PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Guide7 min readReviewed September 202613 sources

What is a QBOM? The Quantum Bill of Materials explained

A Quantum Bill of Materials records the quantum-related and quantum-safe components in a system. In practice it also becomes the working view of how exposed an organisation's cryptography is to future quantum attack, and how far its migration has progressed.

Key takeaways
  • CERT-In defines the QBOM as focusing on components related to quantum computing and quantum-safe cryptography, with 11 minimum elements in Table 8 of its July 2025 guidelines.
  • Migration programmes add a quantum-exposure view on top of the cryptographic inventory: which assets are quantum-vulnerable, how long their data must stay confidential, and their migration status.
  • A QBOM depends on a CBOM; you cannot plan a post-quantum migration for cryptography you have not found.
  • CERT-In recommends machine-readable formats such as SPDX or CycloneDX; CycloneDX 1.6 has native fields for cryptographic assets.
  • A QBOM documents readiness; it does not by itself make any system quantum-safe.

A definition in two parts

The term Quantum Bill of Materials (QBOM) is used in two related ways, and it helps to keep them apart.

The CERT-In definition. India's CERT-In introduced the QBOM in its Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0, dated 9 July 2025. Section 8.1 says a QBOM "focuses on components related to quantum computing and quantum-safe cryptography" and includes quantum algorithms, security frameworks and related technologies [1]. The same section positions QBOMs as a way for organisations to maintain integrity, compliance and resilience as they adopt post-quantum cryptographic (PQC) solutions [1]. In this sense a QBOM is a component inventory, much like an SBOM, but for quantum devices, quantum-safe libraries and the hardware, protocols and dependencies around them.

The migration-practice view. Organisations planning a move to post-quantum cryptography also need a quantum-exposure view of their existing cryptographic inventory. The joint CISA, NSA and NIST factsheet on quantum readiness asks organisations to build an inventory of quantum-vulnerable cryptography, correlate it with asset inventories and document how long sensitive data sets need protection [2]. The U.S. OMB memorandum M-23-02 asks federal agencies for similar per-system detail, including the algorithm, key length and how long the data must be protected [3]. Many teams call this exposure-and-readiness view their QBOM too.

Both views are legitimate. CERT-In's definition tells you which components and fields to document; the migration view tells you what to do with that information. A mature QBOM programme covers both.

Why quantum computing changes cryptographic risk

CERT-In's guidelines state that public-key systems using RSA, ECC, Diffie-Hellman and DSA are vulnerable to Shor's algorithm, and recommend transitioning to quantum-resistant schemes [1]. Symmetric cryptography is affected far less: NIST's draft transition report says it does not expect to need to transition away from its existing symmetric standards such as AES [4], and the UK NCSC says symmetric algorithms with at least 128-bit keys can continue to be used [5].

No one can say with confidence when a cryptographically relevant quantum computer will exist, and this article makes no such prediction. The planning problem is different: data captured today can be stored and decrypted later, a risk the CISA, NSA and NIST factsheet calls "harvest now, decrypt later" [2]. Migrations also take years. See Harvest now, decrypt later explained.

What a QBOM contains: CERT-In's minimum elements

Table 8 of the CERT-In guidelines lists the minimum elements of a QBOM [1]:

ElementWhat it records
Model NameUnique identifier for the quantum device or system
VersionVersion numbers, updates and security patches
Vendor & Origin InformationManufacturer and origin
License InformationLicensing terms and conditions
Cryptographic AssetCryptographic components, described using the CBOM asset types (algorithms, keys, protocols, certificates)
Communication ProtocolProtocols the quantum device or system uses
HardwareProcessors, simulators and networking components
Software DependenciesLibraries, APIs, SDKs and firmware
Environmental ImpactEnergy consumption and sustainability factors
VulnerabilitiesKnown security issues and their severity
AttestationsDigital signatures that establish authenticity and integrity

The Cryptographic Asset element links the QBOM directly to the CBOM. For a detailed walk-through of each field and CERT-In's related recommendations, see CERT-In QBOM requirements.

The quantum-exposure view

For migration planning, organisations typically extend each cryptographic asset record with attributes like these. They are drawn from government migration guidance rather than from CERT-In's table:

AttributeWhy it matters
Algorithm, parameter set and key lengthDetermines whether the asset is quantum-vulnerable; OMB M-23-02 asks for algorithm and key length [3]
Quantum security levelCycloneDX 1.6 has a nistQuantumSecurityLevel field for the NIST security strength category, with 0 meaning none is met [6]
Data protected and confidentiality lifetimeLong-lived secrets are exposed to harvest-now attacks first [2]
Business service and ownerConnects technical findings to accountability
Implementation owner (in-house or vendor)Decides whether you fix it or your supplier does
Target algorithm and migration statusTracks progress towards standards such as ML-KEM (FIPS 203) [7]

Scoring these attributes is covered in Quantum risk assessment.

How the QBOM relates to other BOMs

  • SBOM lists software components. It tells you which libraries you ship, including cryptographic libraries.
  • CBOM lists cryptographic assets (algorithms, keys, protocols and certificates) and where they are used. See What is a CBOM?
  • QBOM documents quantum-related and quantum-safe components and, in practice, the quantum exposure and readiness of the cryptographic inventory.
  • HBOM lists hardware and firmware, which matters because roots of trust and signing keys often live there. See What is an HBOM?

CERT-In itself describes the QBOM and CBOM as together forming a unified foundation for securing cryptographic systems [1]. For the detailed comparison, read QBOM vs CBOM.

Formats

CERT-In recommends that BOMs be generated in recognised formats such as SPDX or CycloneDX [1]. CycloneDX 1.6 added first-class support for cryptographic assets [8]; its schema models four asset types (algorithm, certificate, protocol and related cryptographic material such as keys) and records properties such as primitive, parameter set, classical security level and NIST quantum security level [6]. OWASP describes post-quantum readiness as one of the main CBOM use cases [9].

The standards and timelines a QBOM supports

  • NIST standards. FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) were published on 13 August 2024 [10]. See NIST PQC standards.
  • NIST IR 8547. The initial public draft proposes deprecating quantum-vulnerable algorithms at the 112-bit security strength after 2030 and disallowing quantum-vulnerable algorithms after 2035 [4]. See NIST IR 8547 timeline.
  • CNSA 2.0. NSA intends all U.S. national security systems to be quantum-resistant by 2035 [11]. See CNSA 2.0 timeline.
  • EU. The coordinated roadmap asks Member States to start transitioning by the end of 2026 and to protect high-risk use cases no later than the end of 2030 [12].
  • India. A DST task force report published in February 2026 sets targets for critical information infrastructure by 2029 and enterprise-wide PQC adoption by 2033 [13].

A consolidated view is in QBOM and post-quantum compliance.

Who needs a QBOM

CERT-In's recommendations in section 8.4 are addressed to government, public sector and essential services organisations, which should require a CBOM for cryptographic assets; suppliers of software, systems or devices involving cryptographic or quantum technologies are expected to provide a complete CBOM and/or QBOM, and consumer organisations are expected to maintain an internal CBOM/QBOM aligned with the supplier's data [1]. Beyond India, any organisation that holds data needing long-term confidentiality, operates long-lived devices or sells into markets with post-quantum procurement rules has a reason to build one. Sector guidance is in banks, government and Indian enterprises.

Common misconceptions

  • "A QBOM makes us quantum-safe." It documents components and readiness. Migration is separate engineering work; see Preparing for post-quantum cryptography.
  • "Quantum readiness means quantum key distribution." NSA states it does not generally consider QKD a practical security solution for protecting national security systems [11]; most programmes focus on PQC algorithms.
  • "It is a one-off exercise." CERT-In expects CBOM/QBOM data to be kept up to date as new components, algorithms or quantum technologies are introduced [1]. See QBOM management.

How IntelliXBOM helps

IntelliXBOM generates and ingests CBOM and QBOM data in CycloneDX and SPDX, and validates it against required-field policies such as CERT-In's Table 8 elements. It keeps version history and diffs, so changes in cryptographic assets between releases are visible, and correlates those assets with vulnerabilities, end-of-life data and the business services they support. Inventory is mapped to framework controls with timestamped evidence, on-premise, in private cloud or air-gapped.

Frequently asked questions

What does QBOM stand for?

QBOM stands for Quantum Bill of Materials. CERT-In describes it as a bill of materials focused on components related to quantum computing and quantum-safe cryptography, including quantum algorithms, security frameworks and related technologies.

Is a QBOM the same as a CBOM?

No. A CBOM inventories cryptographic assets such as algorithms, keys, protocols and certificates. A QBOM covers quantum-related and quantum-safe components, and one of its CERT-In elements is the cryptographic asset, so the two are closely linked and usually maintained together.

Which format should a QBOM use?

CERT-In recommends recognised machine-readable formats such as SPDX or CycloneDX. CycloneDX 1.6 includes native fields for cryptographic assets, including a NIST quantum security level property.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. Quantum-Readiness: Migration to Post-Quantum Cryptography (August 2023)CISA, NSA and NISTwww.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf
  3. OMB M-23-02, Migrating to Post-Quantum Cryptography (November 2022)The White House, Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
  4. NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  5. Next steps in preparing for post-quantum cryptographyUK National Cyber Security Centrewww.ncsc.gov.uk/paper/next-steps-in-preparing-for-post-quantum-cryptography
  6. CycloneDX 1.6 JSON schema (cryptoProperties)OWASP CycloneDX on GitHubgithub.com/CycloneDX/specification/blob/1.6/schema/bom-1.6.schema.json
  7. FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)NISTcsrc.nist.gov/pubs/fips/203/final
  8. CycloneDX v1.6 Released, Cryptographic Bill of Materials and AttestationsOWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.6-released/
  9. Cryptography Bill of Materials (CBOM)OWASP CycloneDXcyclonedx.org/capabilities/cbom/
  10. NIST Releases First 3 Finalized Post-Quantum Encryption Standards (13 August 2024)NISTwww.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
  11. The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ (Ver. 2.1, December 2024)NSAmedia.defense.gov/2022/Sep/07/2003071836/-1/-1/0/CSI_CNSA_2.0_FAQ_.PDF
  12. Post-Quantum Cryptography policy pageEuropean Commission, Shaping Europe's digital futuredigital-strategy.ec.europa.eu/en/policies/post-quantum-cryptography
  13. Quantum Safe Ecosystem in IndiaDepartment of Science & Technology, Government of Indiadst.gov.in/quantum-safe-ecosystem-in-india

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related QBOM guides

Across the BOM Suite

Put your QBOM under governance.Quantum readiness with continuous correlation and timestamped evidence.