PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Guide4 min readReviewed September 202612 sources

CBOM tools: open-source cryptographic discovery and scanning tools

No single tool sees all of an organisation's cryptography. This guide groups well-known open-source tools by what they can discover, what they output and where they fit in a CBOM pipeline.

Key takeaways
  • CBOM tools fall into three groups: code and artefact scanners that emit CycloneDX CBOMs, network scanners that probe live endpoints, and BOM utilities that validate and compare documents.
  • CBOMkit, originally developed at IBM Research and donated to the Post-Quantum Cryptography Alliance in June 2025, includes source-code and container scanners that output CycloneDX CBOMs.
  • Network scanners such as testssl.sh, SSLyze, Nmap's ssl-enum-ciphers and ssh-audit produce JSON or structured output that must be mapped into CBOM form.
  • Choose tools by coverage of your languages, protocols and deployment artefacts, not by feature count.

Three kinds of CBOM tool

A Cryptographic Bill of Materials is assembled from several discovery methods, and open-source tools tend to specialise in one. It helps to group them:

  • Code and artefact scanners read source code, container images or file systems and emit a CycloneDX CBOM directly.
  • Network scanners connect to running services and report the protocols, cipher suites and certificates they offer. Their output needs mapping into CBOM form.
  • BOM utilities validate, merge, convert and compare BOM documents once they exist.

CISA's strategy on automated cryptography discovery and inventory tools notes that agencies should expect to combine automated tools with manual collection where automation falls short, particularly for embedded cryptography [12]. The same holds for any organisation.

Code and artefact scanners

CBOMkit and sonar-cryptography

IBM Research donated its CBOM toolset to the Post-Quantum Cryptography Alliance (PQCA), a Linux Foundation project, on 23 June 2025 [1]. PQCA's architecture overview (March 2026) describes five parts, now hosted under the cbomkit GitHub organisation [2]:

  • sonar-cryptography (CBOMkit-hyperion)a SonarQube plugin that detects cryptographic API usage and writes a cbom.json in CycloneDX 1.6 format. Its README lists coverage for Java (JCA and the Bouncy Castle lightweight API), Python (pyca/cryptography) and Go (the standard crypto library, with partial golang.org/x/crypto support), with C# in development [3].
  • cbomkit-lib and cbomkit-actiona library wrapper that runs the detection engine without a SonarQube server, and a GitHub Action for CI pipelines [2].
  • cbomkit-theiaa Go command-line tool that detects certificates, keys, secrets and configuration files in container images and directories [2].
  • cbomkitthe application that stores CBOMs, visualises them and evaluates them against policy. Its README notes that it does not build repositories before scanning, which can reduce accuracy for Java projects without compiled classes [4]. All components are Apache 2.0 licensed.

cdxgen

OWASP CycloneDX's cdxgen generator can produce a CBOM through its cbom alias or the --include-crypto option. Its README describes coverage of Java keystores and certificates and source-level algorithm inventory for JavaScript and TypeScript [5].

cryptobom-forge

Santander Security Research's cryptobom-forge converts CodeQL SARIF output into a CycloneDX CBOM and includes a rules-based check that reports issues such as weak algorithms or modes. It is GPL-3.0 licensed [6].

Network scanners

ToolWhat it examinesStructured outputLicence
testssl.shTLS/SSL protocols, ciphers and a range of cryptographic flaws on any port [7]JSON, CSV, HTMLGPLv2
SSLyzeTLS configuration and known attacks; can check servers against Mozilla's recommended TLS configurations [8]JSON (with published schema)AGPL
Nmap ssl-enum-ciphersEnumerates every cipher suite and compressor a server accepts and grades each A–F [9]Nmap XMLNmap project licence
ssh-auditSSH key exchange, host-key, encryption and MAC algorithms; policy audits against hardened baselines [10]JSONMIT

These tools see what is negotiated on the wire, which a code scanner cannot. They do not see keys at rest, algorithms used internally for data encryption, or services that are not reachable from the scanning host. A typical invocation of the Nmap script is nmap -sV --script ssl-enum-ciphers -p 443 <host> [9].

BOM utilities

The CycloneDX CLI validates, merges, converts and diffs BOMs, and can sign and verify them [11]. Schema validation and diffing are the minimum you need to keep CBOMs trustworthy over time; see CBOM validation.

How to choose

  1. Map coverage to your estate. List your languages, crypto libraries, protocols and deployment artefacts, then check each tool's documented coverage against that list.
  2. Prefer standard output. Tools that emit CycloneDX CBOMs directly reduce mapping work. For the rest, plan a conversion step.
  3. Run in the pipeline and on a schedule. Code scanners belong in CI; network scanners belong on a recurring schedule because configurations drift.
  4. Check licences. GPL and AGPL tools are fine for internal scanning; review obligations before embedding them in a product.
  5. Plan for gaps. HSM and KMS key metadata, firmware and third-party products usually need exports or supplier CBOMs rather than scanning.

For the full discovery approach, see CBOM generation; for what to look for once you have results, see finding weak cryptography with a CBOM.

How IntelliXBOM helps

IntelliXBOM ingests CycloneDX CBOMs produced by open-source scanners and other sources, validates them against required-field policies, and keeps version history and diffs across scans. It correlates the resulting cryptographic assets with vulnerabilities, end-of-life data and business services, so findings from different tools can be reviewed in one place.

Frequently asked questions

What is the best open-source CBOM tool?

There is no single best tool, because each covers a different discovery method. Code scanners such as sonar-cryptography and cdxgen find cryptography in source, while network scanners such as testssl.sh and SSLyze find what services actually negotiate. Most organisations combine several.

Can a TLS scanner produce a CBOM?

TLS scanners such as testssl.sh and SSLyze produce structured JSON describing protocols, cipher suites and certificates, but not a CycloneDX CBOM directly. Their output can be mapped into CBOM protocol, algorithm and certificate assets.

Who maintains CBOMkit?

CBOMkit was developed at IBM Research and donated to the Post-Quantum Cryptography Alliance, a Linux Foundation project, in June 2025. Its repositories are hosted under the cbomkit organisation on GitHub and are Apache 2.0 licensed.

Sources

  1. IBM is donating its CBOM toolset to the Linux Foundation (23 June 2025)IBM Researchresearch.ibm.com/blog/cryptographic-cbom-linux-foundation
  2. PQCA CBOMkit Architecture (16 March 2026)Post-Quantum Cryptography Alliancepqca.org/blog/2026/pqca-cbomkit-architecture/
  3. Sonar Cryptography Plugin (CBOMkit-hyperion)CBOMkit / Post-Quantum Cryptography Alliance (GitHub)github.com/cbomkit/sonar-cryptography
  4. CBOMkitCBOMkit / Post-Quantum Cryptography Alliance (GitHub)github.com/cbomkit/cbomkit
  5. cdxgen, CycloneDX GeneratorOWASP CycloneDX (GitHub)github.com/CycloneDX/cdxgen
  6. cryptobom-forgeSantander Security Research (GitHub)github.com/Santandersecurityresearch/cryptobom-forge
  7. testssl.shtestssl.sh project (GitHub)github.com/testssl/testssl.sh
  8. SSLyzeSSLyze project (GitHub)github.com/nabla-c0d3/sslyze
  9. ssl-enum-ciphers NSE scriptNmap Projectnmap.org/nsedoc/scripts/ssl-enum-ciphers.html
  10. ssh-auditssh-audit project (GitHub)github.com/jtesta/ssh-audit
  11. CycloneDX CLIOWASP CycloneDX (GitHub)github.com/CycloneDX/cyclonedx-cli
  12. Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools (September 2024)CISAwww.cisa.gov/resources-tools/resources/strategy-migrating-automated-post-quantum-cryptography-discovery-and-inventory-tools

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related CBOM guides

Across the BOM Suite

Put your CBOM under governance.Cryptographic visibility with continuous correlation and timestamped evidence.