Definition

A useful CBOM can describe algorithms, certificates, keys metadata, protocols and related components while preserving enough identity and evidence to reconcile the export with its originating inventory.

What a CBOM can contain

  • Cryptographic algorithms, modes, key sizes and named parameters.
  • Certificates and public-key metadata without private key material.
  • Protocols, cipher suites and cryptographic properties.
  • Libraries, modules and software dependencies that implement cryptography.
  • Relationships between components, services, assets and evidence.
  • Lifecycle, ownership, confidence and assessment metadata where supported.

CBOM vs SBOM, inventory and cryptographic audit

ArtifactPrimary purposeImportant boundary
SBOMDescribes software components and dependency relationshipsA package can contain cryptography without identifying its runtime use
CBOMDescribes cryptographic assets and cryptographic relationshipsCompleteness depends on the discovery sources represented
Cryptographic inventoryMaintains normalized assets, evidence, owners and lifecycle over timeIt can be broader and more operational than one exchange document
Cryptographic auditEvaluates a defined system and time period against stated criteriaIt is a point-in-time assessment, not automatically a living inventory

CycloneDX CBOM

CycloneDX extends its bill-of-materials model with cryptographic asset representation. Using a recognized format improves portability between discovery, inventory, governance and migration tools.

Standards-based output does not compensate for weak discovery. The exported CBOM is only as complete as its evidence and coverage, so reports should retain the scanner and rule versions and distinguish unknown or not-scanned sources.

Official sourcesCycloneDX specification overview ↗CycloneDX cryptography registry ↗CycloneDX Authoritative Guide to CBOM ↗CycloneDX 1.7 release ↗

Why normalized discovery matters

Public TLS, source analysis, dependencies and cloud APIs produce different raw observations. A normalized model prevents each scanner from creating an incompatible inventory and gives a CBOM stable identities and relationships.

For PQC migration, that normalization allows teams to find several observations of the same certificate or key, trace them to dependent systems and avoid inflating counts through scanner-specific duplicates.

Exporting a public exposure CBOM with Cipher Discovery

A completed Cipher Discovery public TLS report can be downloaded as CycloneDX JSON. The export maps directly observed TLS protocol and X.509 certificate assets to native CycloneDX cryptographic-asset records while preserving source asset, evidence, confidence and migration references.

The exported CBOM retains the report boundary and coverage metadata. It describes cryptography observed at the submitted public endpoint; it is not represented as a complete inventory of the organization, internal infrastructure, repositories, cloud resources or endpoints.

Run a public TLS scan →Generate a private report and download the CBOM for the public endpoint you are authorized to assess.Understand cryptographic inventory →See the maintained evidence and relationship model behind an export.Review cryptographic discovery →Understand how source-specific observations establish CBOM coverage.
Practical resourcesDownload the synthetic CycloneDX 1.7 public TLS example ↓A documentation-only CBOM with native cryptographic assets, evidence references, confidence, coverage counts and an explicit public-only inventory boundary.

Frequently asked questions

Is a CBOM a complete cryptographic inventory?

Not automatically. A CBOM represents the assets supplied to it. Its coverage depends on the discovery sources, systems and time period used to create it.

Should a CBOM contain private keys?

No. Private key material and credentials should never be included. Public identifiers and metadata are sufficient for inventory and assessment.

How does CBOM help PQC migration?

It provides a portable way to identify affected algorithms and dependencies, link them to systems and exchange evidence with migration workflows.

Can Cipher Discovery export a CycloneDX CBOM?

Yes. A private public TLS scan report can be downloaded as CycloneDX JSON. The export contains the public cryptographic assets observed in that scan and preserves explicit coverage limitations; it is not a complete organizational inventory.