CBOM / SBOM Cryptographic Enrichment
Extend software/component inventories with cryptographic algorithms, libraries, protocols, keys and dependencies.
What this capability solves
Standard SBOMs often identify packages but not how cryptography is used or which downstream systems depend on it. A CBOM makes migration impact visible.
Technology is implemented as an operating capability: architecture, integration, governance, assurance, people, procedures and measurable outcomes are designed together.
Capability model
Modular building blocks allow the scope to start with a focused pilot and expand into an enterprise operating model.
CBOM Schema
Algorithm, mode, key size, protocol, library, certificate, usage and owner.
SBOM Correlation
Link cryptographic findings to software components and versions.
Dependency Graph
Map applications, services, APIs, devices and trust-chain dependencies.
Vendor Metadata
Capture vendor support, upgrade path, EOL and PQC readiness.
Change Detection
Track new/changed cryptographic dependencies across releases.
Evidence Export
Provide machine-readable and management views for risk/remediation.
How the capability fits together
Final topology, control placement and deployment model are validated during discovery and detailed design.
Controls & governance
- Approved cryptographic profile registry
- Hybrid-first transition where compatibility requires it
- No untested algorithm replacement in production
- Key/certificate lifecycle and fallback controls
- Vendor and firmware dependency tracking
- Independent test evidence for critical systems
- Exception ownership and retirement dates
Priority use cases
- Software supply chain
- Application modernization
- PKI dependency analysis
- IoT firmware governance
- Crypto-agility dashboard
Key deliverables
- CBOM model
- Enriched SBOM
- Dependency graph
- Vendor readiness register
- Change workflow
Integration considerations
- CMDB/asset inventory
- PKI/HSM/KMS
- Network/security platforms
- Application/CI-CD dependencies
- Cloud and SaaS configuration
- IoT/OT device inventory
- GRC/remediation workflow
Phased delivery
Each phase ends with evidence, acceptance criteria and a decision gate before broader scale-out.
