India
NIST bloc Standard-contextualiserIndia is building a national quantum-safe ecosystem coordinated through the Department of Science and Technology under the National Quantum Mission, whose 2026 task force report sets a phased strategy for migration to post-quantum cryptography across critical sectors, with mandatory cryptographic inventories, crypto-agile design and a national testing and certification framework. NITI Aayog has published a national roadmap calling for a post-quantum cryptography transition plan, quantum-safe encryption planning in government systems, national testbeds and domestic post-quantum cryptographic stacks. CERT-In and MeitY have issued a transition roadmap and bill-of-materials guidance covering a Quantum and Cryptographic Bill of Materials, the Telecommunication Engineering Centre has published technical reports for the telecom sector and for quantum-secure 5G cores that recommend NIST post-quantum algorithms, and SEBI requires its regulated entities to run post-quantum risk assessments and maintain cryptographic-asset inventories. The DST Quantum-Safe Ecosystem report sets indicative national milestones of quantum resiliency for critical information infrastructure by 2029 and enterprise-wide post-quantum adoption by 2033. The wider effort follows the NIST post-quantum baseline, with indigenous work framed as deployment self-reliance intended to conform to those standards rather than replace them.
Governance credibility
| Criterion | Score | Confidence |
|---|---|---|
| Relevance | 2.0 / 2 | Medium |
| Coherence | 2.0 / 2 | Medium |
| Effectiveness | 2.0 / 2 | Medium |
| Efficiency | 2.0 / 2 | Medium |
| Governance | 2.0 / 2 | Medium |
| Impact | 2.0 / 2 | Medium |
Regulatory basis
- SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) for Regulated Entities
- CERT-In Directions of 28 April 2022 under section 70B(6) of the IT Act 2000
- NITI Aayog Roadmap for Transforming India into a Leading Quantum-Powered Economy
- CERT-In, MeitY and TEC post-quantum migration roadmap, QBOM/CBOM guidance and technical reports
Legal status: Binding
Entities regulated by SEBI (stock exchanges, depositories, brokers, asset managers and other market intermediaries) must comply with the CSCRF, which is mandatory and includes maintaining a cryptographic-asset inventory and conducting post-quantum risk assessment. Separately, CERT-In's 2022 Directions impose legally binding general cyber security and incident-reporting duties across the economy. The wider move to the NIST post-quantum baseline is set out in the CERT-In, MeitY and TEC roadmap and technical reports, which are guidance rather than binding rules.
Standards and algorithms
No standards or algorithms specified.
Hybrid stance
Recommended
Migration timeline
- 2029Quantum resiliency of critical information infrastructure (DST Quantum-Safe Ecosystem report)
- 2033Enterprise-wide post-quantum cryptography adoption (DST Quantum-Safe Ecosystem report)
- 2035National quantum vision horizon with post-quantum cryptography transition plan for government systems (NITI Aayog roadmap)
Target completion: Phased (no fixed end)
Governmental and standards bodies
- DST (National Quantum Mission) Department of Science and Technology, sets national quantum-safe migration strategy through its task force
- NITI Aayog National policy think tank, published the national roadmap calling for a post-quantum cryptography transition plan, quantum-safe encryption planning in government systems and domestic post-quantum cryptographic stacks
- CERT-In Indian Computer Emergency Response Team, issued the quantum cyber readiness transition roadmap and the QBOM/CBOM bill-of-materials guidance
- MeitY Ministry of Electronics and Information Technology, co-author of the quantum-safe cybersecurity whitepaper
- TEC Telecommunication Engineering Centre, published the technical reports on migration to post-quantum cryptography and on quantum-secure 5G cores using NIST post-quantum algorithms
- SEBI Securities and Exchange Board of India, requires post-quantum risk assessment and cryptographic-asset inventories of regulated entities
Key institutional documents
- Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM (Version 2.0)
- Technical Report on Quantum Secure 5G / beyond 5G Core using Post-Quantum Cryptography (TEC 910028:2025)
- Roadmap for Transforming India into a Leading Quantum-Powered Economy
- Technical Clarifications to the CSCRF for SEBI Regulated Entities
- Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI Regulated Entities
- Technical Report on Migration to Post-Quantum Cryptography (TEC 910018:2025)
- MeitY launches whitepaper to guide India's shift towards Atmanirbhar & Quantum-Safe Cybersecurity
- Transitioning to Quantum Cyber Readiness (CERT-In Whitepaper CIWP-2025-0002)
- Report on Quantum-Safe Ecosystem in India
- Implementation of Quantum Safe Ecosystem in India - Report of the Task Force
Advising on this transition, or your own sector's? Request a briefing →