Which Regulators Require A Cryptographic Inventory?
A cryptographic inventory is binding in a few places and recommended almost everywhere else. Here is who requires one, what each expects it to contain, and where a CBOM is named.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Almost every post-quantum roadmap starts with the same step: find out where your organisation uses cryptography. A cryptographic inventory records the algorithms, protocols, keys and certificates in use, where they sit and what they protect. Without one, a migration plan is guesswork.
It is often said that regulators now require such an inventory everywhere. That is not accurate. As of October 2026, an inventory is binding under a short list of instruments, and recommended under many more. A cryptographic bill of materials (CBOM), a structured machine-readable inventory, is named by even fewer. This article sets out who requires what, using the status labels explained in the overview. It is general information, not legal advice.
Where An Inventory Is Binding Today
Five instruments make some form of cryptographic inventory a requirement, each with a different scope.
PCI DSS v4.0.1 requirement 12.3.3 expects a current list of the cipher suites and protocols in use, showing what each does and where it runs, plus an active watch on whether each stays safe and a written plan for reacting to cryptographic weaknesses that can be seen coming. The whole set is revisited at least every 12 months. Requirement 4.2.1.1 adds an inventory of the trusted keys and certificates that protect card numbers in transit. Both were best practices until 31 March 2025 and have been required since then, binding through card scheme contracts.1
The DORA technical standard for ICT risk requires EU financial entities under DORA’s full ICT risk framework to keep a register of all certificates and certificate-storing devices, at least for assets that support critical or important functions, and to keep it current.2 It does not name an algorithm inventory, but the same standard requires entities to update cryptography as cryptanalysis develops, which is hard to do without one.
SAMA Circular 482021280 requires Saudi financial institutions to make their procedures for identifying and classifying all cryptographic assets accurate and comprehensive by the end of Q4 2026.3 The UAE National Encryption Policy requires federal and emirate government entities and non-government critical infrastructure operators to keep a record of every system and application that relies on public key cryptography.4 The Council’s Information Assurance Standard v2.1 repeats that duty as a sub-control of control T3.4.4, but the control applies according to each entity’s risk assessment, and an entity may vary or skip its sub-controls with documented justification and accepted risk.5 In the United States, the Quantum Computing Cybersecurity Preparedness Act requires federal agencies to keep a current inventory of IT that is vulnerable to quantum decryption.6
India’s securities regulator, SEBI, sits between binding and recommended. Its Cybersecurity and Cyber Resilience Framework, which binds SEBI-regulated entities, lists indicative measures for quantum risk, and the first says that entities shall maintain an inventory of cryptographic assets, putting critical assets first for post-quantum migration.7 The wording is mandatory in form but presented as indicative, so how strictly it applies is a question for SEBI.
Where It Is Expected But Not Required
A longer list of regulators and agencies recommends an inventory without making it a rule. The EU NIS Cooperation Group says NIS2 entities should, at a minimum, build an inventory of cryptographic assets and dependency maps.8 FINMA in Switzerland recommends a risk analysis and inventory that prioritises data exposed to harvest now, decrypt later (Supervisory). In June 2025 the Japanese FSA told banks to start roadmap, inventory and risk assessment work immediately and said it would follow up through monitoring. OSFI’s quantum readiness bulletin in Canada makes inventory its second phase, and the UK NCSC advises a full discovery exercise by 2028.9
Singapore’s CSA asks critical infrastructure owners to submit a migration plan by 31 March 2027, which cannot be written without an inventory.10 The handbook calls its milestones requirements for these owners, but it also describes itself as informational and not mandatory, so this group labels them Supervisory. MAS’s 2024 advisory lists an inventory of cryptographic solutions among measures firms should consider.11 These are supervisory expectations or guidance, and the regional articles give the details.
Which Rules Name A CBOM
No regulator found requires private firms to produce a CBOM as of October 2026. The term appears in US federal policy and in India. OMB M-26-15 says agency inventory data should populate a central CBOM, and Executive Order 14412 directs CISA and NIST to publish the minimum elements of a CBOM within 270 days, which falls on 19 March 2027.12 India’s national quantum roadmap recommends that organisations request CBOMs from vendors from FY 2026-27 and make them mandatory in procurement from FY 2027-28. The RBI’s Q-SAFE committee will assess the financial sector’s cryptographic inventory through a CBOM.13
| Instrument | Inventory | Status | CBOM Named | Date |
|---|---|---|---|---|
| PCI DSS 12.3.3 and 4.2.1.1 | Cipher suites and protocols; trusted keys and certificates for card data in transit | Binding (contractual) | No | Since 31 March 2025; 12.3.3 review at least every 12 months |
| DORA RTS 2024/1774, Article 7(4) | Register of certificates and certificate-storing devices | Binding | No | Since 17 January 2025 |
| SAMA Circular 482021280 | Identify and classify all cryptographic assets | Binding | No | End Q4 2026 |
| UAE National Encryption Policy, section 6.1.1 | Systems and applications using public key cryptography | Binding for government entities and non-government CII; the matching IA Standard control T3.4.4 is risk-based | No | No deadline stated |
| US Public Law 117-260 | Federal IT vulnerable to quantum decryption | Binding (federal agencies) | No | Ongoing |
| OMB M-26-15 and EO 14412 | Agency inventories feeding a central CBOM | Binding (federal agencies); CBOM part is guidance | Yes | CBOM minimum elements due 19 March 2027 |
| India national roadmap; RBI Q-SAFE | Vendor CBOMs; sector inventory review | Guidance; Announcement | Yes | Vendor CBOMs from FY 2026-27 |
| SEBI CSCRF, Box Item 7 | Cryptographic assets, critical ones first for post-quantum migration | Binding framework; measure presented as indicative | No | In the framework since 20 August 2024 |
| EU NIS CG, FINMA, Japan FSA, OSFI, UK NCSC, MAS | Inventory of cryptographic assets | Guidance or Supervisory | No | Varies; UK discovery by 2028 |
Does A Binding Inventory Apply To You
The flowchart below is a first screen against the binding duties above. It does not cover every sector rule, and a no at the end does not mean an inventory is optional in practice: most supervisors now expect one.
Do you store, process or transmit payment card data?
- Yes:
Binding Under PCI DSS Keep the 4.2.1.1 inventory of trusted keys and certificates, and document and review the cipher suites and protocols in use at least every 12 months under 12.3.3. Other regimes below may also apply.
- No:
Are you an EU financial entity under DORA’s full ICT risk management framework?
- Yes:
Binding Under DORA Maintain the certificate register in RTS Article 7(4) and an encryption policy that can respond to cryptanalysis. Other regimes below may also apply.
- No:
Are you regulated by the Saudi Central Bank (SAMA)?
- Yes:
Binding Under SAMA Asset identification and classification procedures are due by end Q4 2026. Other regimes below may also apply.
- No:
Are you a UAE federal or emirate government entity, or a designated critical information infrastructure operator?
- Yes:
Binding Under The UAE National Encryption Policy Keep an inventory of public key cryptography use and prepare a transition plan. Other regimes below may also apply.
- No:
Are you a US federal agency?
- Yes:
Binding Under US Federal Law And OMB Guidance Public Law 117-260 and OMB guidance require an inventory of IT vulnerable to quantum decryption, feeding the migration plan due under M-26-15.
- No:
Are you regulated by SEBI in India?
- Yes:
Listed In A Binding Framework The CSCRF lists a cryptographic asset inventory among indicative measures for quantum risk. Check with SEBI how strictly it applies.
- No:
No Binding Duty Identified By These Questions Most supervisors and agencies still expect an inventory, and sector rules not covered here may apply. Check your regional article.
- Yes:
- Yes:
- Yes:
- Yes:
- Yes:
What A Combined Inventory Should Capture
The binding rules ask for overlapping fields. PCI DSS wants a current record of the cipher suites and protocols in use. DORA wants every certificate and the device that stores it. SAMA wants assets classified, which in practice means by data sensitivity and migration priority. The UAE policy wants every system that uses public key cryptography, the part a quantum computer would break.
An inventory built for PCI DSS, extended with certificate and key store data and with classification fields, covers most of the binding duties found in this research. The Preparing For Migration group explains how discovery works and what fields to record, and Cryptography Compliance covers the PCI and DORA wording in depth.
- In effect
European Union · European Commission Binding
Encryption policy, key lifecycle and certificate register rules apply through DORA from this date: the policy must provide for updating cryptography based on developments in cryptanalysis, and a register of certificates and certificate-storing devices must be kept up to date, at least for ICT assets supporting critical or important functions. The RTS itself entered into force on 15 July 2024.
- In effect
Global payments · PCI Security Standards Council Binding
Keep documentation of the cryptographic cipher suites and protocols in use, with a current inventory of what each does and where it runs, active tracking of whether each remains safe and a plan for reacting to foreseeable cryptographic weaknesses, and review it at least once every 12 months. Treated as a best practice until this date and required since.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.
- Upcoming
United States · The White House Binding
CISA, in coordination with NIST, must release public guidance on the minimum elements of a cryptographic bill of materials within 270 days of the order. The date shown is calculated by us as 270 days after 22 June 2026.
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
Submit a quantum-safe migration plan to CSA.
Footnotes
-
PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirements 4.2.1.1 and 12.3.3. pcisecuritystandards.org ↩
-
European Commission, Delegated Regulation (EU) 2024/1774, Articles 6(4) and 7(4), 13 March 2024. eur-lex.europa.eu ↩
-
Saudi Central Bank, Circular 482021280, “Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩
-
UAE Cyber Security Council, “National Encryption Policy v1.0”, September 2025, sections 1.2 and 6.1.1. csc.gov.ae ↩
-
UAE Cyber Security Council, “UAE Information Assurance Standard”, version 2.1, November 2025, sections 2.1 and 3.4, control T3.4.4. csc.gov.ae ↩
-
United States Congress, Quantum Computing Cybersecurity Preparedness Act, Public Law 117-260, section 4(a), December 2022. govinfo.gov ↩
-
Securities and Exchange Board of India, “Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities”, 20 August 2024, Box Item 7. sebi.gov.in ↩
-
NIS Cooperation Group, “EU Roadmap on PQC: Frequently Asked Questions”, section 7.4, 15 April 2026. ec.europa.eu ↩
-
FINMA, Guidance 05/2026, 9 July 2026 (finma.ch); Financial Services Agency of Japan, 24 June 2025 (fsa.go.jp); OSFI, “Quantum Readiness Phases and Timelines”, March 2026 (osfi-bsif.gc.ca); UK NCSC, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩
-
Cyber Security Agency of Singapore, GovTech and IMDA, “Quantum-Safe Handbook V1”, 16 July 2026, page 25. isomer-user-content.by.gov.sg ↩
-
Monetary Authority of Singapore, Circular MAS/TCRS/2024/01, “Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩
-
The White House, Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026, section 5(d); (govinfo.gov); and Office of Management and Budget, Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩
-
Reserve Bank of India, “Quantum Secure and Adaptive Financial Ecosystem (Q-SAFE): Setting up of an Expert Committee”, 25 May 2026 (rbi.org.in); and Department of Science and Technology, “Quantum-Safe Ecosystem in India”, May 2026. dst.gov.in ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.