CBOM · GOVERNANCE PRODUCT / PLATFORM MODULE

QuantumSafe CBOM & Inventory
Available

Maintain a versioned cryptographic bill of materials for systems, applications and suppliers.

CUSTOMER PROBLEM

Maintain a versioned cryptographic bill of materials for systems, applications and suppliers.

Cryptographic assets change across releases and suppliers; a one-time spreadsheet cannot support lifecycle governance, audit or migration waves.

Available
Portfolio class
Governance product / platform module
Public profile
2026.07
Version rule
Confirmed in quotation / release record

PRODUCT-SPECIFIC IMPLEMENTATION FLOW

How QuantumSafe CBOM & Inventory operates from input to evidence.

CSV/JSON import, assessment workflow and project-specific connectors. Versioned CBOM, ownership records, review history and exportable audit package.

01

Import approved source data

Versioned algorithm and key inventory

02

Normalize algorithm identifiers

Certificate, OID and profile registry

03

Build component relationships

Software, firmware and supplier dependency mapping

04

Assign owners and suppliers

Ownership, review and exception workflow

05

Review changes and exceptions

CSV/JSON import and controlled export

06

Export signed inventory snapshot

Change history for audit and procurement

NAMED COMPONENTS AND RESPONSIBILITIES

What QuantumSafe CBOM & Inventory contains and what each component does.

The descriptions below state concrete technical behaviour rather than generic support language.

01

Versioned algorithm and key inventory

Stores algorithm, key type, key length, purpose, location and lifecycle state as versioned records rather than unstructured assessment notes.

02

Certificate, OID and profile registry

Maintains certificate profiles, OIDs, issuance hierarchy, validity rules and relying-party dependencies alongside the systems that consume them.

03

Software, firmware and supplier dependency mapping

Connects software packages, firmware builds, devices and suppliers so that a library or vendor change can be traced to affected services.

04

Ownership, review and exception workflow

Routes additions, corrections and exceptions through named owners, reviewers and approval states with a complete change history.

05

CSV/JSON import and controlled export

Accepts controlled CSV or JSON imports with schema validation and produces filtered exports for engineering, audit and procurement audiences.

06

Change history for audit and procurement

Preserves who changed each record, why it changed, what evidence supported it and which inventory version was used for a decision.

CUSTOMER OUTCOMES
  • Algorithm and key inventory
  • Certificate/profile registry
  • Supplier and product dependency view
INTEGRATION BOUNDARY

CSV/JSON import, assessment workflow and project-specific connectors.

DEPLOYMENT PATTERNS

Bounded assessment workspace

Collectors run against approved sources; findings are reviewed before entering the governed inventory.

Continuous enterprise integration

Scheduled collectors and connectors feed the inventory, risk and policy workflows under customer control.

Managed governance operation

Mobile-ID facilitates refresh, review and reporting while the customer retains ownership and approval authority.

EVIDENCE REQUIRED
  • Versioned CBOM, ownership records, review history and exportable audit package.
  • Version and configuration manifest for: CSV/JSON import, assessment workflow and project-specific connectors.
  • Negative, failure and recovery tests for “Review changes and exceptions” and “Export signed inventory snapshot”.
  • Signed acceptance record, accountable owner, published limitations and next review date.
STANDARDS & PROFILES
  • CycloneDX CBOM
  • SPDX / SBOM linkage
  • X.509 / PKIX
  • ISO 27001 asset governance

PRODUCT-SPECIFIC BOUNDARIES

Conditions that must remain true for QuantumSafe CBOM & Inventory.

These points come from the product profile, not from a shared disclaimer.

NEXT STEP

Request a product workshop: QuantumSafe CBOM & Inventory

Review the exact operating model, interfaces and evidence needed for deployment.