REGULATIONS ACROSS REGIONS / INTERMEDIATE

Which Regulators Require A Cryptographic Inventory?

A cryptographic inventory is binding in a few places and recommended almost everywhere else. Here is who requires one, what each expects it to contain, and where a CBOM is named.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Almost every post-quantum roadmap starts with the same step: find out where your organisation uses cryptography. A cryptographic inventory records the algorithms, protocols, keys and certificates in use, where they sit and what they protect. Without one, a migration plan is guesswork.

It is often said that regulators now require such an inventory everywhere. That is not accurate. As of October 2026, an inventory is binding under a short list of instruments, and recommended under many more. A cryptographic bill of materials (CBOM), a structured machine-readable inventory, is named by even fewer. This article sets out who requires what, using the status labels explained in the overview. It is general information, not legal advice.

Where An Inventory Is Binding Today

Five instruments make some form of cryptographic inventory a requirement, each with a different scope.

PCI DSS v4.0.1 requirement 12.3.3 expects a current list of the cipher suites and protocols in use, showing what each does and where it runs, plus an active watch on whether each stays safe and a written plan for reacting to cryptographic weaknesses that can be seen coming. The whole set is revisited at least every 12 months. Requirement 4.2.1.1 adds an inventory of the trusted keys and certificates that protect card numbers in transit. Both were best practices until 31 March 2025 and have been required since then, binding through card scheme contracts.1

The DORA technical standard for ICT risk requires EU financial entities under DORA’s full ICT risk framework to keep a register of all certificates and certificate-storing devices, at least for assets that support critical or important functions, and to keep it current.2 It does not name an algorithm inventory, but the same standard requires entities to update cryptography as cryptanalysis develops, which is hard to do without one.

SAMA Circular 482021280 requires Saudi financial institutions to make their procedures for identifying and classifying all cryptographic assets accurate and comprehensive by the end of Q4 2026.3 The UAE National Encryption Policy requires federal and emirate government entities and non-government critical infrastructure operators to keep a record of every system and application that relies on public key cryptography.4 The Council’s Information Assurance Standard v2.1 repeats that duty as a sub-control of control T3.4.4, but the control applies according to each entity’s risk assessment, and an entity may vary or skip its sub-controls with documented justification and accepted risk.5 In the United States, the Quantum Computing Cybersecurity Preparedness Act requires federal agencies to keep a current inventory of IT that is vulnerable to quantum decryption.6

India’s securities regulator, SEBI, sits between binding and recommended. Its Cybersecurity and Cyber Resilience Framework, which binds SEBI-regulated entities, lists indicative measures for quantum risk, and the first says that entities shall maintain an inventory of cryptographic assets, putting critical assets first for post-quantum migration.7 The wording is mandatory in form but presented as indicative, so how strictly it applies is a question for SEBI.

Where It Is Expected But Not Required

A longer list of regulators and agencies recommends an inventory without making it a rule. The EU NIS Cooperation Group says NIS2 entities should, at a minimum, build an inventory of cryptographic assets and dependency maps.8 FINMA in Switzerland recommends a risk analysis and inventory that prioritises data exposed to harvest now, decrypt later (Supervisory). In June 2025 the Japanese FSA told banks to start roadmap, inventory and risk assessment work immediately and said it would follow up through monitoring. OSFI’s quantum readiness bulletin in Canada makes inventory its second phase, and the UK NCSC advises a full discovery exercise by 2028.9

Singapore’s CSA asks critical infrastructure owners to submit a migration plan by 31 March 2027, which cannot be written without an inventory.10 The handbook calls its milestones requirements for these owners, but it also describes itself as informational and not mandatory, so this group labels them Supervisory. MAS’s 2024 advisory lists an inventory of cryptographic solutions among measures firms should consider.11 These are supervisory expectations or guidance, and the regional articles give the details.

Which Rules Name A CBOM

No regulator found requires private firms to produce a CBOM as of October 2026. The term appears in US federal policy and in India. OMB M-26-15 says agency inventory data should populate a central CBOM, and Executive Order 14412 directs CISA and NIST to publish the minimum elements of a CBOM within 270 days, which falls on 19 March 2027.12 India’s national quantum roadmap recommends that organisations request CBOMs from vendors from FY 2026-27 and make them mandatory in procurement from FY 2027-28. The RBI’s Q-SAFE committee will assess the financial sector’s cryptographic inventory through a CBOM.13

InstrumentInventoryStatusCBOM NamedDate
PCI DSS 12.3.3 and 4.2.1.1Cipher suites and protocols; trusted keys and certificates for card data in transitBinding (contractual)NoSince 31 March 2025; 12.3.3 review at least every 12 months
DORA RTS 2024/1774, Article 7(4)Register of certificates and certificate-storing devicesBindingNoSince 17 January 2025
SAMA Circular 482021280Identify and classify all cryptographic assetsBindingNoEnd Q4 2026
UAE National Encryption Policy, section 6.1.1Systems and applications using public key cryptographyBinding for government entities and non-government CII; the matching IA Standard control T3.4.4 is risk-basedNoNo deadline stated
US Public Law 117-260Federal IT vulnerable to quantum decryptionBinding (federal agencies)NoOngoing
OMB M-26-15 and EO 14412Agency inventories feeding a central CBOMBinding (federal agencies); CBOM part is guidanceYesCBOM minimum elements due 19 March 2027
India national roadmap; RBI Q-SAFEVendor CBOMs; sector inventory reviewGuidance; AnnouncementYesVendor CBOMs from FY 2026-27
SEBI CSCRF, Box Item 7Cryptographic assets, critical ones first for post-quantum migrationBinding framework; measure presented as indicativeNoIn the framework since 20 August 2024
EU NIS CG, FINMA, Japan FSA, OSFI, UK NCSC, MASInventory of cryptographic assetsGuidance or SupervisoryNoVaries; UK discovery by 2028
Cryptographic inventory and CBOM expectations by instrument, as of October 2026.

Does A Binding Inventory Apply To You

The flowchart below is a first screen against the binding duties above. It does not cover every sector rule, and a no at the end does not mean an inventory is optional in practice: most supervisors now expect one.

Do you store, process or transmit payment card data?

  • Yes:

    Binding Under PCI DSS Keep the 4.2.1.1 inventory of trusted keys and certificates, and document and review the cipher suites and protocols in use at least every 12 months under 12.3.3. Other regimes below may also apply.

  • No:

    Are you an EU financial entity under DORA’s full ICT risk management framework?

    • Yes:

      Binding Under DORA Maintain the certificate register in RTS Article 7(4) and an encryption policy that can respond to cryptanalysis. Other regimes below may also apply.

    • No:

      Are you regulated by the Saudi Central Bank (SAMA)?

      • Yes:

        Binding Under SAMA Asset identification and classification procedures are due by end Q4 2026. Other regimes below may also apply.

      • No:

        Are you a UAE federal or emirate government entity, or a designated critical information infrastructure operator?

        • Yes:

          Binding Under The UAE National Encryption Policy Keep an inventory of public key cryptography use and prepare a transition plan. Other regimes below may also apply.

        • No:

          Are you a US federal agency?

          • Yes:

            Binding Under US Federal Law And OMB Guidance Public Law 117-260 and OMB guidance require an inventory of IT vulnerable to quantum decryption, feeding the migration plan due under M-26-15.

          • No:

            Are you regulated by SEBI in India?

            • Yes:

              Listed In A Binding Framework The CSCRF lists a cryptographic asset inventory among indicative measures for quantum risk. Check with SEBI how strictly it applies.

            • No:

              No Binding Duty Identified By These Questions Most supervisors and agencies still expect an inventory, and sector rules not covered here may apply. Check your regional article.

A first screen for binding cryptographic inventory duties, as of October 2026. More than one regime can apply at once, so a yes does not rule out the others. It is not legal advice.

What A Combined Inventory Should Capture

The binding rules ask for overlapping fields. PCI DSS wants a current record of the cipher suites and protocols in use. DORA wants every certificate and the device that stores it. SAMA wants assets classified, which in practice means by data sensitivity and migration priority. The UAE policy wants every system that uses public key cryptography, the part a quantum computer would break.

An inventory built for PCI DSS, extended with certificate and key store data and with classification fields, covers most of the binding duties found in this research. The Preparing For Migration group explains how discovery works and what fields to record, and Cryptography Compliance covers the PCI and DORA wording in depth.

  1. In effect

    European Union · European Commission Binding

    Encryption policy, key lifecycle and certificate register rules apply through DORA from this date: the policy must provide for updating cryptography based on developments in cryptanalysis, and a register of certificates and certificate-storing devices must be kept up to date, at least for ICT assets supporting critical or important functions. The RTS itself entered into force on 15 July 2024.

    Delegated Regulation (EU) 2024/1774 (DORA ICT risk RTS), Articles 6 and 7. Applies to EU financial entities under the full DORA ICT risk framework. Source · Verified 7 Oct 2026

  2. In effect

    Global payments · PCI Security Standards Council Binding

    Keep documentation of the cryptographic cipher suites and protocols in use, with a current inventory of what each does and where it runs, active tracking of whether each remains safe and a plan for reacting to foreseeable cryptographic weaknesses, and review it at least once every 12 months. Treated as a best practice until this date and required since.

    PCI DSS v4.0.1, requirement 12.3.3. Applies to entities in scope of PCI DSS (contractual standard), for all cipher suites and protocols used to meet PCI DSS requirements. Source · Verified 7 Oct 2026

  3. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  4. Upcoming

    United States · The White House Binding

    CISA, in coordination with NIST, must release public guidance on the minimum elements of a cryptographic bill of materials within 270 days of the order. The date shown is calculated by us as 270 days after 22 June 2026.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, section 5(d). Applies to CISA and NIST (the resulting guidance is for public use). Source · Explainer · Verified 7 Oct 2026

  5. Upcoming

    Singapore · Cyber Security Agency of Singapore Supervisory

    Submit a quantum-safe migration plan to CSA.

    CSA Quantum-Safe Handbook (16 July 2026). Applies to critical information infrastructure owners. Source · Verified 7 Oct 2026

Inventory-related dates. PCI DSS, DORA and SAMA are binding on the organisations they cover; the US date is a duty on CISA and NIST to publish guidance; the Singapore date is a supervisory milestone for critical infrastructure owners.

Footnotes

  1. PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirements 4.2.1.1 and 12.3.3. pcisecuritystandards.org ↩

  2. European Commission, Delegated Regulation (EU) 2024/1774, Articles 6(4) and 7(4), 13 March 2024. eur-lex.europa.eu ↩

  3. Saudi Central Bank, Circular 482021280, “Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩

  4. UAE Cyber Security Council, “National Encryption Policy v1.0”, September 2025, sections 1.2 and 6.1.1. csc.gov.ae ↩

  5. UAE Cyber Security Council, “UAE Information Assurance Standard”, version 2.1, November 2025, sections 2.1 and 3.4, control T3.4.4. csc.gov.ae ↩

  6. United States Congress, Quantum Computing Cybersecurity Preparedness Act, Public Law 117-260, section 4(a), December 2022. govinfo.gov ↩

  7. Securities and Exchange Board of India, “Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities”, 20 August 2024, Box Item 7. sebi.gov.in ↩

  8. NIS Cooperation Group, “EU Roadmap on PQC: Frequently Asked Questions”, section 7.4, 15 April 2026. ec.europa.eu ↩

  9. FINMA, Guidance 05/2026, 9 July 2026 (finma.ch); Financial Services Agency of Japan, 24 June 2025 (fsa.go.jp); OSFI, “Quantum Readiness Phases and Timelines”, March 2026 (osfi-bsif.gc.ca); UK NCSC, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩

  10. Cyber Security Agency of Singapore, GovTech and IMDA, “Quantum-Safe Handbook V1”, 16 July 2026, page 25. isomer-user-content.by.gov.sg ↩

  11. Monetary Authority of Singapore, Circular MAS/TCRS/2024/01, “Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩

  12. The White House, Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026, section 5(d); (govinfo.gov); and Office of Management and Budget, Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩

  13. Reserve Bank of India, “Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE): Setting up of an Expert Committee”, 25 May 2026 (rbi.org.in); and Department of Science and Technology, “Quantum-Safe Ecosystem in India”, May 2026. dst.gov.in ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.