In May 2026, the Reserve Bank of India formed an expert committee, Q-SAFE, to study quantum risk in the financial sector. One of its first responsibilities is to test the financial sector’s cryptographic inventory through a Cryptography Bill of Materials (CBOM) while testing crypto agility in regulated entities.
That is the same exercise your company should be running internally, at your own scale, before a regulator or an attacker forces the question. A CBOM lists every cryptographic asset you depend on: certificates, keys, algorithms and libraries. It shows where cryptography lives across your systems and how exposed it is. A structured CBOM checklist turns that list into 12 direct questions you can answer today, along with how to act on the gaps you find.
12 questions your CBOM checklist should answer
A CBOM checklist helps convert the cryptographic regulatory expectations into an internal audit process – one your security and compliance teams can run before an external inspector asks for evidence.
Run through these questions section by section. Each caters to a specific gap that attackers, auditors or a future quantum-capable adversary could exploit.
1. Inventory and visibility
- Single source of truth: Do you have a single, deduplicated inventory of every certificate, key and algorithm across code, cloud, HSMs and third-party libraries, instead of scattered spreadsheets per team?
- Dependency mapping: Can you trace which applications, APIs and services depend on each cryptographic asset?
- Continuous updates: Does your inventory refresh automatically as code and infrastructure change, or does it rely on periodic manual audits?
2. Algorithm and configuration health
- Deprecated algorithms: Are you still running RSA-1024, SHA-1, or CBC-only cipher suites anywhere in production?
- Legacy protocols: Is TLS 1.0 or 1.1 still enabled on any customer-facing or internal system?
- Certificate lifecycle: Does every certificate in your inventory have a documented expiry, rotation and renewal owner?
3. Quantum and future-state readiness
- Quantum-vulnerable algorithms: Have you identified every instance of RSA, ECC and Diffie-Hellman across your systems?
- Harvest-now-decrypt-later exposure: Is any long-lived sensitive data protected only by classical asymmetric cryptography?
- PQC migration path: Do you have a documented, prioritised roadmap toward NIST-approved post-quantum algorithms?
4. Governance and response
- Named ownership: Is there a board or CISO-level owner accountable for cryptographic risk?
- Incident speed: Can your team identify every affected application within hours, not weeks, when a cryptographic library vulnerability is disclosed?
- Regulatory mapping: Does your CBOM output map directly to RBI, CERT-In, or other applicable regulatory frameworks for audit purposes?
Why crypto agility matters beyond the checklist
Passing this checklist once is not the goal. NIST finalised its first set of post-quantum cryptographic standards, including ML-KEM and ML-DSA, in 2024, and new algorithms are expected to keep emerging over the next decade. A CBOM checklist run as a one-time exercise goes stale within months.
Crypto agility – the ability to swap out a vulnerable algorithm without re-architecting the system around it – is what keeps a CBOM useful over time. Organisations that have crypto agility and treat CBOM as a living, continuously monitored list lead to a much better post-quantum readiness than those without it.
Turning checklist gaps into a migration roadmap
Every “no” on this CBOM checklist is a prioritisation input, not a failure. Rank gaps by data sensitivity and exposure first. A quantum-vulnerable algorithm protecting KYC archives with a ten-year confidentiality requirement deserves attention before a low-risk internal tool.
From there, sequence the work: fix configuration issues (like deprecated TLS versions) immediately, since they need only software upgrades. Then plan algorithm-level migrations with vendor and application owners. Finally, build continuous monitoring so new cryptographic assets get flagged the moment they enter your environment, not at the next audit cycle.
Conclusion
Running through a CBOM checklist gives you a clear, evidence-based view of where cryptographic risk sits today, and how ready you are for the post-quantum shift regulators are already planning for. The 12 questions above are a starting point, not a substitute for continuous, automated visibility across every application, certificate and key you own.
CyberNX’s CBOM solutions build that visibility for you by combining network, code, artifact and HSM/KMS scanning into a single, audit-ready CBOM with a built-in post-quantum migration roadmap. Talk to our team to turn your CBOM checklist into a live, monitored inventory.
CBOM Checklist FAQs
What is a CBOM checklist?
Think of it as a structured set of questions used to test whether an organisation has complete visibility into its cryptographic assets, algorithm health and readiness for post-quantum migration.
Why is CBOM becoming increasingly important for Indian regulated entities?
CERT-In’s Technical Guidelines Version 2.0 recommend maintaining CBOMs as a cybersecurity best practice, while the RBI’s Q-SAFE committee has been tasked with testing the financial sector’s cryptographic inventory using a CBOM. These developments indicate growing regulatory attention.
How often should a CBOM checklist be reviewed
Treat it as continuous rather than periodic. New code, libraries and third-party dependencies change your cryptographic footprint constantly, so automated, ongoing monitoring works better than a once-a-year review.
What is the difference between a CBOM and an SBOM?
An SBOM inventories software components and dependencies. A CBOM narrows that focus specifically to cryptographic assets, algorithms, keys, certificates and protocols, and the risk each one carries.




