Skip to content

Import / Export

CBOM supports standards-compliant export for supply chain integration and multiple import paths for environments where sensors can’t push directly to the API.


Exports your full cryptographic inventory as a CycloneDX v1.6 JSON document. The export includes:

  • bomFormat: "CycloneDX", specVersion: "1.6"
  • Unique serial number (URN UUID)
  • Every asset as a cryptographic-asset component with:
    • algorithmProperties (primitive, family, curve, mode, OID, NIST quantum security level)
    • certificateProperties (subject, issuer, serial, validity, extensions, fingerprint)
    • relatedCryptoMaterialProperties (type, size, format, state)
    • protocolProperties (version, cipher suites)
  • dependencies section mapping issuer chains, key pairs, and keystore containment
  • BOM-Link URNs for cross-referencing with SBOMs

Use this for compliance reporting, supply chain attestations, or integration with other security tools.

Exports all assets in CBOM’s internal format. Useful for custom processing, scripting, or backup.


Upload a CycloneDX CBOM JSON from external tools:

  • cbomkit-theia — IBM’s open-source CBOM scanner
  • cdxgen — CycloneDX generator
  • IBM Quantum Safe Explorer
  • Any CycloneDX v1.4+ compliant CBOM generator

Imported assets are ingested into the unified inventory with full quantum risk classification, relationship linking, and analytics — treated identically to sensor-discovered assets.

Drag and drop any CycloneDX JSON to visualize its contents without modifying your inventory. Useful for reviewing external CBOMs before deciding to import.


For environments where sensors cannot reach the API over the network:

  1. Run the sensor in offline mode on the air-gapped machine:
    Terminal window
    java -jar cbom-sensor.jar scan --config=config.yml --output=results.json
  2. Transfer the results file via USB or secure file transfer
  3. Upload the file through the Import/Export page
  • Single .json — one scan result file
  • Batch .zip — multiple JSON scan results in a ZIP archive

Each file is processed through the same ingestion pipeline as live sensor data — deduplication, risk classification, and relationship linking all apply.

After uploading a ZIP, you’ll see a per-file breakdown: created count, updated count, and status for each JSON file in the archive.


For automated import from CI/CD pipelines, use the API directly:

Terminal window
curl -X POST https://cbom.yourcompany.com/api/v1/import/source-scan \
-H "Authorization: Bearer YOUR_TOKEN" \
-H "Content-Type: application/json" \
-d @scan-results.json

The payload should include a scannerType, hostname, and assets array.