PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Guide4 min readReviewed September 202612 sources

QBOM and PQC-readiness tools: open-source options

No single tool produces a complete QBOM. Open-source projects cover discovery, representation and testing; knowing which does what saves a lot of false starts.

Key takeaways
  • QBOM tooling falls into four jobs: discover cryptography, represent it in a standard format, test post-quantum alternatives and implement them.
  • CBOMkit and the Sonar Cryptography plugin, both under the Post-Quantum Cryptography Alliance, generate CycloneDX CBOMs from code and container images.
  • Open Quantum Safe's liboqs and oqs-provider are for research and prototyping; their maintainers do not recommend them for production.
  • OpenSSL 3.5 includes ML-KEM, ML-DSA and SLH-DSA, and offers a hybrid ML-KEM key share by default in TLS.
  • Tools find algorithms; only people can supply data lifetime and business context.

Four jobs, different tools

A QBOM programme needs tools for four distinct jobs. CERT-In recommends automating the generation, analysis and compliance validation of CBOMs and QBOMs with tooling integrated into development and deployment workflows [1], but no single open-source project covers all four:

  1. Discover where cryptography is used: source code, binaries, container images, configuration and network endpoints.
  2. Represent findings in a machine-readable BOM so they can be shared, diffed and validated.
  3. Test post-quantum algorithms against your protocols and performance budgets.
  4. Implement post-quantum algorithms in production libraries.

Open-source tools at a glance

ToolJobWhat it doesLicence
CycloneDX 1.6RepresentBOM standard with cryptographic asset types and properties, including a NIST quantum security level field [2]Open standard
CBOMkitDiscover, representToolset for CBOM generation, viewing, compliance checks and a CBOM database; components include CBOMkit-hyperion, CBOMkit-theia, CBOMkit-coeus and CBOMkit-action [3]Apache 2.0
Sonar Cryptography pluginDiscoverSonarQube plugin that detects cryptographic assets in source code and writes a CycloneDX 1.6 CBOM; covers Java (JCA, BouncyCastle), Python (pyca/cryptography) and Go, with C# in development [4]Apache 2.0
CBOMkit-theiaDiscoverScans container images and directories for certificates, keys, Java security configuration and OpenSSL configuration; it does not scan source code [5]See repository
testssl.shDiscoverCommand-line check of a server's TLS/SSL protocols, ciphers and some cryptographic flaws on any port [6]GPLv2
liboqsTestC library of quantum-safe KEMs and signature schemes, including ML-KEM, ML-DSA, SLH-DSA, HQC and others [7]MIT
oqs-providerTestOpenSSL 3 provider adding post-quantum and hybrid key exchange and signatures to TLS 1.3 [8]MIT
OpenSSL 3.5ImplementAdds ML-KEM, ML-DSA and SLH-DSA; default TLS key shares offer X25519MLKEM768 and X25519 [9]Apache 2.0
mlkem-nativeImplementML-KEM implementation from the PQ Code Package with formal verification of memory and type safety [10]Apache 2.0, ISC, MIT

The Post-Quantum Cryptography Alliance

Several of these projects sit under the Post-Quantum Cryptography Alliance (PQCA), hosted by the Linux Foundation. Its project list includes CBOMkit, which aims to support tools that "assess quantum vulnerability, and support post-quantum cryptography adoption"; Open Quantum Safe, for development and prototyping of quantum-resistant cryptography; and the PQ Code Package, which maintains high-assurance implementations of standards-track algorithms [11]. PQCA projects are labelled as production-track or experimental-track, which is worth checking before you depend on one.

Research tools versus production libraries

Be careful with the Open Quantum Safe projects. The liboqs README states that its maintainers do not currently recommend relying on it in a production environment or to protect sensitive data, and that it is meant for research and prototyping [7]. The oqs-provider README carries the same warning [8]. They are valuable for interoperability testing and for measuring handshake sizes and latency; they are not a shortcut to production deployment.

For production, most teams will rely on the post-quantum support now arriving in mainstream libraries, such as OpenSSL 3.5, released on 8 April 2025 [9], and on vendor products. Record the library and version in your SBOM and the algorithm and parameter set in your CBOM, so the QBOM can show what is actually deployed.

What tools cannot tell you

  • Data lifetime. Scanners find RSA or ECDH; they cannot know that a data set must stay confidential for 20 years. The CISA, NSA and NIST factsheet asks organisations to document this separately [12].
  • Vendor-controlled cryptography. Appliances, SaaS and HSM firmware are often opaque. You need supplier CBOMs and roadmaps; see PQC procurement requirements.
  • Coverage gaps. Each scanner supports specific languages and libraries. Combine source, binary and network discovery, and record which method found each asset.

For how these outputs feed a governed inventory, see How to build a QBOM and QBOM platform evaluation criteria.

How IntelliXBOM helps

IntelliXBOM ingests CycloneDX and SPDX output from open-source scanners such as those above, so findings from several discovery methods land in one inventory. It validates that inventory against required-field policies, keeps version history and diffs, and correlates cryptographic assets with vulnerabilities, known-exploited lists and business services.

Frequently asked questions

Is there an open-source QBOM generator?

There is no single open-source tool that produces a complete CERT-In style QBOM. CBOMkit and the Sonar Cryptography plugin generate CycloneDX CBOMs, which cover the cryptographic asset element; other elements such as hardware and vendor data come from SBOM, HBOM and procurement records.

Can I use liboqs in production?

Its maintainers say they do not currently recommend relying on liboqs in production or to protect sensitive data; it is intended for research and prototyping. Use it for testing and interoperability work, and use production-supported libraries for deployment.

Does OpenSSL support post-quantum cryptography?

Yes. OpenSSL 3.5, released on 8 April 2025, added ML-KEM, ML-DSA and SLH-DSA, and its default TLS key shares offer the hybrid group X25519MLKEM768 alongside X25519.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. CycloneDX 1.6 JSON schema (cryptoProperties)OWASP CycloneDX on GitHubgithub.com/CycloneDX/specification/blob/1.6/schema/bom-1.6.schema.json
  3. CBOMkitPQCA on GitHubgithub.com/cbomkit/cbomkit
  4. Sonar Cryptography PluginPQCA on GitHubgithub.com/PQCA/sonar-cryptography
  5. CBOMkit-theiaPQCA on GitHubgithub.com/cbomkit/cbomkit-theia
  6. testssl.shtestssl.sh on GitHubgithub.com/testssl/testssl.sh
  7. liboqsOpen Quantum Safe on GitHubgithub.com/open-quantum-safe/liboqs
  8. oqs-providerOpen Quantum Safe on GitHubgithub.com/open-quantum-safe/oqs-provider
  9. OpenSSL 3.5 release notesOpenSSL Libraryopenssl-library.org/news/openssl-3.5-notes/
  10. mlkem-nativePQ Code Package on GitHubgithub.com/pq-code-package/mlkem-native
  11. PQCA projectsPost-Quantum Cryptography Alliance (Linux Foundation)pqca.org/projects/
  12. Quantum-Readiness: Migration to Post-Quantum Cryptography (August 2023)CISA, NSA and NISTwww.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related QBOM guides

Across the BOM Suite

Put your QBOM under governance.Quantum readiness with continuous correlation and timestamped evidence.