Designed to be deprecated

The X- lesson

In June 2012, the IETF deprecated the X- prefix for experimental identifiers, in RFC 6648, after two decades in which provisional names never migrated, and X-Forwarded-For, which got a standardised replacement two years later, is still what most of the internet sends. An extension without a hand-over plan becomes permanent by default, whatever its author intended.

Vendor namespaces meet the same suspicion, and they have earned it. Most extension fields never hand anything back. So the Applied Quantum CBOM Profile ships its exit policy inside the specification, as Section 2, one page, and binding.

Five commitments

Where a field in this profile is accepted into the CycloneDX core, five things follow.

  1. The appliedquantum field is marked deprecated in the release following acceptance.
  2. The profile publishes a normative one-to-one mapping to the core equivalent, including any enumeration translation.
  3. The deprecated field stays valid and supported for no fewer than two subsequent Profile versions.
  4. Tooling consuming the profile must accept both forms during the window.
  5. No field is removed without a major version increment.

One clause covers the harder case. Where the core adopts a field with different semantics rather than an equivalent, the appliedquantum field is retained and the difference documented, because silent semantic drift is the failure mode this clause exists to prevent, and a mapping that pretends two meanings are one corrupts every stored record that relies on it.

Why those numbers

None of the numbers is decorative, starting with the window. Bills of materials outlive their emitters, so an assessment recorded against v1.0 must still parse when v1.2 ships, and estates don’t re-emit on our schedule. Renames and semantic changes need a major increment too, under Section 11, because all three invalidate stored assessments.

Enumeration translation is the commitment that looks pedantic and isn’t. A closed enumeration can be translated value for value, an open one can’t, and we have already run this translation on ourselves once. The v0.3 revision renamed safe to not-known-quantum-vulnerable, documented in the changelog, because the old value claimed more than the profile could stand behind.

And the both-forms rule is reciprocity rather than generosity. This profile is already on the consuming side of CycloneDX’s own deprecations. Tier 1 requires consumers to accept the deprecated curve alongside ellipticCurve for 1.6 compatibility, and either of signatureAlgorithmRef and relatedCryptographicAssets across the 1.7 deprecation. The policy asks tooling to do for our fields exactly what the profile already does for the core’s.

Where fields go

Deprecation is only triggered by core adoption, and Section 9 names the candidates in public. Quantum vulnerability classification, migration state, harvest exposure with its retention period, the CMVP certificate reference and entropy modelling are marked proposed upstream, because none of them is a financial-sector concern. Proposals follow this release candidate, with filing status tracked in the taxonomy repository. The sector- and computation-specific remainder, payment context, path records, trust anchors, assessment scaffolding, stays in the namespace permanently, which is what vendor namespaces are for.

Together with the pedigree decision, the discipline has three moves. Use what the standard already has, add only where it is silent, and hand over what generalises, on the terms above. The namespace is designed to shrink wherever the core grows, and the Section 9 table is the record of where.

What this buys

For anyone building tooling, the worst case on an appliedquantum field is now a documented rename with a two-version runway and a published translation. For the maintainers weighing the registration we filed as issue #189, it is a registrant whose exit terms preceded acceptance. Most deprecation policies are written after the first regret. Ours shipped in the release candidate, as Section 2, with the comment window open through October 31, 2026, which leaves ten weeks to tell us where the terms fall short. The page is short enough to read before you build on the fields, and it is written to be held against us.

ed53c567bc35d72dfc8e9a08403662f52deaf93d4990736d7dca4ea0dd4ee55f?s=120&d=mp&r=g
marin@ivezic.com | About me |  Other articles

Marin Ivezic is the founder and CEO of Applied Quantum, author of PostQuantum.com, and creator of the Applied Quantum PQC Migration Framework. He is also the author of Quantum Ready, a practitioner's guide to organizational quantum readiness. A former Fortune Global 500 CISO/CTO who has served as a Big 4 partner and leader at Accenture and IBM, he has advised governments on quantum threats since the early 2000s and led PQC migration programs across financial services, telecommunications, and critical infrastructure.