Skip to content

CBOM — Cryptographic Bill of Materials

QCecuring CBOM discovers, inventories, and assesses every cryptographic asset across your infrastructure — certificates, keys, algorithms, protocols, and code-level crypto usage — then classifies quantum risk and exports a standards-compliant CycloneDX v1.6 CBOM.


Organizations have no unified view of what cryptography is deployed where. Certificates live in file systems, keystores, cloud services, Active Directory, and TLS endpoints. Private keys sit untracked. Source code uses deprecated algorithms nobody audited. When quantum computing arrives, there is no inventory to migrate from.

CBOM solves this with automated, continuous discovery.


  1. Deploy sensors near your infrastructure (on-prem servers, cloud VMs, developer machines)
  2. Sensors scan — TLS endpoints, file systems, keystores, source code, binaries, cloud APIs, Active Directory
  3. Central API ingests — deduplicates by content fingerprint, classifies quantum risk, links relationships
  4. Platform UI — browse inventory, assess compliance, plan migration, export CBOM

Sensors scan 11 source types:

CategoryScannersWhat They Find
NetworkTLS Endpoint, SSH EndpointCertificate chains, cipher suites, protocol versions, host keys
FilesystemCertificates & Keys, SSH Keys, Remote (agentless)PEM, DER, CRT, P12, JKS, SSH key files
Source CodeSource Code ScannerCrypto API calls, hardcoded keys, library imports across 6 languages
BinaryBinary AnalysisLinked crypto libraries, embedded keys, code signatures (Authenticode, JAR)
CloudAWS, Azure Key VaultACM certificates, KMS keys, IAM credentials, vault certificates and keys
IdentityActive Directory / ADCSADCS certificates, templates, domain controller certs, SSH/NGC keys
Certificate StoreWindows Certificate StoreLocalMachine and CurrentUser store certificates

Every asset is classified automatically:

Risk LevelMeaningExamples
CRITICALBroken or deprecatedMD5, SHA-1, DES, RC4, TLS 1.0/1.1
HIGHQuantum-vulnerableRSA, ECDSA, ECDH, DH, DSA
MEDIUMReduced strength under Grover’sAES-128
LOWAdequate with marginAES-192
NONEQuantum-safeAES-256, SHA-256+, ML-KEM, ML-DSA

Evaluate your inventory against cryptographic policy standards:

  • CNSA 2.0 (NSA Commercial National Security Algorithm Suite)
  • NIST PQC (Post-Quantum Cryptography)
  • FIPS 140-3 (Approved algorithms and key sizes)
  • Custom organizational policies

Each standard defines rules per algorithm with status (SAFE, WEAKENED, VULNERABLE, COMPROMISED, DEPRECATED), deadlines, and required actions.

Full spec-compliant CBOM including:

  • Cryptographic asset components with algorithmProperties and certificateProperties
  • dependencies section (issuer chains, key associations, keystore containment)
  • NIST Quantum Security Levels (QSL 0–5)
  • BOM-Link URNs for SBOM cross-referencing

Interactive graph showing certificate issuer chains, key-to-certificate associations, keystore containment, and signer relationships.


SectionPages
MonitorDashboard, Custom Analytics, Timeline, Reports
InventoryAsset Inventory, Sensors, Scanner Catalogue, Source Inspector, Import/Export
GovernanceCompliance, Migration Planner
PlatformUsers, Settings, Theme