Cryptographic Inventory: the foundation of post-quantum migration.
You cannot migrate what you have not counted. A cryptographic inventory — sometimes called a Cryptographic Bill of Materials, or CBOM — is the structured catalog of every algorithm, key, certificate, and signing identity that protects your business. It is the first thing NIST, CISA, NCUA, and DORA expect you to produce. It is also the first thing most institutions do not have.
What is a cryptographic inventory?
A cryptographic inventory is a structured catalog of every cryptographic primitive in use across your systems, vendors, and machine-to-machine communications. Every TLS certificate, every signing key, every algorithm in every library, every HSM, every workload identity, every dependency that decides who is allowed to say something on your behalf.
A useful inventory captures, at minimum: the algorithm and parameters, the key length, the owner, the data or transaction it protects, its expiration or rotation cadence, the replacement lead time, and whether the controlling key sits inside the organization or with a vendor. The last item — vendor exposure — is the one most spreadsheets quietly omit and the one most regulators are starting to ask about first.
Why this is the first step of PQC migration.
You cannot prioritize what you cannot count.
Without a CBOM, every PQC roadmap is guesswork. A scored inventory turns 'we should probably look at this' into a defensible sequence.
Harvest-now-decrypt-later has already started.
Encrypted data exfiltrated today is decryptable later. The inventory tells you which long-lived data is exposed now, not in five years.
Auditors are already asking.
NCUA, DORA, NIS2, and FFIEC examiners now ask for cryptographic discovery evidence. 'We are working on it' is no longer an answer.
What belongs in the inventory.
Algorithms and key material
- RSA, ECC, DH, DSA — anything asymmetric and quantum-vulnerable
- Symmetric algorithms and key lengths (AES-128 vs AES-256)
- Key escrow, HSM-resident keys, KMS configurations
- Hash functions used in signing contexts
Identities and certificates
- TLS certificate estates (internal and edge)
- Code-signing and document-signing certificates
- Workload, service-account, and machine identities
- AI agent and autonomous-system credentials (often uninventoried)
Protected data classes
- Data with confidentiality lifetimes > 10 years
- Transaction integrity surfaces (payments, settlement, audit logs)
- Regulated records (PHI, PII, financial, classified)
- Backups, archives, and offline media
Vendor and dependency exposure
- Third-party libraries with embedded cryptography
- SaaS vendors holding signing or encryption authority
- CAs, KMS providers, and identity providers
- Hardware supply chain (firmware signing roots)
CBOM vs SBOM.
A Software Bill of Materials (SBOM) tells you which components and libraries make up an application. A Cryptographic Bill of Materials (CBOM) tells you which cryptographic primitives, key material, and signing identities those components actually use. A complete SBOM is necessary but not sufficient — a library entry of "openssl 3.2.1" does not tell you which curves, which key lengths, or which certificate stores production is actually relying on.
In practice, a CBOM is built on top of an SBOM, augmented by runtime telemetry, key store enumeration, certificate transparency data, and vendor attestations. The QCI-QS1 QASI specification defines the schema that ties these signals together.
How it maps to QCI-QS1 and the Q-Risk Score.
QCI-QS1 Clause 4.5 and Annex A specify the Quantum Asset Surface Inventory (QASI) — the conformance baseline for what a cryptographic inventory must contain. QASI is the input layer of the Q-Risk Score. Without it, the score cannot pass 65: v2.3 added a hard ceiling that no institution clears past 65 without a complete identity and trust-chain inventory.
In practice that means the inventory is not optional. It is the single artifact that unlocks the rest of the standard — vendor scope (Clause 7), data-longevity classification (Clause 6), and the board briefing insert (Clause 8) all depend on it.
Inventory is the unlock. We can run yours.
A QASI-conformant cryptographic inventory, scored against QCI-QS1, with a board-ready insert and the evidence trail behind every finding.
Book a posture review