Quaatso – Quantum Advanced Technologies & Solutions Quaatso Quantum Advanced Technologies & Solutions

Finding Your Encryption: A Beginner’s Guide to Cryptographic Inventories

You can’t upgrade encryption you don’t know about. A cryptographic inventory, sometimes called a CBOM, is the first step of every post-quantum migration.

By the Quaatso Team • • 2 min read
Share: 𝕏 in

Ask most organisations where they use RSA, and you’ll get a pause. That is normal, and it is exactly why every post-quantum migration starts with an inventory.

01

Encryption is everywhere, and mostly invisible

Encryption hides inside websites, mobile apps, databases, VPNs, email servers, payment terminals, cloud services, software libraries, hardware security modules and your suppliers’ products. Most organisations have never written down where it all is, because it usually just works.

02

What a cryptographic inventory is

A cryptographic inventory is a list of where and how your organisation uses cryptography. For each item, it records things like:

  • ◆Which algorithm is used (for example, RSA-2048 or ECDSA P-256).
  • ◆Where it is used (which application, server, device or supplier).
  • ◆What it protects (customer data, payments, logins, software updates).
  • ◆Who owns it, and how easily it can be changed.

When this list is kept in a standard, machine-readable format, it is often called a Cryptography Bill of Materials (CBOM). The open CycloneDX standard added support for CBOMs in version 1.6, released in 2024.

03

Why governments ask for one

US federal agencies are already required to inventory their quantum-vulnerable cryptography: a 2022 White House memorandum (M-23-02) asks them to submit inventories every year, and the Quantum Computing Cybersecurity Preparedness Act, signed in December 2022, put migration planning into law. The UK NCSC also makes discovery the first milestone, due by 2028.

04

How to build one, step by step

  1. 1Start with what matters most: list the systems that handle your most sensitive and long-lived data.
  2. 2Use tools, then check by hand: code scanners, network scanners and certificate tools can find much of your cryptography automatically, but not all of it.
  3. 3Ask your suppliers: much of your encryption lives in products you buy. Ask vendors which algorithms they use and when they will support the new standards.
  4. 4Rank by risk: combine how sensitive the data is, how long it must stay secret, and how hard the system is to change.
  5. 5Keep it up to date: an inventory is a living document, not a one-off project.
05

Common surprises

Inventories often uncover old algorithms nobody knew were still running, expired certificates, and encryption hard-coded inside legacy applications. Finding these is valuable even before quantum computers arrive, because many are weak today.

task_altKey takeaways

  • check_circleA cryptographic inventory lists which algorithms you use, where, and what they protect.
  • check_circleA CBOM is an inventory in a standard format; CycloneDX 1.6 supports it.
  • check_circleStart with sensitive, long-lived data and include your suppliers.

Sources and further reading

Keep reading

Related articles

View all articlesarrow_forward

Not sure what this means for your organisation?

Book a free, no-obligation consultation. We’ll explain your quantum risks and options in plain language.

Book a Consultationarrow_forward
Quaatso – Quantum Advanced Technologies & Solutions Who We Are

Quaatso (Quantum Advanced Technologies & Solutions) is a quantum technology consultancy. We help organisations migrate to quantum-safe cryptography and put practical quantum computing to work on real business problems.