About

About the CBOM Profile

The Applied Quantum CBOM Profile is a property taxonomy layered on CycloneDX (ECMA-424) for cryptographic bills of materials. It defines the registered appliedquantum namespace, 50 properties across eight subnamespaces, and the conventions for using native CycloneDX structures. One CBOM then holds post-quantum migration governance, financial-sector and custody context, and the inputs a cryptographic concentration computation needs. It was developed by Marin Ivezic and Steve Vaile and is published by Applied Quantum under CC BY 4.0.

The Profile exists because CycloneDX deliberately stops where governance begins. The base specification models cryptographic assets. It doesn’t model migration program state, harvest exposure, counterparty readiness, HSM firmware families, or entropy source designs, and those are the fields real migration and concentration assessments run on. The Profile supplies them without competing with the standard: native cryptoProperties fields are referenced and never restated, a binding deprecation policy governs any field the CycloneDX core later absorbs, and the whole set is versioned so stored assessments survive. Four external review rounds shaped the field set before it reached release candidate.

Two frameworks consume it. The PQC Migration Framework builds its Phase 2 cryptographic inventory and CBOM on the Profile’s tiers, and the Cryptographic Concentration Framework computes from a CBOM conforming to it, v1.0-RC or later. The Profile serves both and is owned by neither, which is why it versions independently, carries its own visual identity, and lives on its own domain.

The current version is 1.0-RC, in its corrected edition of September 9, 2026, open for comment through October 31, 2026, with feedback by issue on the taxonomy repository. The appliedquantum namespace registration is filed with the CycloneDX property-taxonomy registry as issue #189, August 14, 2026. The issue is open, and the registry table does not yet carry the namespace. A JSON Schema, a validator, fixtures and controlled vocabularies ship alongside under Apache-2.0, and a second release candidate adds canonical asset identity in Q4 2026.

The Authors

Marin Ivezic

Marin Ivezic is the founder and CEO of Applied Quantum and author of PostQuantum.com. He brings over thirty years of experience at the intersection of cybersecurity, cryptography, and enterprise risk, and over twenty-five years of involvement with quantum technologies.

A former Fortune Global 500 CISO and CTO, Marin has held regional and global leadership positions at IBM, Accenture, PwC, and KPMG. His classical cryptography career spans more than two decades of cryptographic upgrade programs across some of the world’s largest enterprises. His post-quantum work began over a decade ago, advising governments on quantum threats and leading PQC readiness programs with 120,000+ tasks for organizations across financial services, telecommunications, and critical infrastructure.

Marin is the author of Quantum Ready, a practitioner’s guide to organizational quantum readiness; Quantum Sovereignty, on strategic leadership and geopolitics in the quantum era; and Quantum Systems Integration.

Steve Vaile

Steve Vaile is Director of Post-Quantum Cryptography and Resilience for banking and financial services at Applied Quantum, and co-author of the Applied Quantum CBOM Profile and the Cryptographic Concentration Framework. He brings over thirty years of experience across technology, financial services, telecommunications, and international operations, and his advisory work assesses cryptographic dependencies and third-party, counterparty, and concentration risk across the financial sector.

The dependency analysis at the heart of the Profile’s Tier 4 has been his territory since the 1990s. From 1994 to 2007 he worked in operational causal analysis at MAXM, IBM RiverSoft, and EMC’s SMARTS and Voyence lines, tracing faults in banking, telecommunications, and defense networks to the shared infrastructure behind them. He later advised on Cambodia’s national credit bureau, working with the IMF and the National Bank of Cambodia on its regulatory framework and reaching full adoption across the country’s banks and microfinance institutions.

Since 2024 he has also served as Director of Post-Quantum Cryptography and Resilience at Quantum Security Defence (QSECDEF), providing board-level governance across an international quantum-security community of 1,400+ members. Before his quantum-security work he spent thirteen years as CEO and chairman of an international hospitality group operating across seven countries, and he began his career as a Royal Navy engineer.

Organizations

Applied Quantum

A research-driven professional services firm focused entirely on quantum technologies and post-quantum security, serving financial services, payments, government & defense, telecommunications, critical infrastructure, healthcare/pharma, and digital assets sectors.

PostQuantum.com

Marin’s personal blog on quantum security, with over one million monthly readers. Practitioner-grounded analysis aimed at CISOs, CTOs, security architects, and technology leaders. The cryptographic-inventory and CBOM groundwork behind this Profile has been analyzed in depth on PostQuantum.com.

Secure Quantum

Applied Quantum’s dedicated quantum security arm, delivering PQC migration programs, cryptographic inventory and CBOM engagements, quantum risk assessments, SOC and GRC integration for quantum threats, and crypto-agility implementation.

appliedquantum Property Taxonomy

The machine-readable home of this Profile on GitHub, with the taxonomy for the appliedquantum namespace, the JSON Schema and validator, test fixtures, and the controlled-vocabulary registry. The namespace registration is filed as CycloneDX issue #189.