Cryptoramic

Terminology

CBOM versus SBOM, and what a CBOM profile adds

Both are bills of materials. They answer different questions, and post-quantum migration needs the second one.

SBOM and CBOM answer different questions and overlap at the cryptographic library Left, an SBOM lists an application and its components. Right, a CBOM lists a protocol, a certificate, a key and the algorithms they use, with relationships. The library that implements the cryptography appears in both. SBOM · which components? Application 2.4 libcurl 8.x zlib 1.3 libssl 3.0.x CBOM · which cryptography, how used? TLS 1.3 on api.example:443 ECDHE RSA-2048 Certificate, signed SHA-256 implemented by libssl 3.0.x key exchange · authentication · signature · library The library appears in both. Only the CBOM says what it is used for. A migration plan needs the right-hand list.
  1. SBOM

    Describe software components and dependencies.

  2. CBOM

    Describe cryptographic assets and their relationships in a defined scope.

  3. Shared context

    Connect cryptography with the product and software version it belongs to.

An SBOM lists components; a CBOM lists cryptographic assets and how they relate.

Two lists, two questions

A software bill of materials (SBOM) answers “which components are in this software, and which versions?” It exists so that a vulnerability in a library can be traced to every product that includes it.

A cryptographic bill of materials (CBOM) answers “which cryptography does this system depend on, and how is it used?” It lists algorithms, keys, certificates, protocols and the libraries that implement them, and the relationships between them: this service uses this certificate, signed with this algorithm, provided by this library. It exists so that a change in cryptographic requirements, most urgently the move to post-quantum algorithms, can be traced to every place that needs to change.

The two overlap where a component is a cryptographic library. An SBOM tells you OpenSSL 3.x is present. A CBOM tells you which algorithms it is configured to use, on which interface, and whether that can change.

The format: CycloneDX and SPDX

CycloneDX added a cryptographic asset component type and the properties needed to describe algorithms, keys, certificates, protocols and related material. It is the format most discovery tools export and most consumers expect. SPDX is used for software components and is gaining cryptographic coverage; in practice a CBOM today is usually a CycloneDX document.

A CBOM can be produced from two directions:

A migration plan needs both. The observed CBOM shows exposure; the declared CBOM shows what can be done about it.

Why profiles: the PKI Consortium work

A format defines what can be expressed. It does not say what a CBOM must contain to be useful for a given decision. That is the gap the PKI Consortium’s CBOM profiles work addresses. A profile is a constrained, use-case-specific specification of what a CBOM should contain, how its fields are interpreted and what validation rules apply. Profiles map onto CycloneDX and SPDX rather than replacing them.

The work is a working draft with a fully developed profile for post-quantum migration and a draft for IoT device estates, plus a register of regulatory references and an inventory of CBOM tooling. The practical effect for a buyer: instead of asking a supplier for “a CBOM” and receiving a document that answers nothing, you can ask for a CBOM that conforms to the migration profile, and then compare suppliers on the same fields.

How Cryptoramic uses them

Cryptoramic imports existing CycloneDX and SPDX documents into the inventory and exports CycloneDX CBOMs for a selected scope, such as a host or a scan, with the discovery path of each asset preserved. Export follows a CBOM profile definition, so the same inventory can produce the view a supplier conversation needs or the view an auditor needs. The inventory itself stays the source; the CBOM is one way to hand a slice of it to someone else.

Read what CADI means for how discovery, inventory and CBOM fit together, or see the supplier side of the same conversation.

Frequently asked questions

Is a CBOM part of an SBOM?

It can be. A software bill of materials (SBOM) lists software components. A cryptographic bill of materials (CBOM) describes cryptography, such as algorithms, keys and certificates. CycloneDX can carry both in one document.

Which format is used for a CBOM?

CycloneDX supports cryptographic assets and their relationships. The PKI Consortium’s work on CBOM profiles uses existing formats, including CycloneDX and SPDX, rather than creating a new one. Agree a format and required fields with whoever will receive the file.

What is a CBOM profile?

It is a set of rules for what a CBOM must include for a particular job, such as planning a post-quantum migration. It defines the information needed and how to check it, so different suppliers can provide comparable answers.

Can a scanner generate a CBOM?

Yes. A scanner can export the cryptography it found and where it found it. It cannot discover every future capability a supplier plans to deliver. Keep observed findings separate from supplier statements about what a product supports.

Back to perspectives

Export a CBOM from one scope of your own.

Book a demo

Product screenshot

Illustrative assessment data