CycloneDX Bill of Materials Standard
Second edition aligns to CycloneDX v1.7. The first edition (June 2024) aligned to v1.6 — cite the edition, not just the ECMA number.
CBOM Reference Register
Standards, regulation and guidance relevant to Cryptography Bills of Materials. Filter, search, or regroup the register below.
Second edition aligns to CycloneDX v1.7. The first edition (June 2024) aligned to v1.6 — cite the edition, not just the ECMA number.
Released 21 October 2025; final release of the 1.x line and backward compatible with 1.4–1.6. Adds the algorithm-family and elliptic-curve properties `algorithmFamily` and `ellipticCurve`, both constrained to enumerations held in the `cryptography-defs` subschema, and deprecates the free-text `curve` property carried since v1.6. Field names confirmed against the published 1.7 schema.
Authoritative machine-readable registry of algorithm families and curves, published as the `cryptography-defs` JSON Schema and carrying its own `lastUpdated` timestamp rather than the specification's version. Enumerates 93 algorithm families and 246 elliptic curves, and records per-curve aliases tagged by category — which is the naming problem of Q20 expressed as data, and what makes it the natural normalisation target for a format-independent profile.
No dedicated cryptographic-asset object model equivalent to CycloneDX CBOM in the released 3.0.1 line. Work has since become concrete: an SPDX Cryptography Group now maintains a Cryptographic Algorithm List [F9], and a 3.1 release candidate is in progress. Confirm the 3.1 status and the standing of the algorithm list with the SPDX project before citing.
Normative keyword vocabulary for profile conformance language.
A community-curated vocabulary of cryptographic algorithms, modelled on the SPDX License List and maintained alongside the specification rather than inside it. It is the SPDX-side counterpart to the CycloneDX Cryptography Registry [F3], and therefore the normalisation target an SPDX mapping would have to use. No numbered release; its normative standing within SPDX is not established. Confirm both before citing.
Vendor-neutral, format-independent methodology for defining CBOM profiles that map onto CycloneDX and SPDX. Deliverables in development: CBOM Profile Methodology and Standards Mapping Guidance.
The motivating precedent for the profile-first, format-independent methodology. Cite this — not the PQC Maturity Model, which is a separate effort.
Prioritise inventoried assets by data sensitivity and protection lifetime.
Maintained tracker of national PQC mandates; useful for keeping this register current.
Assesses products and services in the supply chain rather than an organisation's internal posture, which makes its subject the same as this methodology's. Level 3 requires a cryptographic inventory and SBOM support; Level 4 requires CBOM support without defining what a CBOM must contain, and names no format. That undefined requirement is the dependency the profile methodology addresses.
Aggregates vendor-declared post-quantum capability across products, recording support for ML-KEM, ML-DSA, SLH-DSA, LMS and XMSS as available, planned, unavailable or not applicable. Its subject overlaps the migration profile's declared capability attributes. No version or release date is published for the matrix itself.
Assesses an organisation's PKI operation across five levels, with a separate PQC Readiness Extension. Its subject is the operator rather than the product, so it sits at a different level from both the PQCMM [M10] and this methodology.
Sector guidance directing financial institutions to inventory cryptographic assets together with the keys, systems and business processes that depend on them. Names no format, which makes the sector a candidate consumer of a profile rather than a competing specification. Individual papers are undated on the landing page; take dates from each paper before citing.
Requirement 12.3.3 obliges an entity to document an inventory of the cryptographic cipher suites and protocols in use, with where and why each is used, and to review it at least every twelve months; it became mandatory on 31 March 2025. A binding commercial inventory mandate that names no format. Confirm the requirement text and the current DSS revision against the PCI SSC library before citing.
Frames the move to a fully quantum-safe state in three stages, of which the first is compiling an inventory of cryptographic assets. The earliest inventory-first migration framework this register carries, predating the national roadmaps by several years, and it names no format.
Main obligations apply from 11 December 2027. Mandates SBOM-based supply-chain transparency; contains no direct CBOM reference.
Milestones: 31 Dec 2026 national roadmaps plus identification and awareness (i.e. cryptographic inventory); 31 Dec 2030 high-risk use cases; 31 Dec 2035 full transition. Annual reporting from April 2026. Recommends a standardised format for cryptographic inventories — the clearest hook for a CBOM profile in EU policy.
Recommends inventorying cryptographic assets.
Raises CycloneDX 1.5 to 1.6 and SPDX 2.2.1 to 3.0.1. Supersedes v2.0.0.
The German baseline for algorithm and key-length adequacy against which a CBOM profile's conformance rules would be assessed.
The NIS-2 cryptographic-procedures framework follows Inventarisieren → Bewerten → Umsetzen. BSI has no official German term for CBOM; recommended first use is "CBOM (kryptografische Stückliste)".
Three phases: by 2028 discovery, cryptographic inventory and migration plan; 2028–2031 high-priority upgrades; 2031–2035 full migration.
Second edition of the March 2023 handbook, presented on 3 December 2024. Covers cryptographic asset management and the creation of a cryptographic inventory, with expanded advice on discovering cryptography inside software and on crypto-agility. Guidance rather than a mandate, and it names no format.
Follow-up to the March 2022 position paper. Requires hybridisation wherever post-quantum mitigation is needed, on the grounds that post-quantum algorithms are not yet mature enough to stand alone, and sets the agenda for French security visas covering hybrid implementations. Bears directly on how a profile represents hybrid and coexistence as facts rather than as a judgement.
A national algorithm and key-length baseline of the same kind as BSI TR-02102-1 [E6], against which a profile's conformance rules would be assessed. Revised more than once during 2025; confirm the current revision and its date against NÚKIB before citing.
Amends rather than rescinds EO 14144. Directs CISA to publish a list of product categories supporting PQC; removes the 90-day solicitation trigger and the "as soon as practicable" hybrid-adoption mandate.
Two tiers — Widely Available (cloud, browsers, endpoint security) and Transitioning (networking, SAN, IAM, containers). Advisory, not a procurement mandate.
Substantially amended by EO 14306.
Origin of federal SBOM procurement expectations.
Directs federal agencies to maintain a cryptographic inventory.
Statutory basis for federal inventories of cryptographic systems and migration prioritisation.
RSA/ECC deprecated 2030, disallowed 2035. Still an initial public draft, so the report itself binds nothing — but OMB M-26-15 [U15] directs agencies to align their migration plans with it "or successor document", which gives the draft timeline force it does not carry on its own. Cite it as the referenced timeline, not as a standard.
Volume B covers public-key application discovery tools and a multi-tool discovery approach — directly relevant to how a conforming CBOM is produced.
Signed 22 June 2026 and published 25 June 2026. Accelerates the migration of federal systems to the NIST PQC standards and directs assistance to critical infrastructure owners and operators. The operative timetable is set out in OMB M-26-15 [U15], which implements it two days later.
Implements EO 14412 [U14] and discharges OMB's duty under the Quantum Computing Cybersecurity Preparedness Act [U6]. Sets five migration phases from 2026 to 2035, and requires each agency's plan to state "the methodologies and automated tools used for the cryptographic inventory". Of that inventory it says the data "should populate a central Cryptographic Bill of Materials (CBOM)" — and names no CBOM format, which makes it the most direct statement to date of the gap this working group exists to fill. Excludes national security systems.
The reference OMB M-26-15 [U15] cites for cryptographic agility. Relevant because agility is a judgement formed from disclosed facts rather than an attribute a CBOM records, which is the separation decision 0002 rests on. An updated revision (upd1) exists; confirm which revision and date apply before citing.
Issued under EO 14028 [U4] and the origin of the seven baseline SBOM data fields. Updated and replaced by the 2026 minimum elements [X1]. Retained because procurement language and existing tooling still cite it by name.
The most CBOM-explicit national guideline published to date. Defines five BOM types; the CBOM is an inventory of cryptographic assets carrying metadata such as usage patterns and expiry, with a separate QBOM for quantum algorithms and quantum-safe technologies. Currently voluntary, addressed to the public sector, government, essential services and the software export industry. A strong candidate consumer of a PKIC-defined profile.
Directs financial institutions to maintain an inventory of all cryptographic assets and identify priority assets for migration. Names no format.
Handbook covers discovery of cryptographic assets, risk-based prioritisation, phased migration, testing and post-migration monitoring. The Readiness Index is a five-domain self-assessment: governance, risk assessment, training and capability, external engagement, technology and agility.
The most aggressive timeline of any jurisdiction: traditional asymmetric cryptography to cease by end 2030, pure PQC rather than hybrid, ML-KEM-1024 preferred. Control ISM-1917 already requires cryptographic dependencies to be considered in procurement.
Sets a 2035 government PQC transition target; CRYPTREC will fold NIST PQC algorithms into Japan's recommended-algorithm lists.
No regional ASEAN PQC or CBOM framework exists; the ASEAN Digital Masterplan 2025 does not mention quantum. Activity is national — Singapore leads (nationwide quantum-safe network; MAS quantum-safe sandbox with DBS, HSBC, OCBC and UOB), with Malaysia and Indonesia (BSSN) following. Recorded as an engagement opportunity for the working group rather than a citable reference.
Sets a 2035 target for transitioning national cryptographic systems, organised in six tracks covering technology, regulation, procedure, transition support, assurance infrastructure and industrial base. Korea also runs its own KpqC algorithm selection alongside the NIST standards, so a profile applied here must carry algorithm names that are not in either carrier's registry. Primary sources are Korean-language and the document designation is not confirmed against them.
Updates the 2021 NTIA minimum elements. Adds SBOM Generation Context (the lifecycle phase at which the data was captured), SBOM Author Signature, data format name and version, and tool provenance. Requires authors to distinguish information that is unknown from information deliberately withheld, and states that supporting automation means supporting all widely used formats rather than mandating one — both positions the profile methodology depends on. Updates and replaces the 2021 NTIA minimum elements [U17].
April 2026 initial departmental migration plan with annual reporting; end 2031 high-priority systems migrated; end 2035 remaining systems.
The protocol behind the worked example's service interface. Defines the handshake whose negotiated result, rather than either endpoint's capability, determines the cryptography actually in use.
The protocol behind the worked example's management interface. Authenticates with a host key rather than a certificate, which is why a profile has to name the authentication role abstractly rather than in TLS terms.
Defines X25519, used for key exchange in the worked example. The same curve appears in the wild as P-256-style SECG and ANSI names elsewhere, which is the naming problem the CycloneDX Cryptography Registry addresses.
Defines Ed25519, the host key algorithm in the worked example's SSH interface.
The AEAD construction used by the worked example's SSH interface.
RSA, used for the server certificate signature in the worked example. Quantum vulnerable, and therefore one of the facts a post-quantum posture evaluation is derived from.
Defines GCM, the mode in AES-256-GCM. Mode matters for identity: a bare "AES256" omits it, which is why encoding an algorithm name without its parameters cannot be compared reliably.
The identifier scheme the methodology uses to name the library implementing an interface, and the value that links a CBOM entry to vulnerability feeds and to the corresponding SBOM component.
Informational, and the agreed vocabulary for schemes combining post-quantum and traditional algorithms — hybrid, composite, combiner. A profile describing coexistence or hybrid capability should take its terms from here rather than coin its own.
Normative constructions for combining elliptic-curve key exchange with ML-KEM, superseding V1.1.1 of December 2020. A named construction of this kind is what an interface disclosure records when it states a hybrid key exchange, rather than the two algorithms listed separately. Confirm the published version against the ETSI portal before citing.
No references match those filters.