CBOM — Cryptographic Bill of Materials
QCecuring CBOM discovers, inventories, and assesses every cryptographic asset across your infrastructure — certificates, keys, algorithms, protocols, and code-level crypto usage — then classifies quantum risk and exports a standards-compliant CycloneDX v1.6 CBOM.
The Problem
Section titled “The Problem”Organizations have no unified view of what cryptography is deployed where. Certificates live in file systems, keystores, cloud services, Active Directory, and TLS endpoints. Private keys sit untracked. Source code uses deprecated algorithms nobody audited. When quantum computing arrives, there is no inventory to migrate from.
CBOM solves this with automated, continuous discovery.
How It Works
Section titled “How It Works”- Deploy sensors near your infrastructure (on-prem servers, cloud VMs, developer machines)
- Sensors scan — TLS endpoints, file systems, keystores, source code, binaries, cloud APIs, Active Directory
- Central API ingests — deduplicates by content fingerprint, classifies quantum risk, links relationships
- Platform UI — browse inventory, assess compliance, plan migration, export CBOM
Core Capabilities
Section titled “Core Capabilities”Discovery
Section titled “Discovery”Sensors scan 11 source types:
| Category | Scanners | What They Find |
|---|---|---|
| Network | TLS Endpoint, SSH Endpoint | Certificate chains, cipher suites, protocol versions, host keys |
| Filesystem | Certificates & Keys, SSH Keys, Remote (agentless) | PEM, DER, CRT, P12, JKS, SSH key files |
| Source Code | Source Code Scanner | Crypto API calls, hardcoded keys, library imports across 6 languages |
| Binary | Binary Analysis | Linked crypto libraries, embedded keys, code signatures (Authenticode, JAR) |
| Cloud | AWS, Azure Key Vault | ACM certificates, KMS keys, IAM credentials, vault certificates and keys |
| Identity | Active Directory / ADCS | ADCS certificates, templates, domain controller certs, SSH/NGC keys |
| Certificate Store | Windows Certificate Store | LocalMachine and CurrentUser store certificates |
Quantum Risk Classification
Section titled “Quantum Risk Classification”Every asset is classified automatically:
| Risk Level | Meaning | Examples |
|---|---|---|
| CRITICAL | Broken or deprecated | MD5, SHA-1, DES, RC4, TLS 1.0/1.1 |
| HIGH | Quantum-vulnerable | RSA, ECDSA, ECDH, DH, DSA |
| MEDIUM | Reduced strength under Grover’s | AES-128 |
| LOW | Adequate with margin | AES-192 |
| NONE | Quantum-safe | AES-256, SHA-256+, ML-KEM, ML-DSA |
Compliance
Section titled “Compliance”Evaluate your inventory against cryptographic policy standards:
- CNSA 2.0 (NSA Commercial National Security Algorithm Suite)
- NIST PQC (Post-Quantum Cryptography)
- FIPS 140-3 (Approved algorithms and key sizes)
- Custom organizational policies
Each standard defines rules per algorithm with status (SAFE, WEAKENED, VULNERABLE, COMPROMISED, DEPRECATED), deadlines, and required actions.
CycloneDX v1.6 Export
Section titled “CycloneDX v1.6 Export”Full spec-compliant CBOM including:
- Cryptographic asset components with
algorithmPropertiesandcertificateProperties dependenciessection (issuer chains, key associations, keystore containment)- NIST Quantum Security Levels (QSL 0–5)
- BOM-Link URNs for SBOM cross-referencing
Relationship Visualization
Section titled “Relationship Visualization”Interactive graph showing certificate issuer chains, key-to-certificate associations, keystore containment, and signer relationships.
Platform Pages
Section titled “Platform Pages”| Section | Pages |
|---|---|
| Monitor | Dashboard, Custom Analytics, Timeline, Reports |
| Inventory | Asset Inventory, Sensors, Scanner Catalogue, Source Inspector, Import/Export |
| Governance | Compliance, Migration Planner |
| Platform | Users, Settings, Theme |
Next Steps
Section titled “Next Steps”- Architecture — How sensors, API, and UI fit together
- Deployment — Get the platform running
- First Sensor — Register and configure your first sensor
- Scanner Reference — Configure each scanner type