QNSI

QNSI platform

What is CBOM?

Also known as Cryptographic Bill of Materials.

CycloneDX-compatible inventory of every cryptographic asset across an organisation's estate - algorithms, keys, certificates, TLS endpoints, code-signing keys. QNSI crypto-inventory-service exports CBOM with per-asset NIST classification and HNDL-exposure scoring.

Decision context

Why CBOM matters

A cryptographic bill of materials connects algorithms, keys, certificates, protocols, libraries, owners and data lifetimes so migration can be prioritized. A CBOM is useful only when discovery coverage, freshness, provenance and ownership are visible; an inventory assembled from one scanner is rarely complete.

How to evaluate CBOM

Check which sources, hosts, repositories, clouds and runtime paths were actually observed, when, and with what permissions. Reconcile duplicates and unknowns, link assets to business services and owners, and retain source evidence. Report uncovered scope as unknown rather than as a plausible zero.

QNSI platform

QNSI platform evidence boundary

QNSI platform terms describe intended control or evidence boundaries. Their presence in documentation is not proof that a customer deployment executed them. Verify the selected service path, tenant policy, custody provider, production record, and independent evidence before relying on the term in an assurance decision.

FAQ

Common questions

What is CBOM?

CycloneDX-compatible inventory of every cryptographic asset across an organisation's estate - algorithms, keys, certificates, TLS endpoints, code-signing keys. QNSI crypto-inventory-service exports CBOM with per-asset NIST classification and HNDL-exposure scoring.

Why does CBOM matter?

A cryptographic bill of materials connects algorithms, keys, certificates, protocols, libraries, owners and data lifetimes so migration can be prioritized. A CBOM is useful only when discovery coverage, freshness, provenance and ownership are visible; an inventory assembled from one scanner is rarely complete.

How should CBOM be evaluated?

Check which sources, hosts, repositories, clouds and runtime paths were actually observed, when, and with what permissions. Reconcile duplicates and unknowns, link assets to business services and owners, and retain source evidence. Report uncovered scope as unknown rather than as a plausible zero.

What is CBOM also known as?

CBOM is also known as Cryptographic Bill of Materials. CycloneDX-compatible inventory of every cryptographic asset across an organisation's estate - algorithms, keys, certificates, TLS endpoints, code-signing keys. QNSI crypto-inventory-service exports CBOM with per-asset NIST classification and HNDL-exposure scoring.

More

Keep exploring