Two lists, two questions
A software bill of materials (SBOM) answers “which components are in this software, and which versions?” It exists so that a vulnerability in a library can be traced to every product that includes it.
A cryptographic bill of materials (CBOM) answers “which cryptography does this system depend on, and how is it used?” It lists algorithms, keys, certificates, protocols and the libraries that implement them, and the relationships between them: this service uses this certificate, signed with this algorithm, provided by this library. It exists so that a change in cryptographic requirements, most urgently the move to post-quantum algorithms, can be traced to every place that needs to change.
The two overlap where a component is a cryptographic library. An SBOM tells you OpenSSL 3.x is present. A CBOM tells you which algorithms it is configured to use, on which interface, and whether that can change.
The format: CycloneDX and SPDX
CycloneDX added a cryptographic asset component type and the properties needed to describe algorithms, keys, certificates, protocols and related material. It is the format most discovery tools export and most consumers expect. SPDX is used for software components and is gaining cryptographic coverage; in practice a CBOM today is usually a CycloneDX document.
A CBOM can be produced from two directions:
- Observed. A discovery tool scans a scope and records the cryptography it found, with the source of every finding. File and image inspection records what is present; traffic observations show what was used in the connections observed.
- Declared. A supplier describes what a product supports and how it can change. This is a commitment, not an observation.
A migration plan needs both. The observed CBOM shows exposure; the declared CBOM shows what can be done about it.
Why profiles: the PKI Consortium work
A format defines what can be expressed. It does not say what a CBOM must contain to be useful for a given decision. That is the gap the PKI Consortium’s CBOM profiles work addresses. A profile is a constrained, use-case-specific specification of what a CBOM should contain, how its fields are interpreted and what validation rules apply. Profiles map onto CycloneDX and SPDX rather than replacing them.
The work is a working draft with a fully developed profile for post-quantum migration and a draft for IoT device estates, plus a register of regulatory references and an inventory of CBOM tooling. The practical effect for a buyer: instead of asking a supplier for “a CBOM” and receiving a document that answers nothing, you can ask for a CBOM that conforms to the migration profile, and then compare suppliers on the same fields.
How Cryptoramic uses them
Cryptoramic imports existing CycloneDX and SPDX documents into the inventory and exports CycloneDX CBOMs for a selected scope, such as a host or a scan, with the discovery path of each asset preserved. Export follows a CBOM profile definition, so the same inventory can produce the view a supplier conversation needs or the view an auditor needs. The inventory itself stays the source; the CBOM is one way to hand a slice of it to someone else.
Read what CADI means for how discovery, inventory and CBOM fit together, or see the supplier side of the same conversation.
Frequently asked questions
Is a CBOM part of an SBOM?
It can be. A software bill of materials (SBOM) lists software components. A cryptographic bill of materials (CBOM) describes cryptography, such as algorithms, keys and certificates. CycloneDX can carry both in one document.
Which format is used for a CBOM?
CycloneDX supports cryptographic assets and their relationships. The PKI Consortium’s work on CBOM profiles uses existing formats, including CycloneDX and SPDX, rather than creating a new one. Agree a format and required fields with whoever will receive the file.
What is a CBOM profile?
It is a set of rules for what a CBOM must include for a particular job, such as planning a post-quantum migration. It defines the information needed and how to check it, so different suppliers can provide comparable answers.
Can a scanner generate a CBOM?
Yes. A scanner can export the cryptography it found and where it found it. It cannot discover every future capability a supplier plans to deliver. Keep observed findings separate from supplier statements about what a product supports.