Four actions per device model
The PKI Consortium’s IoT use case frames the operator’s problem precisely. When cryptography standards change, for each device model in an estate the operator chooses between four actions: update the firmware, replace the device, put a gateway in front of it, or accept the risk. A cryptographic inventory for a device estate is useful only if it supports that choice.
That is a different decision from post-quantum migration in IT, and the work treats it as a separate profile branch for fleet remediation rather than a variant of the migration profile.
What makes devices different
- Physics sets permanent limits. Usable flash, RAM and maximum frame size decide whether a post-quantum handshake fits at all. A “no” caused by hardware is permanent; a “no” caused by a missing firmware feature is temporary. The inventory has to tell them apart.
- The producer knows the model, not the deployment. A manufacturer can declare what a model supports. Only the operator knows which firmware a unit runs, how its keys were provisioned and how long it will stay in the field.
- The party who can update may be neither vendor nor operator. Firmware may reach devices through a connectivity provider, a platform operator or an installer. Update mechanism, update authority and update support status are inventory attributes, not footnotes.
- Field life outlasts support. A device may operate for fifteen years while the manufacturer’s support ends much earlier. Stewardship after discontinuation is part of the plan.
The draft profile therefore proposes attributes such as resource bounds, update mechanism and authority, key provisioning and replaceability, the cryptography termination point (device, gateway or both) and integration constraints.

What TNO found
TNO’s 2025 market survey of CADI tooling for the Dutch government found the category less mature for operational technology than for IT: little OT tooling to tie into, and some providers with no interest in OT. It nevertheless considered CADI highly relevant for OT because of its role in vital infrastructure, and recommended more cooperation among stakeholders and clearer regulation on cryptographic inventory.
An honest approach
Nobody observes a fleet of constrained devices the way a scanner observes a server estate, and a tool that claims to should be asked how. What can be done today:
- Inventory what you can reach without touching devices. Firmware images, gateway configurations, the certificates and keys provisioned through the platform, and the traffic devices produce at a mirror point. Each of these is a source a discovery tool can read.
- Record the device-level attributes from the people who know them. Resource bounds, update authority and field life come from the vendor and the operator, not from a scan. Treat them as context attached to the model.
- Decide per model, not per unit. Devices are a class. The inventory should group findings by model and firmware version so the four-way decision is made once per class and applied to the units.
- Ask suppliers for a device CBOM as the profile matures. Until then, ask the questions the draft profile lists; they are the questions you will need answered anyway.
Cryptoramic can read firmware and disk images, captured traffic and gateway configurations, and attaches supplier evidence to identified products and versions. It does not run on constrained devices and does not claim visibility it cannot get. See the operational technology page for what a scoped assessment in such an environment looks like.
Frequently asked questions
Why is cryptographic inventory harder for IoT and OT than for IT?
Many devices have limited memory and processing power, stay in service for years and are difficult to update. The manufacturer may know what it shipped without knowing how each device is configured today. An inventory needs to capture those differences.
What did TNO find about CADI tooling for OT?
The 2025 survey found discovery tools less mature for operational technology than for IT. It also found fewer existing OT tools to connect them to. TNO still considered cryptographic discovery important for OT because these systems support critical infrastructure.
What should a device inventory record beyond algorithms?
Record whether the device can be updated, who controls updates, how long support lasts and whether keys can be replaced. Also capture limits such as memory and processing power, and whether cryptography runs on the device or a gateway. These details help determine whether a migration is practical.