Cryptographic Bill of Materials (CBOM):
Your First Step to Quantum Readiness
You can't protect what you can't see. Build an approved-scope inventory of observable cryptographic assets, disclose residual gaps, and prioritize your PQC migration.
What is a Cryptographic Bill of Materials?
A Cryptographic Bill of Materials (CBOM) is a machine-readable record of cryptographic assets within a defined scope — algorithms, keys, certificates, libraries, and configurations. It answers the fundamental question: “What cryptography are we using, where, and is it quantum-safe?”
Just as SBOM (Software Bill of Materials) catalogs software dependencies for supply chain security, CBOM catalogs cryptographic implementations for quantum readiness. The key difference: CBOM goes deeper into how cryptography is configured and deployed, not just which libraries are present.
Without a current, scope-bounded CBOM, PQC migration is difficult to plan, budget, or execute. You cannot prioritize what you haven't inventoried. Coverage goals and residual gaps must remain visible when estimating migration timelines.
Why CBOM is Critical for PQC
- NIST IR 8547: Requires cryptographic inventory as prerequisite for migration planning
- OMB M-26-15: Scoped federal agencies use cryptographic inventory and prioritization to support the migration plans required by the 2026 memo
- CNSA 2.0: Applicable National Security Systems follow staged transition milestones and program-specific scope
- Inventory discipline: Report measured coverage and residual unknowns instead of assuming the initial system estimate is complete
Key Components of a Cryptographic Inventory
A defensible CBOM records six critical areas within its approved infrastructure, application, and data-store scope.
Algorithms in Use
RSA, ECC, AES, SHA, 3DES, and all cryptographic algorithms deployed across applications and infrastructure.
Key Lengths & Configurations
Key sizes, rotation policies, and cryptographic parameters that determine security strength.
Certificate Authorities & PKI
Root CAs, intermediate CAs, certificate chains, and trust hierarchies.
Key Management Systems
HSMs, cloud KMS, vaults, and all systems responsible for key lifecycle management.
Cryptographic Libraries
All crypto libraries, SDKs, and dependencies in your software supply chain.
Protocol Configurations
TLS versions, cipher suites, and cryptographic protocol settings.
Discovery Methods
Building defensible CBOM coverage requires multiple complementary discovery approaches. No single method captures everything.
Network Traffic Analysis
Passive inspection of TLS handshakes, certificate exchanges, and encrypted protocol negotiations to identify algorithms and configurations in transit.
Code Scanning & SBOM Integration
Static analysis of source code, binaries, and dependencies to identify cryptographic function calls and library usage.
Configuration Audits
Direct inspection of server configurations, HSM settings, and key management system exports.
Certificate Inventory
Comprehensive mapping of all certificates, their algorithms, validity periods, and trust chains.
API & Endpoint Scanning
Active probing of APIs and endpoints to determine cryptographic posture and supported algorithms.
QScout: Automated CBOM Generation
QScout's multi-level module stack builds your CBOM across discovery, cryptographic inventory, PQC readiness, and evidence workflows.
Certificate chains, cipher suites, protocol versions, and handshake analysis
HSM configurations, KMS policies, key rotation, and lifecycle management
CA hierarchies, certificate policies, revocation mechanisms
DKIM, DMARC, SPF, S/MIME, and email transport encryption
JWT/JWE, API authentication, session management, token signing
SSH, IPSec, VPN configurations, and protocol crypto
Database encryption, file system crypto, backup encryption
PQC readiness, HNDL exposure, hybrid TLS, migration gaps
Point-in-Time vs. Continuous
Point-in-Time Scan: QScout delivers initial approved-scope CBOM findings within the engagement window, producing a bounded snapshot with residual coverage gaps identified.
Continuous Monitoring: QScout Pulse performs ongoing governed checks for cryptographic drift, new deployments, and configuration changes within approved scope.
Integration with Asset Management
CBOM data exports to JSON and SARIF formats for integration with existing CMDB, SBOM tools, and vulnerability management platforms.
Maps directly to NIST CSF 2.0 cryptographic controls and feeds into Board Number risk calculations for executive reporting.
CBOM Prioritization Framework
Not all cryptographic assets require immediate attention. Use this framework to prioritize migration based on risk, complexity, and business impact.
Data Sensitivity Classification
30%Public, Internal, Confidential, Restricted, Top Secret — each level increases migration priority.
Algorithm Vulnerability Scoring
25%Shor-vulnerable algorithms (RSA, ECC, DH) scored higher than symmetric algorithms with adequate key lengths.
Migration Complexity Assessment
20%Systems with deep crypto dependencies, legacy code, or third-party constraints require more time.
Business Criticality Weighting
25%Revenue-generating systems, customer-facing applications, and regulatory-scoped assets prioritized.
Priority Scoring Example
| System | Sensitivity | Vulnerability | Complexity | Criticality | Priority Score |
|---|---|---|---|---|---|
| Customer Payment API | 95 | 90 | 70 | 100 | 91.5 |
| Internal HR Portal | 60 | 85 | 40 | 50 | 62.5 |
| Public Marketing Site | 10 | 85 | 20 | 30 | 36.0 |
7-Step Guide to Building Your CBOM
A practical framework for creating your first cryptographic inventory in 4 weeks.
Define Scope and Objectives
Week 1Identify all systems, applications, and infrastructure components that will be included in the cryptographic inventory. Set approved-scope coverage goals and define how residual unknowns will be recorded.
Deploy Automated Discovery Tools
Weeks 1-2Implement network traffic analysis, code scanning, and configuration auditing tools. Configure passive monitoring and schedule active scans across all in-scope environments.
Catalog Algorithms and Key Lengths
Week 2Document all cryptographic algorithms in use, key lengths, and configurations. Create a structured inventory database with consistent naming conventions.
Inventory PKI and Certificate Infrastructure
Week 2-3Map certificate authorities, certificate chains, key management systems (HSMs, KMS), and certificate lifecycle management processes across the organization.
Assess Cryptographic Libraries and Dependencies
Week 3Identify all cryptographic libraries, SDKs, and third-party dependencies. Integrate with existing SBOM processes and identify version-specific vulnerabilities.
Classify Quantum Vulnerability
Week 3-4Score each cryptographic asset against quantum vulnerability criteria. Apply the prioritization framework to rank systems for migration planning.
Establish Continuous Monitoring
Week 4 + OngoingImplement ongoing cryptographic drift detection, change management integration, and regular review cadence to keep the CBOM current.
Frequently Asked Questions
How long does it take to build a CBOM?
Initial CBOM creation typically takes 2-4 weeks for mid-sized organizations and 1-3 months for large enterprises. This includes automated discovery (1-2 weeks), manual verification and gap-filling (1-2 weeks), and classification/prioritization (1 week). QScout Surface, Silver, or Gold can shorten the first discovery cycle to about 7 days, and organizations that need ongoing drift detection can extend into QScout Pulse afterward.
What tools are used for cryptographic discovery?
Cryptographic discovery combines multiple approaches: network traffic analysis (TLS inspection, protocol scanning), static code analysis (grep-based and AST parsing), configuration audits (HSM, KMS, PKI), certificate transparency log monitoring, API endpoint assessment, and SBOM integration. QScout Surface, Silver, and Gold scope depths bring these methods together in deeper scoped engagements when first-step intake is no longer enough.
How often should I update my cryptographic inventory?
Best practice is continuous monitoring with formal reviews quarterly. At minimum, update the CBOM whenever major infrastructure changes occur, new applications deploy, or cryptographic policies change. NIST and OMB M-23-02 recommend maintaining a current inventory as part of PQC migration readiness.
What's the difference between CBOM and SBOM?
SBOM (Software Bill of Materials) lists all software components and dependencies in an application. CBOM (Cryptographic Bill of Materials) specifically inventories cryptographic algorithms, keys, certificates, and related configurations. A CBOM can be derived from SBOM data but goes deeper into cryptographic implementation details that SBOM alone does not capture.
Request QScout assessment
Get an approved-scope CBOM snapshot with residual coverage gaps disclosed. QScout uses multiple discovery methods to identify and classify observable cryptographic assets within the approved scope, with dedicated quantum-risk analysis for PQC readiness assessment.