Srijan Dhare, founder and CEO of QuantumGenie, shared the stage with representatives from NIST, HEQA Security and ID Quantique (an IonQ company) at the September 22 PQC Summit held at The Hotel at the University of Maryland. The event, a focused precursor to Quantum World Congress 2026, highlighted the critical need for automated tools in the transition to post-quantum cryptography.
Dhare emphasized a core challenge, stating, “You cannot migrate what you don’t see or what you don’t know,” and described how QuantumGenie’s platform combines discovery, attribution and continuous monitoring to map an organization’s cryptographic footprint. The Westlake Village, California-based software company’s approach centers automation on maintaining a live Cryptographic Bill of Materials for effective risk assessment and remediation.
QuantumGenie’s CBOM Platform Drives Automated PQC Migration
QuantumGenie’s CBOM platform addresses a critical challenge in post-quantum cryptography (PQC) migration: maintaining a continuously updated cryptographic inventory. The company’s approach, detailed at the September 22 PQC Summit, centers on a live Cryptographic Bill of Materials (CBOM) that maps cryptographic dependencies to applications, services and infrastructure, QuantumGenie says. This dynamic inventory contrasts with static, point-in-time assessments that quickly become obsolete in modern, rapidly changing enterprise environments.
The platform uses API connectors, agent-based and agentless discovery and source-code analysis to achieve this continuous monitoring. This initial phase focuses on identifying existing cryptographic implementations without initiating any changes, allowing for a comprehensive assessment of the organization’s PQC readiness. QuantumGenie’s technology normalizes algorithm identifiers, key parameters, and certificate attributes across diverse sources, enabling teams to differentiate between classical, hybrid and fully post-quantum implementations. The summit discussions highlighted the importance of interoperability and authentication alongside encryption in PQC migration.
QuantumGenie’s architecture is designed to address both encryption and authentication, encompassing ML-KEM key establishment, ML-DSA signatures, PKI integration, multi-factor authentication dependencies, and identity lifecycle evidence. This approach recognizes that upgrading key establishment protocols is only the first step. Organizations must also plan for the migration of digital signatures to avoid repeating the process. The company’s evidence model aims to maintain traceability throughout the entire migration lifecycle, providing a clear audit trail of cryptographic changes.
Automation is central to QuantumGenie’s strategy, handling the repetitive tasks of discovery, normalization, attribution, and monitoring, according to the company. This allows human decision-makers to focus on policy, business priorities, validation of findings, treatment of legacy systems and ultimately, production migration. Dhare described this as creating “an engine that performs while you sleep,” emphasizing the platform’s ability to operate continuously in the background.
The timing of this technology coincides with a shift in U.S. PQC policy from standards development to implementation. With NIST finalizing ML-KEM, ML-DSA and SLH-DSA as FIPS 203, 204, and 205, organizations are now expected to begin applying these standards.
Executive Order 14412 and OMB Memorandum M-26-15 further reinforce this mandate, directing federal agencies to establish migration leadership, maintain cryptographic inventories and create prioritized migration plans. QuantumGenie’s CBOM platform provides the foundational inventory and monitoring capabilities needed to meet these requirements, enabling organizations to proactively address the quantum threat and ensure the long-term security of their systems., the firm reports.



See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
