惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The Register - Security
The Register - Security
GbyAI
GbyAI
The GitHub Blog
The GitHub Blog
Google DeepMind News
Google DeepMind News
Y
Y Combinator Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
罗磊的独立博客
P
Proofpoint News Feed
A
About on SuperTechFans
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
D
DataBreaches.Net
V
Visual Studio Blog
Microsoft Azure Blog
Microsoft Azure Blog
Recent Announcements
Recent Announcements
T
Tailwind CSS Blog
Hugging Face - Blog
Hugging Face - Blog
腾讯CDC
V
V2EX
博客园_首页
大猫的无限游戏
大猫的无限游戏
月光博客
月光博客
人人都是产品经理
人人都是产品经理
小众软件
小众软件
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Microsoft Security Blog
Microsoft Security Blog
博客园 - 聂微东
L
LangChain Blog
博客园 - 三生石上(FineUI控件)
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
Cloudbric
Cloudbric
L
LINUX DO - 最新话题
WordPress大学
WordPress大学
M
MIT News - Artificial intelligence
Engineering at Meta
Engineering at Meta
The Hacker News
The Hacker News
Hacker News: Ask HN
Hacker News: Ask HN
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Stack Overflow Blog
Stack Overflow Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
PCI Perspectives
PCI Perspectives
Cisco Talos Blog
Cisco Talos Blog
N
News and Events Feed by Topic
The Cloudflare Blog
AWS News Blog
AWS News Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
What Is a QBOM? Quantum Bill of Materials vs CBOM Explained
Marin Ivezic · 2026-05-05 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This is part of the Quantum Security Reference Deep Dive series. For the full landscape overview, see the capstone article on quantum security.

Introduction

QBOM stands for Quantum Bill of Materials. The term is used in at least two distinct ways across the industry, which creates confusion for security leaders trying to figure out what they actually need. This reference sorts out the terminology and points you to the inventory that matters for PQC migration.

The Terminology Problem

A Bill of Materials (BOM) is a structured inventory of components in a system. The concept originated in manufacturing and was adopted by cybersecurity through the Software Bill of Materials (SBOM), which catalogues software components and dependencies for supply chain transparency. As the quantum threat gained urgency, the BOM concept was extended into quantum and cryptographic contexts, but without consistent naming.

The result is two terms that overlap, diverge, and are frequently conflated.

QBOM (Quantum Bill of Materials) was formalized by India’s CERT-In in their July 2025 Technical Guidelines (Version 2.0) alongside SBOM, CBOM, AIBOM, and HBOM. In the CERT-In framework, a QBOM specifically inventories quantum computing components: quantum algorithms, quantum security protocols, quantum hardware elements, and quantum software dependencies within an organization’s systems. It is designed for organizations that are building, integrating, or consuming quantum computing technology and need to track those components for interoperability, compliance, and risk management.

CBOM (Cryptographic Bill of Materials) inventories cryptographic components: encryption algorithms, key management mechanisms, digital certificates, TLS configurations, hash functions, and their deployment across an organization’s infrastructure. IBM’s research team developed the CBOM concept as an extension of SBOM, and it has become the standard term for the cryptographic inventory that PQC migration requires.

In practice, many organizations and vendors use “QBOM” to mean what is more precisely called a CBOM: a cryptographic inventory viewed through the lens of quantum risk. When a CISO hears “you need a QBOM,” the speaker almost always means “you need to know where your quantum-vulnerable cryptography is deployed.” That is a CBOM.

Which One Do You Need?

For the vast majority of organizations preparing for PQC migration, the answer is a CBOM. You need to know where RSA, ECC, and Diffie-Hellman are deployed across your infrastructure, which systems depend on them, and what the migration priority should be based on HNDL and TNFL exposure.

A QBOM in the CERT-In sense is relevant only if your organization is actively deploying quantum computing technology: running quantum processors, integrating quantum algorithms into workflows, or consuming quantum-as-a-service platforms. Most enterprises are not there yet. When they are, the QBOM will matter for securing quantum computers and managing quantum supply chain risk. For now, the cryptographic inventory is the priority.

I cover both inventories in my detailed analysis of Bills of Materials for Quantum Readiness: SBOM, CBOM, and Beyond, which maps each BOM type to its role in the quantum preparedness lifecycle.

Building a Cryptographic Inventory

Whether you call it a QBOM or a CBOM, the work is the same: discovering and cataloguing every instance of quantum-vulnerable cryptography across your organization. This is the foundation of any PQC migration program. Without it, prioritization is guesswork.

A comprehensive cryptographic inventory should map which algorithms are in use (RSA-2048, ECDSA P-256, ECDH, etc.), where they are deployed (network protocols, application code, certificate hierarchies, key management systems, HSMs, embedded devices), what data or functions they protect, and how long that protection must last.

The scope can feel overwhelming. A large enterprise may have cryptographic dependencies in thousands of systems, many of them undocumented or buried in vendor-supplied components. Risk-driven strategies provide a pragmatic starting point: begin with the systems carrying the highest-exposure data (long-lived confidential information subject to HNDL, and critical signature infrastructure subject to TNFL), then expand the inventory outward.

Several vendor tools can accelerate the discovery process by scanning networks, code repositories, and configurations for cryptographic usage. No single tool finds everything, but automated discovery combined with manual assessment provides a workable baseline.

The Regulatory Context

CERT-In’s July 2025 guidelines are voluntary, but they signal a direction. India’s framework is the first national-level guidance to formalize both QBOM and CBOM as distinct inventory categories. As quantum security regulation matures globally, similar requirements are likely to emerge in other jurisdictions.

In the United States, the emphasis has been on cryptographic inventory rather than quantum component inventory. NIST’s guidance and the CNSA 2.0 requirements both assume organizations will conduct cryptographic discovery as the first step of PQC migration. The US PQC regulatory framework does not use the QBOM term, but the underlying requirement (know your cryptographic exposure) is identical.

The Applied Quantum PQC Migration Framework incorporates cryptographic inventory as a core phase, regardless of which terminology your organization or regulator prefers.

Go Deeper

What Is PQC Migration? — the program that the inventory feeds into

Bills of Materials for Quantum Readiness: SBOM, CBOM, and Beyond — the full BOM landscape

Cryptographic Bill of Materials (CBOM) — what a CBOM contains and how to build one

Cryptographic Inventory for Quantum Readiness — the discovery process

Risk-Driven Quantum Crypto Inventory — starting with the highest-risk systems

Cryptographic Inventory Vendor Tools — automated discovery options

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum