PQC / CRYPTO-AGILITY / CBOM

CBOM Builder.

Additional page sections

Builds a manual cryptographic bill of materials draft with algorithms, operations, owners, evidence and migration candidates.

Version 2.4 Beta Protected engine CBOM draft
PURPOSE

Decision supported.

Builds a manual cryptographic bill of materials draft with algorithms, operations, owners, evidence and migration candidates.

Intended user

research, assurance and technical review teams

Output status

Preliminary outputHuman review requiredNot certification
USE CASES

Where this instrument fits.

  • Draft CBOM rows
  • Collect owner and evidence metadata
  • Prepare PQC migration inventory
  • Export crypto inventory data for review
INPUTS

Required input fields.

  • Asset or component (required)
  • Cryptographic algorithm (required)
  • Operation (required): Key exchange, Signature, Encryption, Hash
  • Protocol (required)
  • Certificate/key location (required)
  • Owner (required)
  • Confidentiality lifetime (required): Less than 1 year, 1-5 years, More than 5 years
  • Evidence source (required): Absent, Draft, Reviewed, Reviewed and monitored
  • Migration candidate (required): Unknown, Hybrid classical/PQC, PQC migration candidate

Data handling: this interface uses the L2ET protected same-origin instrument engine. Do not enter confidential, regulated, privileged, incident, medical or sensitive operational data.

METHOD

Inventory Table logic.

Structures cryptographic component rows and classifies quantum vulnerability, verification state and migration-candidate status.

Source families

CBOM practicecryptographic inventoryPQC migration

Assumptions

  • Manual entry only.
  • Fields must be verified from source systems or documentation.
  • CBOM completeness depends on discovery scope.
INTERACTIVE INSTRUMENT

CBOM draft.

Use the controls below to generate a preliminary artifact. The output is intentionally bounded and requires human review.

OUTPUT ARTIFACT

CBOM draft.

The generated artifact includes findings, assumptions, limitations, recommended next actions and exportable structured output.

Export options

Copy outputMarkdownJSONCSVPDF/print
EXAMPLE

Example input and output.

Example input

API gateway certificate uses RSA-2048 signature with medium confidentiality lifetime and draft evidence.

Example output

Produces CBOM row with owner, evidence source, vulnerability note and migration candidate field.

LIMITATIONS

What this tool does not do.

  • Not an automatic cryptographic scanner.
  • Does not inspect binaries or certificates.
  • Does not validate implementation security.

This instrument does not provide legal, medical, cryptographic, engineering, regulatory or compliance certification.

RELATED METHOD

Method and workflow links.

Read the family method note for assumptions, output artifacts, update policy and review boundaries.

Open methodology Open family

CHANGELOG

Version history.

  • v2.4 - Research-grade instrument template, method notes, assumptions, limitations, example and export actions added.
  • Last updated: 2026-05-27.
  • Maturity state: Beta.