Release Candidate

Published for review and comment. Comments are open through October 31, 2026: file them as issues on the taxonomy repository. A second release candidate adding canonical asset identity is planned for Q4 2026.

The Applied Quantum CBOM Profile is a property taxonomy layered on CycloneDX (ECMA-424) for cryptographic bills of materials. It defines the registered appliedquantum namespace: 50 properties across eight subnamespaces, covering post-quantum migration governance, financial-sector and custody context, and the inputs a cryptographic concentration computation needs. It serves the PQC Migration Framework and the Cryptographic Concentration Framework, and it’s owned by neither.

Licensed under CC BY 4.0. Free to use, adapt, and share, including for commercial purposes, with attribution to Steve Vaile and Marin Ivezic, Applied Quantum. The schema, validator and vocabularies are Apache-2.0 on GitHub.

Release Candidate · v1.0-RC

The Applied Quantum
CBOM Profile

Version 1.0-RC specifies all 50 properties with closed enumerations and value formats, the four-tier structure, and evidence tiers E1–E5. It adds a binding deprecation and migration policy for any field the CycloneDX core later absorbs, and a worked ML-KEM fragment that validates against the CycloneDX 1.7 schema.

The appliedquantum namespace registration is filed with the CycloneDX property-taxonomy registry as issue #189, August 14, 2026. This release candidate is open for comment through October 31, 2026, and a second candidate adds canonical asset identity in Q4 2026.

Version 1.0-RC · corrected edition of September 9, 2026 · Marin Ivezic and Steve Vaile / Applied Quantum · CC BY 4.0

Ships With the Profile

Machine-Readable Companions

Apache-2.0

JSON Schema & Validator

A schema for every property, with a closed name set, closed enumerations and value formats, plus a validator that walks a whole BOM and fixtures that pass and fail on purpose. The canonical schema identifier lives at cbomprofile.org/schema/.

Browse schema/ →

Issue-Driven Registry

Controlled Vocabularies

Shared labels for entropy source designs, entropy generation designs and HSM firmware families, so identical designs group as one dependency across institutions. Seeded with the ring-oscillator family, the SP 800-90A DRBG designs and the ROCA-class prime generation entry.

Browse vocab/ →

Filed · Open

Namespace Registration

The top-level namespace appliedquantum is filed with the CycloneDX property-taxonomy registry as issue #189, August 14, 2026. The issue is open. We’ll update this page when it gets resolved.

View issue #189 →

“Switching vendors moves the contract, not the dependency.”
Profile Architecture

Four Tiers, Independently Adoptable

Tiers are additive. An institution running a PQC migration adopts Tiers 1 to 3. One computing concentration adds Tier 4. Neither requires the other, and the Profile references native CycloneDX cryptoProperties rather than restating them.

1
CycloneDX Core
native cryptoProperties · serves both frameworks
2
PQC Migration Governance
appliedquantum:pqc · PQC Migration Framework
3
Sector & Custody Context
:fs · :custody · serves both frameworks
4
Concentration & Dependency Resolution
:conc · :pki · :path · :entropy · :lineage · CCF
Runs Across Every Tier
The rules that hold the taxonomy stable while it grows
Evidence tiers E1–E5
Deprecation & migration policy
Closed enumerations
Multi-valued carriage rules
Controlled vocabularies

Getting Started

Adopt the Profile in Three Moves

You don’t need the whole Profile to start. Tiers are additive, so adopt the ones your program needs and add the rest when the questions arrive.

Migrating
Tiers 1–3
Start from native cryptoProperties in your CBOM
Add pqc:* fields your governance owns: horizons, exposure, vendor readiness
Add custody and payment context where HSMs and rails apply
Measuring Concentration
Add Tier 4
Map assets to services with conc:serviceRef
Record paths as first-class records, one per negotiated outcome
Populate lineage, entropy, custody and trust-root inputs as evidence arrives
Validate & Cite
Ship It
Run the validator against your BOM
Cite the Profile by minimum version: v1.0-RC or later
Comment by October 31, 2026, by issue on the taxonomy repository

The Family

Frameworks & Related Projects

The Profile is one of three openly published Applied Quantum properties. Both frameworks cite it by minimum version, and neither owns it.

Consumer Framework

PQC Migration Framework

The eight-phase migration methodology at v2.1, with six sector extensions. Phase 2 of its lifecycle builds the cryptographic inventory and CBOM this Profile structures.

pqcframework.org →

Consumer Framework

Cryptographic Concentration Framework

Measures cryptographic concentration beneath the vendor layer. It consumes a CBOM conforming to this Profile, v1.0-RC or later, and its CBOM Conformance Statement states which fields each CCF level requires. CCF v1.0-RC was published August 16, 2026.

ccframework.org →

Machine-Readable Home

appliedquantum Property Taxonomy

The taxonomy on GitHub, with the JSON Schema, validator, fixtures and controlled vocabularies. Namespace registration filed as CycloneDX issue #189.

github.com/appliedquantum →

 

Applied Quantum

Research-driven professional services firm focused entirely on quantum technologies, from quantum computing and systems integration to strategy, sovereignty advisory, and quantum-safe security across all sectors.

appliedquantum.com →

Secure Quantum

Applied Quantum’s security-focused practice. Hands-on services including PQC readiness assessments, cryptographic inventory and CBOM, crypto-agility consulting, hybrid implementation, quantum risk assessment, and regulatory advisory.

securequantum.com →

PostQuantum.com

Marin’s personal blog on quantum security with over 1 million monthly readers. In-depth practitioner analysis covering PQC migration, cryptographic inventory, CBOM, hybrid deployment, vendor governance, and sector deep dives.

postquantum.com →

Stay Current