Every application that your bank or insurer runs – depends on some sort of cryptography that actually spreads faster than anyone can track it. Keys, certificates, algorithms and libraries pile up across code and your cloud platforms – each one added at a different time by a different team. That gap turns urgent the moment quantum computing enters the picture. An attacker can collect encrypted data today and simply wait for a quantum computer to break it later. This tactic is known as “harvest now, decrypt later”.
Bills of materials for quantum readiness close that gap. They give you a structured inventory of every asset in your systems, mapped against how exposed each one is as quantum-safe algorithms move from recommendation to requirement. SEBI’s CSCRF, CERT-In’s Technical Guidelines v2.0 and RBI Advisory No. 11/2024 are driving firms to build structured cryptographic inventories such as CBOMs. This guide breaks down what a cryptography bill of materials contains, why it now sits at the centre of compliance and how you can build one without slowing your teams down.
What is a cryptography bill of materials (CBOM)?
A Cryptography Bill of Materials (CBOM) is a structured inventory of every cryptographic asset in your systems. That includes algorithms, keys, certificates, protocols and the libraries that implement them. CERT-In’s Technical Guidelines v2.0 pair this with a QBOM, which layers on quantum-exposure scoring and a migration plan, so the two are usually built and read together.
A CBOM extends the same idea behind a Software Bill of Materials (SBOM). Where an SBOM lists the components inside your software, a CBOM lists how that software uses cryptography.
Why CBOM compliance is non-negotiable for quantum readiness
Quantum readiness stopped being theoretical the day Indian regulators attached deadlines to it. SEBI’s CSCRF requires regulated entities to inventory keys, certificates and algorithms, and to prioritise post-quantum migration based on risk, criticality and data sensitivity. CERT-In’s Technical Guidelines v2.0 build on this with a dedicated CBOM for cryptographic assets and a QBOM for quantum-readiness planning, sitting alongside the SBOM requirements many teams already meet.
5 cryptographic assets a CBOM should track for quantum readiness
A useful CBOM goes beyond a flat list of algorithm names. It should give your team enough context to prioritise tasks by real business risk, not just technical classification.
- Algorithms and key lengths: Every instance of RSA, ECC, AES and hashing functions in use, with their key sizes.
- Digital certificates: TLS, code-signing and client certificates, along with issuers and expiry dates.
- Cryptographic libraries: The underlying implementations (OpenSSL, BoringSSL and similar) that carry their own vulnerability history.
- Keys and key stores: Where keys are generated, stored and rotated, including HSMs and KMS integrations.
- Protocol versions: TLS and cipher suite versions still active across your network and application layers.
How to build quantum readiness with a bill of materials
Discovery is the slowest phase of any cryptographic inventory. Starting the process now, ahead of final CBOM guidance, gives your team extra time to fix issues instead of racing a deadline.
- Discover: Scan code repositories, build artifacts, cloud environments and HSMs to surface every cryptographic asset in use.
- Classify: Tag each asset by quantum exposure, sensitivity and the systems it protects.
- Prioritise: Rank findings by business impact, starting with long-lived sensitive data and high-value applications.
- Migrate and monitor: Replace quantum-vulnerable algorithms with NIST-approved alternatives, then keep the inventory live as systems change.
Conclusion
A Cryptography Bill of Materials is rapidly becoming a regulatory expectation for Indian BFSI, driven by SEBI’s CSCRF, CERT-In’s Technical Guidelines v2.0 and RBI Advisory No. 11/2024. Building one gives your team complete visibility into cryptographic assets, a clear prioritisation plan and a head start on post-quantum migration.
CyberNX’s NXRADAR platform generates and continuously monitors your bill of materials for quantum readiness across code, cloud and HSMs, mapped directly to RBI and CERT-In requirements. Connect with our experts to understand how our CBOM solutions can help you monitor every cryptographic asset in a single platform and understand where your cryptography stands today.
Bills of Materials for Quantum Readiness FAQs
What is a Cryptography Bill of Materials?
It is a structured inventory that lists every cryptographic asset in your systems, built specifically to support quantum readiness. This includes algorithms, certificates, keys and libraries, mapped against quantum exposure.
Is a CBOM mandatory in India?
CBOMs are becoming an expected practice in India. CERT-In’s Technical Guidelines v2.0 recommend maintaining CBOMs and QBOMs for cryptographic and quantum systems, and regulatory frameworks like SEBI CSCRF and RBI cybersecurity guidance are driving organisations toward cryptographic asset inventories and post-quantum preparedness.
How is a CBOM different from an SBOM?
An SBOM lists the software components in an application. A CBOM lists the cryptography those components use, including algorithms, keys and certificates. Both can be represented using recognised standards such as CycloneDX or SPDX.
When should organisations start building a CBOM?
Discovery takes the longest of any migration step, so starting now, ahead of final regulatory guidance, gives teams time to remediate rather than react under deadline pressure.





