government moves first

Government data often needs protection for decades, making it a natural target for harvest-now, decrypt-later collection [1]. Government and defence systems also stay in service for a long time, so the time needed to migrate them is long. Both factors push the public sector to act earlier than most.

United States

  • NSM-10, signed on 4 May 2022, directs U.S. government agencies to migrate vulnerable cryptographic systems to quantum-resistant cryptography, with NSA leading for national security systems [2].
  • OMB M-23-02 requires agencies to submit a prioritised inventory of quantum-vulnerable systems by 4 May 2023 and annually until 2035, covering high-impact systems, high value assets and systems holding data that will remain mission-sensitive through 2035. Each entry records the algorithm, key length, hosting and how long the data must be protected [3].
  • CNSA 2.0 sets algorithms and dates for national security systems, including CNSA 2.0 compliance for new acquisitions by 1 January 2027 and quantum resistance for all NSS by 2035 [4]. See CNSA 2.0 timeline.
  • Executive Order 14306 (6 June 2025) required CISA to publish a list of product categories that support post-quantum cryptography by 1 December 2025, and agencies to support TLS 1.3 or a successor by 2 January 2030 [5]. CISA's list, released in January 2026, advises organisations to acquire only PQC-capable products within the listed categories [6].

UK, EU and Canada

JurisdictionMilestones
UK NCSCDiscovery and initial plan by 2028; highest-priority migration by 2031; all systems by 2035 [7]
EU roadmapMember States start transitioning by end of 2026; high-risk use cases by end of 2030 [8]
Canada (ITSM.40.001)Departmental plans by April 2026 with annual reporting; high-priority systems by end of 2031; the rest by end of 2035 [9]

India

CERT-In's BOM guidelines recommend that government, public sector and essential services organisations require a CBOM for cryptographic assets, and that suppliers of systems involving cryptographic or quantum technologies provide a complete CBOM and/or QBOM [10]. The DST task force report sets targets for critical information infrastructure of foundations by 2027, high-priority migration by 2028 and full adoption by 2029 [11]. See Quantum readiness for Indian enterprises.

Defence-specific concerns

  • Firmware and software signing. CNSA 2.0 expects exclusive use of quantum-resistant signing (LMS, XMSS or ML-DSA-87) by 2030 [12]. Devices whose trust anchors cannot be updated in the field need a plan now.
  • Long-life platforms. Record expected service life in the QBOM so migration difficulty is scored correctly, and link devices to the HBOM.
  • Classified and air-gapped estates. Inventories themselves are sensitive and may need to stay inside the enclave. CERT-In asks that CBOM/QBOM data be protected with encryption, access control and integrity mechanisms [10].
  • Coalition interoperability. Allies may use different parameter sets or hybrid policies; record partner requirements against each interface.

What a government QBOM should show

At minimum: each system's quantum-vulnerable cryptography with algorithm and key length, the data it protects and for how long, hosting and ownership (all M-23-02 fields [3]), the applicable timeline and category, supplier roadmap dates and migration status. See How to build a QBOM.

How IntelliXBOM helps

IntelliXBOM can be deployed on-premise, in private cloud or fully air-gapped, which suits classified and sovereign environments. It validates supplier BOMs against required-field policies, correlates cryptographic, software and hardware components with business services, and maps inventory to framework controls with timestamped evidence. This article summarises public guidance and is not legal advice.

Frequently asked questions

What does OMB M-23-02 require?

It requires U.S. federal agencies to submit a prioritised inventory of cryptographic systems vulnerable to a cryptographically relevant quantum computer, first by 4 May 2023 and annually until 2035. Entries include the algorithm, key length, hosting and how long the data must remain protected.

When do U.S. national security system purchases need to be quantum-resistant?

NSA's CNSA 2.0 FAQ states that by 1 January 2027 all new acquisitions for national security systems will be required to be CNSA 2.0 compliant unless otherwise noted.

Does CERT-In require QBOMs from government suppliers?

CERT-In's guidelines recommend that suppliers of software, systems or devices involving cryptographic or quantum technologies provide a complete CBOM and/or QBOM, and that government, public sector and essential services organisations require them in procurement.

Sources

  1. Quantum-Readiness: Migration to Post-Quantum Cryptography (August 2023)CISA, NSA and NISTwww.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf
  2. President Biden Signs Memo to Combat Quantum Computing Threat (NSM-10, 4 May 2022)NSAwww.nsa.gov/Press-Room/News-Highlights/Article/Article/3020175/president-biden-signs-memo-to-combat-quantum-computing-threat/
  3. OMB M-23-02, Migrating to Post-Quantum Cryptography (November 2022)The White House, Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
  4. The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ (Ver. 2.1, December 2024)NSAmedia.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
  5. Executive Order 14306, Sustaining Select Efforts To Strengthen the Nation's Cybersecurity (6 June 2025)Federal Registerwww.federalregister.gov/documents/full_text/html/2025/06/11/2025-10804.html
  6. CISA Releases List of Post-Quantum Cryptography Product CategoriesInfosecurity Magazinewww.infosecurity-magazine.com/news/cisa-post-quantum-cryptography/
  7. Timelines for migration to post-quantum cryptography (20 March 2025)UK National Cyber Security Centrewww.ncsc.gov.uk/guidance/pqc-migration-timelines
  8. Post-Quantum Cryptography policy pageEuropean Commission, Shaping Europe's digital futuredigital-strategy.ec.europa.eu/en/policies/post-quantum-cryptography
  9. Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)Canadian Centre for Cyber Securitywww.cyber.gc.ca/en/guidance/roadmap-migration-post-quantum-cryptography-government-canada-itsm40001
  10. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  11. Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
  12. CNSA 2.0: Complete Guide to NSA's PQC RequirementsPostQuantum.compostquantum.com/cnsa-2-0/complete-guide/

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related QBOM guides

Across the BOM Suite

Put your QBOM under governance.Quantum readiness with continuous correlation and timestamped evidence.