Owned by neither

Eleven words of governance

Two frameworks consume the Applied Quantum CBOM Profile, the Cryptographic Concentration Framework and the PQC Migration Framework, and the front matter of the August 2026 release candidate answers the governance question in eleven words: “Owned by neither. Both cite a minimum version of this document.”

That sentence pair is architecture, not sentiment. A taxonomy owned by either framework would follow that framework’s release cycle and vocabulary, and the other consumer would be citing a dependency it does not control, on a schedule it does not set.

Most industry artifacts that claim neutrality have an owner with a favourite. We built this one so the claim is checkable.

Three mechanisms

Versioning is the first mechanism, and it is semantic and independent of both frameworks. Each framework cites a minimum version rather than aligning baselines, because this is a shared dependency rather than an extension of either. A CCF release does not move the Profile, and a PQC Migration Framework release doesn’t either. When the Profile does move, consumers raise their cited minimum on their own timetable, and our shipping a release changes nothing for them by itself.

The second mechanism is the location of requirements. The Profile defines fields, types and semantics, and it never says what any assessment must collect. What a framework requires of a CBOM is that framework’s own document. The CCF publishes a CBOM Conformance Statement at ccframework.org mapping fields to its conformance levels, and if the PQC Migration Framework publishes an equivalent, it does so at pqcframework.org. Requirements travel with the framework that imposes them.

The third mechanism is the intake question. When either framework asks for a field, the first question is whether it belongs in the shared taxonomy at all or in that framework’s own documents. A field enters the Profile when more than one consumer could use it as specified, and stays out when it encodes one framework’s computation. We ran that test throughout the v1.0-RC preparation, and the changelog records requests answered with no new field.

One declared exception

A clean boundary claim would be easy to make and false, so we declare the one crossing instead. CCF conformance level 1 requires pqc:vulnerabilityStatus from Tier 2, because layer 1 scoping runs on the Shor and Grover classification rather than on the raw security level, and no other Tier 2 field is required by CCF.

A boundary with one documented crossing can be enforced, and an undocumented purity claim can’t be checked at all. The exception is stated in Section 3, next to the tier table it cuts across.

What this buys a third consumer

Neutral dependencies spread in a way owned ones never do. Malcom McLean released the shipping container’s patents royalty-free during ISO standardisation in the late 1960s, and the box conquered every carrier because no carrier owned the specification. The same logic applies here at a smaller scale.

If you run a framework that needs cryptographic inventory semantics, the adoption path is the same one the first two consumers use. Cite a minimum Profile version, publish your own conformance document on your own property, and request fields through the taxonomy repository’s issue tracker. No permission from the CCF or the PQC Migration Framework appears anywhere in that path, and nothing in the Profile’s licence or governance lets either of them add one.

The independence extends to the small things. The Profile keeps its own domain, its own repository and its own accent on the covers, and even the order the two consumers are named in is not fixed across the family’s documents, because a permanent first place reads as a ranking.

Where things stand

The Profile is at cbomprofile.org as v1.0-RC, with comment open through October 31, 2026, and the CCF’s conformance statement is at ccframework.org. Governance questions belong on the taxonomy repository, in public, where our answers can be cited against us later. That is what owned by neither costs, and what it is for.