PlatformPlatform architectureProduct tourProduct graphRisk intelligenceContinuous governanceEvidence & auditDeploymentIntegrationsExecutive view
BOM SuiteSBOMCBOMQBOMAIBOMHBOMBOM Governance
SolutionsSecurityComplianceSupply chain riskQuantum readinessAI governanceDigital trust
ComplianceCERT-InRBISEBI / CSCRFMeitYNISTEU CRAEU AI ActCERT-In SBOM guide
IndustriesBanking & Financial ServicesGovernment & Public SectorDefence & Critical InfrastructureHealthcareIndian enterprises
ResourcesResource centreSBOM resourcesCBOM resourcesQBOM resourcesAIBOM resourcesHBOM resourcesProgramme & regulationBlog
CompanyAboutSecurity & trustContact
Request a DemoTalk to an expert
Explainer4 min readReviewed September 20266 sources

CycloneDX CBOM format explained: cryptoProperties and asset types

CycloneDX is the most widely used format for CBOMs. This is a field-level walk through how version 1.6 represents cryptographic assets, based on the published schema.

Key takeaways
  • CycloneDX 1.6 (April 2024) added a cryptographic-asset component type and a cryptoProperties object; 1.6 was ratified as ECMA-424 in June 2024.
  • cryptoProperties.assetType takes one of four values: algorithm, certificate, protocol or related-crypto-material.
  • Each asset type has its own properties object, and references such as signatureAlgorithmRef and algorithmRef link assets to each other.
  • The dependency graph's provides relationship links a library to the algorithms it implements.
  • CycloneDX 1.7 (October 2025) adds standard lists of algorithm families and elliptic curves.

Versions and status

CycloneDX introduced Cryptography Bill of Materials support in version 1.6, released on 9 April 2024 [1]. Version 1.6 was ratified as ECMA-424, 1st Edition, in June 2024, and version 1.7, released on 21 October 2025, adds a standardised list of cryptographic algorithm families and a list of elliptic curves [2]. This article follows the 1.6 JSON schema [3]; 1.7 extends it rather than replacing it.

The building block: a cryptographic-asset component

A CBOM entry is an ordinary CycloneDX component whose type is cryptographic-asset, alongside types such as library, application and firmware. It carries a cryptoProperties object with three top-level members [3]:

  • assetTypeone of algorithm, certificate, protocol, related-crypto-material.
  • One properties object matching the asset type: algorithmProperties, certificateProperties, protocolProperties or relatedCryptoMaterialProperties.
  • oidthe object identifier, where one exists.

A minimal algorithm entry looks like this: {"type":"cryptographic-asset","bom-ref":"alg-aes128gcm","name":"AES-128-GCM","cryptoProperties":{"assetType":"algorithm","algorithmProperties":{"primitive":"ae","mode":"gcm","cryptoFunctions":["encrypt","decrypt"],"classicalSecurityLevel":128},"oid":"2.16.840.1.101.3.4.1.6"}}.

Algorithm properties

FieldPurpose and allowed values
primitivedrbg, mac, block-cipher, stream-cipher, signature, hash, pke, xof, kdf, key-agree, kem, ae, combiner, other, unknown
parameterSetIdentifier, curveParameter set (for example a key or digest size) and elliptic curve
modecbc, ecb, ccm, gcm, cfb, ofb, ctr, other, unknown
paddingpkcs5, pkcs7, pkcs1v15, oaep, raw, other, unknown
cryptoFunctionsgenerate, keygen, encrypt, decrypt, digest, tag, keyderive, sign, verify, encapsulate, decapsulate, other, unknown
executionEnvironmentsoftware-plain-ram, software-encrypted-ram, software-tee, hardware, other, unknown
implementationPlatformgeneric, x86_32, x86_64, armv7/8/9 variants, s390x, ppc64, ppc64le, other, unknown
certificationLevelnone, FIPS 140-1/140-2/140-3 levels 1–4, Common Criteria EAL1–EAL7 (with +), other, unknown
classicalSecurityLevelClassical strength in bits
nistQuantumSecurityLevelNIST post-quantum security category 0–6; 0 means none is met

Values from the 1.6 schema [3].

Certificate properties

subjectName, issuerName, notValidBefore, notValidAfter, signatureAlgorithmRef, subjectPublicKeyRef, certificateFormat and certificateExtension [3]. The two Ref fields point to the bom-ref of an algorithm asset and a key asset, so the signature algorithm and public key are inventoried once and referenced.

Keys are not a separate asset type. They are related-crypto-material, whose type can be private-key, public-key, secret-key, key, ciphertext, signature, digest, initialization-vector, nonce, seed, salt, shared-secret, tag, additional-data, password, credential, token, other or unknown [3]. Other fields are id, state, algorithmRef, creationDate, activationDate, updateDate, expirationDate, value, size, format and securedBy. The state values, pre-activation, active, suspended, deactivated, compromised, destroyed, match the key states in NIST SP 800-57 Part 1 [6]. Avoid populating value with real secret material.

Protocol properties

type (tls, ssh, ipsec, ike, sstp, wpa, other, unknown), version, cipherSuites, ikev2TransformTypes and cryptoRefArray [3]. Each cipher suite has a name, a list of algorithms (references to algorithm assets) and identifiers (the schema gives code-point values such as 0xC0 and 0x9E as examples). IKEv2 transform types cover encryption, PRF, integrity, key exchange, ESN and authentication.

Linking assets to software

Two mechanisms connect the CBOM to the rest of the BOM. Internal references (signatureAlgorithmRef, subjectPublicKeyRef, algorithmRef, cipher-suite algorithm lists) connect cryptographic assets to each other. The dependency graph connects them to software: a library's provides list names the cryptographic assets it implements, and dependsOn shows use. The schema notes that implementing an algorithm does not imply it is in use [3]. CycloneDX describes this as representing cryptographic assets "and their relationships to software components" [4].

Mapping to CERT-In

The CERT-In Table 9 elements map closely to these fields, Primitive, Mode, Crypto Functions and Classical security level to algorithmProperties; id, state, size and dates to relatedCryptoMaterialProperties; and so on [5]. The full mapping is in CERT-In CBOM requirements.

How IntelliXBOM helps

IntelliXBOM generates and ingests CycloneDX CBOMs, validates them against schema and required-field policies such as CERT-In's, and keeps version history with diffs. It correlates cryptographic-asset components with vulnerabilities, end-of-life data and the business services they support.

Frequently asked questions

Which CycloneDX version supports CBOM?

CBOM support was introduced in CycloneDX 1.6, released in April 2024 and ratified as ECMA-424. CycloneDX 1.7, released in October 2025, adds standard lists of algorithm families and elliptic curves.

What are the CycloneDX CBOM asset types?

The cryptoProperties.assetType field takes one of four values: algorithm, certificate, protocol or related-crypto-material. Keys, secrets, tokens and similar items are represented as related-crypto-material.

How does a CycloneDX CBOM link cryptography to software?

Cryptographic assets reference each other through fields such as signatureAlgorithmRef and algorithmRef. Libraries link to the algorithms they implement through the dependency graph's provides relationship.

Sources

  1. CycloneDX v1.6 Released, Advances Software Supply Chain Security with Cryptographic Bill of Materials and Attestations (9 April 2024)OWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.6-released/
  2. CycloneDX v1.7 Delivers Advanced Cryptography, Intellectual Property, and Data Provenance Transparency (21 October 2025)OWASP CycloneDXcyclonedx.org/news/cyclonedx-v1.7-released/
  3. CycloneDX v1.6 JSON Reference (bom-1.6 schema)OWASP CycloneDXcyclonedx.org/docs/1.6/json/
  4. Cryptography Bill of Materials (CBOM)OWASP CycloneDXcyclonedx.org/capabilities/cbom/
  5. Technical Guidelines on SBOM, QBOM & CBOM, AIBOM and HBOM, Version 2.0 (9 July 2025)CERT-In, Government of Indiawww.cert-in.org.in/PDF/TechnicalGuidelines-on-SBOM,QBOM&CBOM,AIBOM_and_HBOM_ver2.0.pdf
  6. SP 800-57 Part 1 Rev. 5, Recommendation for Key Management: Part 1 – General (May 2020)NISTcsrc.nist.gov/pubs/sp/800/57/pt1/r5/final

Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.

Related CBOM guides

Across the BOM Suite

Put your CBOM under governance.Cryptographic visibility with continuous correlation and timestamped evidence.