Quantum readiness for Indian enterprises
India now has a national PQC migration roadmap, technical guidance from TEC and CERT-In, and a central-bank committee on quantum risk. Together they give Indian enterprises a clear starting point.
- The DST task force report (February 2026) targets quantum resilience for critical information infrastructure by 2029 and enterprise-wide PQC adoption by 2033.
- It recommends common procurement requirements with mandatory CBOMs and a national PQC testing and certification programme.
- CERT-In's July 2025 guidelines define the QBOM and recommend CBOM/QBOM requirements in procurement.
- TEC's technical report TEC 910018:2025 recommends a cryptographic inventory, a CBOM and hybrid approaches during migration.
- RBI's Q-SAFE committee, formed in May 2026, will develop a roadmap for the financial sector.
The policy landscape
| Initiative | Body | Relevance |
|---|---|---|
| National Quantum Mission (approved 19 April 2023) | Department of Science & Technology | Rs 6,003.65 crore from 2023-24 to 2030-31 for quantum technologies, including satellite and inter-city quantum communication [1] |
| Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM v2.0 (9 July 2025) | CERT-In | Defines the QBOM and its minimum elements; recommends CBOM/QBOM in procurement [2] |
| Migration to Post Quantum Cryptography, TEC 910018:2025 | Telecommunication Engineering Centre, DoT | Technical roadmap: inventory, CBOM, hybrid migration, NIST standards [3] |
| Implementation of Quantum Safe Ecosystem in India (February 2026) | DST task force under the National Quantum Mission | National timelines for CII and enterprises [4] |
| Q-SAFE expert committee (25 May 2026) | Reserve Bank of India | Financial-sector quantum risk assessment and roadmap [5] |
The DST task force roadmap
The Department of Science & Technology constituted a task force under the National Quantum Mission, chaired by the CEO of C-DOT [4], with sub-groups led by TEC and the Data Security Council of India [6]. Its report sets time-bound national targets: quantum resiliency across critical information infrastructure by 2029 and enterprise-wide PQC adoption by 2033 [6].
| Phase | Critical information infrastructure | Other enterprises |
|---|---|---|
| Foundations (pilots, testing, procurement requirements) | By 2027 | By 2028 |
| High-priority system migration | By 2028 | By 2030 |
| Full adoption | By 2029 | By 2033 |
Source: DST task force report [4]. The short-term actions include PQC pilots, a national PQC testing and certification programme through TEC, STQC and BIS, and common procurement requirements with a mandatory Cryptographic Bill of Materials covering algorithms, key sizes, protocols, libraries and random number generators [4]. Banking and finance, government, defence, power and telecom are identified as sectors needing accelerated adoption [4].
TEC's technical guidance
TEC's report recommends building a comprehensive cryptographic inventory, representing it as a Cryptographic Bill of Materials that can be shared with vendors and partners, running classical and quantum-safe algorithms together in hybrid mode during transition, and adopting NIST's FIPS 203, 204 and 205 [3]. It applies Mosca's model of migration time plus security shelf-life against the quantum threat timeline to decide urgency [3].
What CERT-In adds
CERT-In's QBOM gives the field list (Table 8) and a set of recommendations: suppliers should provide a complete CBOM and/or QBOM, consumers should maintain internal CBOM/QBOMs aligned with supplier data, and inventories should be updated, audited and protected [2]. Its migration section recommends tiered vendor PQC contract requirements, including quarterly migration progress reports with C-level attestation [2]. See CERT-In QBOM requirements.
A plan for an Indian enterprise
- Determine your track. If any of your systems are notified as CII, or you supply CII operators, plan to the 2027 to 2029 dates; otherwise to 2028 to 2033.
- Build the CBOM for critical services and extend it into a QBOM with CERT-In's elements (see How to build a QBOM).
- Add procurement clauses requiring supplier CBOMs, QBOMs and PQC roadmaps (see PQC procurement requirements).
- Pilot hybrid key exchange on selected internet-facing services, as TEC suggests.
- Watch sector regulators. Banks and payment operators should follow the RBI Q-SAFE committee's output (see Quantum readiness for banks).
How IntelliXBOM helps
IntelliXBOM validates CBOMs and QBOMs against CERT-In's required fields, keeps version history and diffs, and correlates cryptographic assets with vulnerabilities, known-exploited lists and business services. It maps inventory to framework controls with timestamped evidence and runs on-premise, in private cloud or air-gapped. This article summarises public guidance and is not legal advice.
Frequently asked questions
Does India have a post-quantum migration deadline?
The DST task force report published in February 2026 sets national targets of quantum resiliency for critical information infrastructure by 2029 and enterprise-wide PQC adoption by 2033. These are roadmap targets; sector regulators may issue their own requirements.
What does TEC recommend for PQC migration?
TEC's technical report TEC 910018:2025 recommends a comprehensive cryptographic inventory, a Cryptographic Bill of Materials, hybrid classical and quantum-safe operation during transition, and adoption of NIST's FIPS 203, 204 and 205.
Is the National Quantum Mission about post-quantum cryptography?
The mission, approved on 19 April 2023, funds quantum technologies broadly, including quantum communication. The DST task force on a quantum-safe ecosystem, which produced India's PQC migration roadmap, was constituted under it.
Sources
- Cabinet approves National Quantum Mission to scale-up scientific & industrial R&D for quantum technologies (19 April 2023)Press Information Bureau, Government of Indiawww.pib.gov.in/PressReleaseIframePage.aspx?PRID=1917888
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
- Technical Report: Migration to Post Quantum Cryptography (TEC 910018:2025)Telecommunication Engineering Centre, DoTtec.gov.in/pdf/TR/Final%20technical%20report%20on%20migration%20to%20PQC%2028-03-25.pdf
- Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science & Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
- RBI constitutes Expert Committee on Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE) (25 May 2026)Reserve Bank of Indiarbi.org.in/Scripts/BS_PressReleaseDisplay.aspx?prid=62803
- Quantum Safe Ecosystem in IndiaDepartment of Science & Technology, Government of Indiadst.gov.in/quantum-safe-ecosystem-in-india
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.