CBOM resources · 18 guides
CBOM Resources: Cryptographic Inventory Guides
How to find, record and govern the algorithms, keys, protocols and certificates your systems depend on, and use that inventory for policy, audit and post-quantum planning.
Fundamentals
Explainer · 6 minWhat is a CBOM? The Cryptographic Bill of Materials explainedA CBOM is an inventory of algorithms, keys, protocols and certificates. Learn what it contains, who requires it and how it supports quantum readiness.Explainer · 4 minCrypto-agility: what it is and how a CBOM enables itCrypto-agility is the ability to replace cryptographic algorithms without disrupting operations. See NIST's definition, key practices and the CBOM's role.Explainer · 4 minCycloneDX CBOM format explained: cryptoProperties and asset typesThe CycloneDX CBOM format explained: cryptographic-asset components, the four assetType values, algorithm, certificate, key and protocol fields, and links.
Tools & platforms
Guide · 4 minCBOM platforms: evaluation criteria for enterprise cryptographic inventoryHow to evaluate a CBOM platform: discovery coverage, CycloneDX support, CERT-In field validation, policy, lifecycle, PQC planning, evidence and deployment.Guide · 4 minCBOM tools: open-source cryptographic discovery and scanning toolsOpen-source CBOM tools compared by discovery method: CBOMkit, sonar-cryptography, cdxgen, testssl.sh, SSLyze, Nmap and ssh-audit, and where each fits.
Operations
Guide · 4 minCBOM management: ownership, policy, certificate lifecycle and driftHow to manage a CBOM over time: assign owners, codify cryptographic policy, track key states and certificate expiry, detect drift, refresh supplier CBOMs.How-to · 4 minCBOM validation: completeness and accuracy checksHow to validate a CBOM: schema checks, CERT-In required fields, reference integrity, cross-checks against live scans and key stores, coverage and freshness.
Comparisons
Comparison · 3 minCBOM vs QBOM: cryptographic and quantum bills of materials comparedCBOM vs QBOM: how CERT-In defines each, how their minimum elements differ, and how a cryptographic inventory feeds quantum-readiness and PQC migration.Comparison · 3 minCBOM vs SBOM: how a cryptographic inventory extends the software bill of materialsCBOM vs SBOM: what each inventories, how their fields differ, what each answers and how CycloneDX links cryptographic assets to software components.Comparison · 4 minCBOM vs certificate lifecycle management and PKI inventoryCBOM vs certificate lifecycle management: how a PKI inventory differs from a cryptographic bill of materials, where they overlap and how to use them together.
Compliance
Compliance · 4 minCBOM compliance: which frameworks expect a cryptographic inventoryWhich frameworks expect a cryptographic inventory or CBOM: CERT-In, SEBI CSCRF, India's DST roadmap, OMB M-23-02, CNSA 2.0, NIST, the EU roadmap and UK NCSC.Compliance · 4 minCBOM procurement requirements for suppliersWhat to ask suppliers for in a CBOM: scope, format, CERT-In fields, update triggers, VEX, PQC roadmaps and secure delivery, with sample contract language.Compliance · 3 minCERT-In CBOM requirements: the four asset types and their fieldsCERT-In CBOM requirements explained: minimum elements for algorithms, keys, protocols and certificates, CycloneDX mappings and Section 8.4 recommendations.
Industries
Industry · 4 minCBOM for Indian enterprises: CERT-In, SEBI, RBI and the national quantum-safe roadmapWhat Indian enterprises should know about CBOMs: CERT-In v2.0 elements, SEBI CSCRF crypto inventory, RBI's quantum signal and the DST roadmap timelines.Industry · 3 minCBOM for banks and financial servicesWhy banks, payment operators and market intermediaries need a CBOM: payment cryptography, HSMs, partner links, SEBI CSCRF, G7 and BIS quantum roadmaps.Industry · 3 minCBOM for government and the public sectorHow public sector bodies use a CBOM: CERT-In procurement recommendations, India's DST roadmap, OMB M-23-02, CNSA 2.0 and EU and UK PQC timelines.
How-to
How-to · 4 minCBOM generation: discovering algorithms, keys, protocols and certificatesHow to generate a CBOM: network scanning, source-code analysis, binary and container inspection, HSM and KMS exports and supplier CBOMs, merged in CycloneDX.How-to · 4 minHow to find weak cryptography with a CBOMUse a CBOM to find weak cryptography: deprecated TLS, short keys, SHA-1 signatures, TDEA, ECB mode, expiring certificates and quantum-vulnerable algorithms.
See it on your own stack.Map your SBOM, CBOM, QBOM, AIBOM and HBOM coverage against the frameworks you report to.
Request a Demo