Skip to content

Compliance

The Compliance page evaluates your cryptographic inventory against defined policy standards. Each standard specifies which algorithms are acceptable, which are vulnerable, and what action to take — then CBOM assesses every asset and reports violations.


The platform ships with built-in standards and supports custom ones:

  • CNSA 2.0 — NSA Commercial National Security Algorithm Suite
  • NIST PQC — Post-Quantum Cryptography transition requirements
  • FIPS 140-3 — Approved algorithms and minimum key sizes

Create your own organizational policies with:

  • Standard name, description, and category (regulatory, industry, organizational, custom)
  • Source URL (link to the reference document)
  • A set of rules defining algorithm requirements

Each standard contains rules that define the status of specific algorithms:

FieldDescription
AlgorithmAlgorithm name to match (e.g., RSA, AES, SHA-256)
Key SizeOptional key size constraint with operator (=, ≥, ≤, any)
StatusClassification of the algorithm
DeadlineDate by which migration must complete
ActionRequired remediation (e.g., “Migrate to ML-KEM”)
ReasonExplanation for the classification
StatusMeaning
SAFEQuantum-resistant, no action needed
WEAKENEDReduced strength post-quantum (e.g., AES-128 under Grover’s)
VULNERABLEBroken by quantum, must migrate before deadline
COMPROMISEDImmediate action required — algorithm is already broken
DEPRECATEDClassically broken, must be removed everywhere

Compliance Assessment Flow

Click Run Assessment on any standard (or Run All Assessments to evaluate all at once). The assessment:

  1. Evaluates every asset in your inventory against the standard’s rules
  2. Classifies each asset’s compliance status
  3. Produces a detailed report with violation breakdown

After running an assessment, the results view shows:

  • Total assets assessed
  • Count per status: Safe, Weakened, Vulnerable, Compromised, Deprecated
  • Overall status badge
  • Percentage breakdown (doughnut chart)
  • Delta vs. the previous assessment for the same standard
  • Direction indicator: IMPROVED, REGRESSED, or UNCHANGED
  • Per-category changes (violations added/resolved)

Tabbed by status (DEPRECATED, COMPROMISED, VULNERABLE, WEAKENED):

ColumnDescription
AssetAsset name (clickable to open detail)
TypeAsset type (certificate, key, etc.)
AlgorithmAlgorithm in use
Key SizeKey size in bits
DeadlineMigration deadline from the rule
ActionRequired action
ReasonWhy this is a violation

Results are paginated and searchable. Export the full assessment as JSON.


  1. Click Create Standard
  2. Fill in name, category, description, and optional source URL
  3. Add rules — each rule specifies an algorithm, key size constraint, status, deadline, and action
  4. Click Save Standard

You can also Clone any existing standard (including built-ins) and modify it.