Open source · AGPL-3.0
Active
qubitac · checked 13 Sep 2026
A network scanner that outputs a CBOM as structured JSON. Its README does not say which format the JSON follows.
- Does
- Generates
- Finds cryptography in
- Network traffic
Where CBOM support is stated ↗
Free tier
Active
AppViewX · checked 13 Sep 2026
Scans code, dependencies, certificates and configuration, gives a PQC readiness score, and generates a CBOM in CycloneDX or CSV. Free with registration.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Source codeCertificates and keystoresConfiguration
- Formats
- CycloneDX
Where CBOM support is stated ↗
Commercial
Active
SandboxAQ · checked 13 Sep 2026
A platform for discovering and managing cryptographic assets that imports CBOM files produced by other tools. The product site also says it generates CBOMs; the export format is not stated.
- Does
- ConsumesGeneratesAnalyses
- Formats
- CycloneDX 1.4 (import)CycloneDX 1.6 (import)
Where CBOM support is stated ↗
Open source · GPL-3.0-only
Active
Software Engineering Group, University of Bern · checked 13 Sep 2026
A research framework that runs several CBOM generators in containers and compares their output side by side.
- Does
- AnalysesConsumesVisualises
Where CBOM support is stated ↗
Free tier
Active
verify
NextGenRails · checked 13 Sep 2026
A web service that grades the cryptographic assets in an uploaded BOM against NIST PQC deadlines. The site gives no company details beyond a contact address.
- Does
- ValidatesConsumesAnalyses
- Formats
- CycloneDX 1.6CycloneDX 1.7SPDX
Where CBOM support is stated ↗
Open source · GPL-3.0-or-later
Active
CipherIQ · checked 13 Sep 2026
A browser-based viewer that loads a CBOM and shows its assets and dependencies as an interactive graph. Also offered under a commercial licence.
- Does
- VisualisesConsumes
- Formats
- CycloneDX 1.6CycloneDX 1.7
Where CBOM support is stated ↗
Open source · GPL-3.0-or-later
Active
CipherIQ · checked 13 Sep 2026
A static scanner for Linux systems that inventories certificates, keys, algorithms, cryptographic libraries and services. Also offered under a commercial licence.
- Does
- Generates
- Finds cryptography in
- FilesystemsCertificates and keystoresConfiguration
- Formats
- CycloneDX 1.6CycloneDX 1.7
Where CBOM support is stated ↗
Commercial
Active
Encryption Consulting · checked 13 Sep 2026
A discovery and inventory product with sensors for cloud platforms, HSMs, TLS endpoints, directories, databases, filesystems, source code and binaries.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Source codeBinariesFilesystemsNetwork trafficCloud servicesCertificates and keystores
- Formats
- CycloneDX 1.6CycloneDX 1.7
Where CBOM support is stated ↗
Open source · MIT
Active
GitHub (advanced-security) · checked 13 Sep 2026
GitHub Actions that build a crypto bill of materials from CodeQL analysis across a set of repositories and languages. The output format is not documented.
- Does
- Generates
- Finds cryptography in
- Source code
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
OmniTrust (formerly 3Key Company, CZERTAINLY) · checked 13 Sep 2026
A command-line tool or service that finds certificates, keys, secrets and algorithms on filesystems, in container images and on network ports, and writes a CBOM.
- Does
- Generates
- Finds cryptography in
- FilesystemsContainer imagesNetwork trafficCertificates and keystores
- Formats
- CycloneDX 1.6CycloneDX 1.7
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
OmniTrust (formerly 3Key Company, CZERTAINLY) · checked 13 Sep 2026
A REST service on S3-compatible storage for uploading, versioning, retrieving and searching CBOMs in JSON.
- Does
- Stores and managesConsumes
- Formats
- CycloneDX 1.6CycloneDX 1.7
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
Anthony Harrison · checked 13 Sep 2026
Generates a CBOM for installed certificates. One of few tools offering SPDX output, which its README describes as incomplete.
- Does
- Generates
- Finds cryptography in
- Certificates and keystores
- Formats
- CycloneDXSPDX (incomplete)
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
Sadjad Asadi · checked 13 Sep 2026
Takes a CBOM from any generator and evaluates it against several national PQC policies. It does not scan anything itself.
- Does
- AnalysesConsumes
- Formats
- CycloneDX
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
Post-Quantum Cryptography Alliance (Linux Foundation); originally IBM Research · checked 13 Sep 2026
A service with a web viewer, an API and a database: it generates CBOMs from repositories, displays uploaded CBOMs, checks them against compliance policies, and stores them behind a REST API.
- Does
- GeneratesStores and managesVisualisesAnalysesConsumes
- Finds cryptography in
- Source code
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
Post-Quantum Cryptography Alliance (CBOMkit project) · checked 13 Sep 2026
A GitHub Action that finds the modules in a repository, scans their Java and Python source, and produces one CBOM per module as a workflow artifact.
- Does
- Generates
- Finds cryptography in
- Source code
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
Post-Quantum Cryptography Alliance (CBOMkit project) · checked 13 Sep 2026
A command-line tool that finds certificates, keys, secrets and cryptographic configuration in container images and directories and writes a CBOM, or enriches an existing one. It does not scan source code.
- Does
- GeneratesConsumes
- Finds cryptography in
- Container imagesFilesystemsCertificates and keystoresConfiguration
- Formats
- CycloneDX 1.6
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
cdxgen project (OWASP) · checked 13 Sep 2026
A general BOM generator whose CBOM coverage is Java keystores and certificates and algorithm use in JavaScript and TypeScript source; its tracebom command records cryptographic activity while a command runs.
- Does
- Generates
- Finds cryptography in
- Certificates and keystoresSource codeRunning systems
- Formats
- CycloneDX 1.7
Where CBOM support is stated ↗
Open source · MIT-0
Active
AWS Samples · checked 13 Sep 2026
Builds an organisation-wide inventory of cryptography in AWS services as a CBOM. A sample project rather than a supported AWS product.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Cloud services
- Formats
- CycloneDX 1.7
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
jhammant · checked 13 Sep 2026
A scanner for network endpoints and certificates that can write its findings as a CBOM.
- Does
- Generates
- Finds cryptography in
- Network trafficCertificates and keystores
- Formats
- CycloneDX 1.6
Where CBOM support is stated ↗
Open source · GPL-3.0
Active
Santander Security Research · checked 13 Sep 2026
Turns CodeQL analysis results into a CBOM and checks a CBOM against rules, reporting in SARIF. Its documented output uses the CBOM extension that preceded CycloneDX 1.6.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Source code
- Formats
- CycloneDX 1.4 with the pre-standard CBOM extension
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
CSNP (QRAMM Toolkit) · checked 13 Sep 2026
Analyses a project's dependencies for cryptography and can report as a CBOM. The sample output in its README declares CycloneDX 1.5, which predates cryptographic assets in CycloneDX.
- Does
- Generates
- Finds cryptography in
- Source code
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
CSNP (QRAMM Toolkit) · checked 13 Sep 2026
A source code scanner with a CBOM output format. The sample output in its README declares specVersion 1.0, and CycloneDX 1.6 cryptographic properties are listed as planned.
- Does
- Generates
- Finds cryptography in
- Source code
Where CBOM support is stated ↗
Open source · MIT
Active
Software Engineering Group, University of Bern · checked 13 Sep 2026
Experimental software that traces OpenSSL 3 calls at runtime with eBPF and writes a CBOM, without changing the traced program.
- Does
- Generates
- Finds cryptography in
- Running systems
- Formats
- CycloneDX 1.6
Where CBOM support is stated ↗
Commercial
Active
verify
IBM · checked 13 Sep 2026
Imports code repository findings from IBM Quantum Safe Explorer, including CBOMs, into a portfolio view. CBOM is mentioned only as an imported data type.
- Does
- ConsumesAnalyses
Where CBOM support is stated ↗
Commercial
Active
IBM · checked 13 Sep 2026
Scans source code in several languages for quantum-vulnerable cryptography and reports as a CBOM, among other formats. The documentation does not name a CycloneDX version.
- Does
- Generates
- Finds cryptography in
- Source code
Where CBOM support is stated ↗
Commercial
Active
Keyfactor (formerly InfoSec Global) · checked 13 Sep 2026
A cryptographic inventory platform that exports its findings as a CBOM for each scanned source, from release 3.4.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Source codeBinariesConfiguration
- Formats
- CycloneDX 1.6
Where CBOM support is stated ↗
Open source · MIT
Active
jimbo111 · checked 13 Sep 2026
A scanner that combines its own findings with those of other engines, such as CryptoScan, cdxgen and CBOMkit-theia, into one CBOM.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Source codeBinariesNetwork trafficCertificates and keystores
- Formats
- CycloneDX 1.7
Where CBOM support is stated ↗
Open source · MIT
Active
PQCWorld · checked 13 Sep 2026
An audit tool for quantum-vulnerable cryptography in code, configuration and endpoints that reports as a CBOM.
- Does
- Generates
- Finds cryptography in
- Source codeConfigurationNetwork traffic
- Formats
- CycloneDX 1.6
Where CBOM support is stated ↗
Open source · MIT
Active
Qtonic Quantum · checked 13 Sep 2026
Reads PEM and DER certificate files and writes a CBOM.
- Does
- Generates
- Finds cryptography in
- Certificates and keystores
- Formats
- CycloneDX 1.7
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
quantakrypto (Dandelion Labs) · checked 13 Sep 2026
A set of scanners for source code and network endpoints whose outputs include a CBOM. Its README does not name the CBOM format.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Source codeNetwork traffic
Where CBOM support is stated ↗
Commercial
Active
QCecuring · checked 13 Sep 2026
A discovery product covering code repositories, directories, certificate authorities, web servers, cloud platforms, HSMs and Kubernetes that reports in CycloneDX JSON and XML.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Source codeCertificates and keystoresNetwork trafficCloud services
- Formats
- CycloneDX
Where CBOM support is stated ↗
Commercial
Active
Qinsight · checked 13 Sep 2026
A cryptographic posture management platform that builds a CBOM for each scanned source. The product page does not name a format.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Cloud servicesSource codeRunning systems
Where CBOM support is stated ↗
Commercial
Active
Qtonic Quantum (formerly Qryptonic) · checked 13 Sep 2026
An assessment service and platform for quantum cryptographic risk with CBOM output among its deliverables.
- Does
- AnalysesGenerates
- Formats
- CycloneDX 1.7
Where CBOM support is stated ↗
Commercial
Active
QuSecure · checked 13 Sep 2026
A PQC platform whose reporting component produces CBOMs from the inventory its sensors build.
- Does
- GeneratesAnalyses
- Formats
- CycloneDX
Where CBOM support is stated ↗
Commercial
Active
PQStation · checked 13 Sep 2026
A discovery platform that reconciles network, certificate, filesystem and source code observations into one CBOM.
- Does
- GeneratesAnalyses
- Finds cryptography in
- Network trafficCertificates and keystoresFilesystemsSource code
- Formats
- CycloneDX 1.7
Where CBOM support is stated ↗
Open source · MIT
Active
sbom-tool project · checked 13 Sep 2026
A tool for diffing, quality scoring and compliance checks of BOMs that reads the cryptographic properties of CycloneDX 1.6 and 1.7 documents and tells a CBOM from an SBOM.
- Does
- AnalysesConsumesValidatesVisualises
- Formats
- CycloneDX 1.6CycloneDX 1.7
Where CBOM support is stated ↗
Open source · Apache-2.0
Active
Post-Quantum Cryptography Alliance (CBOMkit project) · checked 13 Sep 2026
A SonarQube plugin, also known as CBOMkit-hyperion, that detects cryptographic assets in Java, Python and Go source and writes a CBOM when its Cryptographic Inventory rule is enabled.
- Does
- Generates
- Finds cryptography in
- Source code
- Formats
- CycloneDX 1.6
Where CBOM support is stated ↗
Open source · MIT
Active
CSNP (QRAMM Toolkit) · checked 13 Sep 2026
Analyses TLS endpoints and can report as a CBOM.
- Does
- Generates
- Finds cryptography in
- Network traffic
- Formats
- CycloneDX
Where CBOM support is stated ↗
Commercial
Active
TYCHON · checked 13 Sep 2026
A cryptographic inventory product with quantum readiness scoring that lists CBOM as an inventory output.
- Does
- GeneratesAnalyses
- Formats
- CycloneDX
Where CBOM support is stated ↗
No tools match those filters.