PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert

CBOM · Cryptographic visibility

Know every algorithm, key and certificate you run

Build a governed Cryptographic Bill of Materials across applications, infrastructure and suppliers, and use it to remove weak cryptography and plan post-quantum migration.

AlgorithmsCertificatesKeysProtocolsTLS configPKICrypto librariesLifecycle
cbom · Relationship pathIllustrative
  1. Assetcore-banking-db
  2. Applicationledger-service
  3. CryptoTLS 1.2 · RSA key exchange
  4. Certificate*.ledger.internal
  5. AlgorithmRSA-2048 · SHA-256
  6. RiskQuantum-vulnerable · expires 41d

Why CBOM

Cryptographic Bill of Materials

Cryptography is spread across code, servers, HSMs, cloud services, devices and supplier products, and rarely has one owner. A CBOM records which algorithms, keys, protocols and certificates are in use, where, and how strong they are. CERT-In, SEBI and post-quantum roadmaps in India, the US, the EU and the UK now expect that inventory to exist and to be kept current.

What CBOM tracks

Algorithms & key sizesSymmetric, asymmetric and hash usage by asset
Certificates & PKIIssuer, chain, validity and renewal ownership
Protocols & TLSVersions, cipher suites and configuration drift
Crypto librariesOpenSSL, BoringSSL, Bouncy Castle and others, by version
Weak & deprecated usageLegacy protocols, short keys, deprecated hashes
Certificate lifecycleExpiry forecasting and owner notifications

Capabilities

What IntelliXBOM does with your CBOM.

One governed inventory, correlated with the rest of your BOMs, the risks they carry and the controls they support.

Generate and ingest CBOMs

Bring in CycloneDX CBOMs from code scanners, network scans, key and certificate exports and suppliers, and generate CBOMs in CycloneDX and SPDX.

Validate against CERT-In fields

Check each algorithm, key, protocol and certificate against required-field policies such as CERT-In's Table 9 minimum elements, and see exactly what is missing.

Version history and drift

Keep every CBOM version and compare them, so reintroduced protocols, new weak algorithms and lost coverage are visible between reviews.

Risk correlation

Correlate cryptographic assets with vulnerabilities, known-exploited lists, end-of-life data and the business services that depend on them.

Framework mapping and evidence

Map the inventory to controls in CERT-In, SEBI CSCRF, NIST and CNSA 2.0 guidance and produce timestamped evidence for audits and regulators.

Self-hosted and air-gapped

Keep a sensitive map of your cryptography inside your own boundary, on-premise, in a private cloud or fully air-gapped.

How it works

From collection to evidence.

The same five-step loop runs continuously, so the CBOM never becomes yesterday’s inventory.

  1. 01Discover

    Collect cryptographic assets from source-code and container scans, TLS and SSH scans, HSM, KMS and PKI exports, and supplier CBOMs.

  2. 02Normalise

    Merge results into CycloneDX cryptographic-asset components, deduplicate them and link each to its software component, service and owner.

  3. 03Validate

    Check each CBOM against schema and required-field policies such as CERT-In's minimum elements.

  4. 04Correlate

    Relate assets to vulnerabilities, end-of-life data and business services, and compare against the previous version to detect drift.

  5. 05Evidence

    Map the inventory to framework controls, record decisions and export timestamped evidence for each review cycle.

Use cases

The questions CBOM answers.

Each question resolves to a governed, versioned record, and to the frameworks that record helps provide evidence for.

Which of our services still accept TLS 1.0 or 1.1?

Query protocol assets by version across every scanned endpoint, linked to the owning service. RFC 8996 deprecates both versions.

Where do we use RSA and elliptic-curve cryptography that will need post-quantum migration?

Filter algorithm assets by primitive and quantum security level, then rank them by the business service and data they protect.

Which certificates expire in the next 30 days and who owns them?

Sort certificate assets by Not Valid After and route each to the named owner of the service that presents it.

Does this supplier's CBOM meet CERT-In's minimum elements?

Validate the delivered CBOM against a CERT-In required-field policy and return a per-asset list of missing fields to the supplier.

CERT-In BOM guidelinesRBISEBI CSCRFNIST PQCSee compliance mapping →

CBOM questions, answered

What is a CBOM?

A Cryptographic Bill of Materials is a machine-readable inventory of the cryptographic assets used by software or systems: algorithms, keys, protocols and certificates. It records the properties that determine each asset's strength and lifetime and links it to the components that use it. CERT-In's Version 2.0 guidelines define minimum elements for each of the four asset types.

Is a CBOM required in India?

CERT-In's Technical Guidelines v2.0 (July 2025) recommend that government, public sector and essential services organisations require CBOMs in related procurements, developments and integrations. SEBI's CSCRF FAQs expect regulated entities to maintain an inventory of cryptographic assets including keys, certificates and algorithms. India's DST task force report of February 2026 also calls for CBOMs as part of quantum-safe migration.

What format should a CBOM use?

CERT-In recommends recognised formats such as SPDX or CycloneDX. CycloneDX added dedicated support for cryptographic assets in version 1.6, released in April 2024, with a cryptoProperties object covering algorithms, certificates, protocols and related cryptographic material.

How does a CBOM help with post-quantum cryptography?

A CBOM shows where quantum-vulnerable algorithms such as RSA and elliptic-curve schemes are used, so migration can be prioritised by exposure and data lifetime. NIST's draft IR 8547 proposes deprecating these algorithms at the 112-bit level after 2030 and disallowing them after 2035. The EU and UK roadmaps both place cryptographic discovery at the start of migration.

How is a CBOM different from an SBOM?

An SBOM lists software components such as libraries and their versions. A CBOM lists the cryptography those components use, including protocol versions, cipher suites, key sizes and certificate expiry, which an SBOM does not capture. CycloneDX can hold both in one document and link them.

How often should a CBOM be updated?

Code-level CBOMs should be regenerated with each build or release, and infrastructure inventories on a regular schedule. CERT-In's guidelines recommend reflecting changes promptly and conducting scheduled reviews at least quarterly to verify accuracy and completeness.

Sources

  1. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  2. CycloneDX v1.6 Released, Advances Software Supply Chain Security with Cryptographic Bill of Materials and Attestations (9 April 2024)OWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.6-released/
  3. FAQs on Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI REs (11 June 2025)SEBIwww.sebi.gov.in/sebi_data/faqfiles/jun-2025/1749647139924.pdf
  4. Implementation of Quantum Safe Ecosystem in India: Report of the Task Force (February 2026)Department of Science and Technology, Government of Indiadst.gov.in/sites/default/files/Report_TaskForce_PQMigration_4Feb26%20(v1).pdf
  5. M-23-02, Migrating to Post-Quantum Cryptography (18 November 2022)US Office of Management and Budgetwww.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
  6. NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  7. EU PQC Workstream publishes 'A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography'PQShieldpqshield.com/eu-pqc-workstream-publishes-a-coordinated-implementation-roadmap-for-the-transition-to-post-quantum-cryptography/
  8. Timelines for migration to post-quantum cryptography (20 March 2025)UK National Cyber Security Centrewww.ncsc.gov.uk/guidance/pqc-migration-timelines
  9. RFC 8996, Deprecating TLS 1.0 and TLS 1.1 (March 2021)IETFwww.rfc-editor.org/rfc/rfc8996
  10. SP 800-131A Rev. 2, Transitioning the Use of Cryptographic Algorithms and Key Lengths (March 2019)NISTcsrc.nist.gov/pubs/sp/800/131/a/r2/final

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

The rest of the BOM Suite

See it on your own stack.Map your SBOM, CBOM, QBOM, AIBOM and HBOM coverage against the frameworks you report to.
Request a Demo