What does CADI mean?
CADI stands for cryptographic asset discovery and inventory. It is the practice, and the category of tools, for finding the cryptography an organization depends on and recording it in a form that supports decisions: which certificates, keys, algorithms and protocols exist, where they were observed, what software and services use them, and how that compares with policy.
The term is used in procurement and in government guidance, including a 2025 market survey of CADI tooling that TNO carried out for the Dutch government (our summary), because a cryptographic inventory is the precondition for almost every other cryptographic control: certificate lifecycle management, crypto-agility, post-quantum migration and audit evidence all start from knowing what is there.
How does CADI differ from a certificate inventory?
A certificate inventory records certificates and their properties, usually from a certificate authority, a load balancer or a network scan. CADI is broader on three axes:
- Assets. Keys, keystores, algorithm and protocol configurations, signatures, and cryptographic libraries inside software, not only certificates.
- Sources. File systems, container and disk images, source repositories, Windows certificate stores and traffic captures, alongside network endpoints.
- Context. The discovery path of each finding, the host and software version it belongs to, and the supplier behind that software.
A certificate inventory is a useful part of a cryptographic inventory. It is not a substitute for it.

What is a CBOM, and how does it relate?
A cryptographic bill of materials (CBOM) is a structured document, standardized in CycloneDX, that lists the cryptographic assets and dependencies of a system or product. CADI produces the observations; a CBOM is one way to exchange them, for example with a supplier, an auditor or a software supply-chain process. A CADI tool should import CBOMs it receives and export CBOMs for the scope it has assessed.
Where do crypto-agility and cryptographic posture management fit?
Crypto-agility is the ability to change algorithms, keys and protocols without redesigning systems. Cryptographic posture management (CPM) is the continuous assessment of an estate against cryptographic policy. Both depend on an inventory that is current and traceable. In practice the terms overlap: a CADI tool with policy evaluation and repeat assessments provides the posture view; the migration work that follows is where agility is tested.
Why does post-quantum migration make CADI urgent?
Post-quantum cryptography replaces the key-establishment and signature algorithms most systems use today. Migrating requires knowing where those algorithms are used, which software versions can be upgraded, which suppliers must deliver a change, and which data is exposed to a harvest-now-decrypt-later attack in the meantime. An inventory that stops at certificates misses most of that.
What should you look for in a CADI tool?
- Breadth of sources with provenance. Files, images, repositories, stores and traffic, with the discovery path kept for every finding.
- Policy assessment that explains itself. Findings tied to a rule, a source reference and a date, not a single opaque score.
- Software and supplier context. Product and version identification, so a finding turns into an upgrade or a supplier question.
- A deployment model your security team accepts. Runs on your infrastructure, keeps secret key material out of results, and works offline where needed.
- A first result without a platform project. You should be able to assess one golden image or one segment this week.
Cryptoramic is a CADI product with policy assessment, supplier readiness and reporting built in. Explore the platform or read what discovery covers.
Frequently asked questions
What does CADI stand for?
Cryptographic Asset Discovery and Inventory. It means finding the certificates, keys, algorithms and protocols your organization depends on, and recording where they are found and how they are used.
Is a CADI tool the same as a certificate manager?
No. Certificate management focuses on issuing, renewing and managing certificates. CADI looks more broadly for cryptography, including keys, software libraries and security settings. Some products combine these functions, so check their actual coverage.
What is the difference between a CBOM and a cryptographic inventory?
The inventory is your record of discovered cryptography. A cryptographic bill of materials, or CBOM, is a document describing cryptography for a particular system or product. You can export it to share findings with suppliers or auditors.
Do you need a complete cryptographic inventory before starting post-quantum migration?
No. Start with one application, network segment or set of software images. Fix the issues you can control and ask suppliers about the rest. Expand the inventory as you learn.