The adage “you can’t manage what you can’t measure” has a cybersecurity analog: You can’t secure what you can’t see. With advanced quantum computing on the horizon, a race is on to take inventory.
At a theoretical but foreseeable moment called Q-Day, quantum systems will be able to break the public key cryptography that safeguards modern communications and commerce.
“For commercial enterprises, a security failure of this magnitude compromises far more than internal infrastructure,” says cybersecurity adviser and author Xander Hamman. “It erodes customer trust, damages brand integrity, and introduces severe operational liability when the validity of digital records, contracts, and software updates can no longer be guaranteed.”
Like others in the field, Hamman believes post-quantum readiness is a matter of urgency, And critical to any organization’s preparations, for visibility into and prioritization of what must be secured, is a Cryptographic Bill of Materials (CBOM).
Xander Hamman
CBOMs effectively move an abstract future concern into the here and now. They provide evidence for risk registers, control assessments, vendor due diligence, procurement requirements, audit reporting, investment decisions, and migration planning, says Peter Bentley, CEO of Patero, which advertises “cryptographic discovery and inventory for PQC [post-quantum cryptography] migration.”
A CBOM is not in itself a risk-reduction tool. Its value lies in connecting the systems inventory to business impact, accountable ownership, remediation priorities, and continuous governance.
As Hamman, who is founder and principal of Collective Force, explains, the key is to understand how post-quantum cryptography will impact the organization, its departments, business units, and mission-critical systems and software.
A similar concept, a Software Bill of Materials (SBOM), identifies software components and dependencies within a product or system, including supplier sourcing and version lineage.
A CBOM identifies the cryptographic assets used within and across those components. They include algorithms, protocols, keys, certificates, libraries, implementations, and their relationships.
The two bills of materials are complementary and may be represented within an extended “BOM" framework, according to Bentley. But an SBOM alone generally cannot reveal whether cryptography is vulnerable, deprecated, misconfigured, or difficult to replace.
Jamshir Qureshi, vice president, DevSecOps engineering, MUFG Bank, prepared this comparison:
|
SBOM |
CBOM |
|
Inventories software components (libraries, packages, dependencies) |
Inventories cryptographic assets (algorithms, keys, certificates, protocols) |
|
Answers: "What open-source libraries am I running?" |
Answers: "What encryption and signing mechanisms are those libraries using?" |
|
Primarily driven by supply-chain vulnerability management |
Primarily driven by post-quantum migration and crypto-agility |
An organization might know the pedigree of its software, yet be unable to answer questions essential to post-quantum migration. For example, which quantum-vulnerable algorithms are active? Where do they reside? How are they configured? What systems, data flows, or trust functions do they support? Are they inherited through third-party or open-source dependencies?
Essential to addressing quantum vulnerability is a granular level of architectural visibility. Organizations must understand which systems and software are most at risk, along with their upstream and downstream dependencies; which ones require more or less coordination; and which require the most or least effort.
This is known as understanding the crypto-agility in an operating environment, Hamman notes. The CBOM generates data in machine-readable format to facilitate scaling post-quantum migration efforts in a timely manner.
“PQC is all about prior planning,” states Tom Cornelius, founder of Secure Controls Framework (SCF) and an author of its Quantum Security (QTS) domain. “The projected window for legacy encryption to be vulnerable to hostile actors using quantum computers is within the next five years.
“The migration timeline for companies to transition from legacy to quantum-resistant algorithms is expected to take years, so it is a race at this point. Those companies that wait until the threat materializes will essentially have no transmission confidentiality.”
Hamman identifies challenges that CBOMs may face:
-- Institutional resistance. After working on SBOMs, and misguidedly assuming they will carry over to quantum, firms will be reluctant to introduce another bill of materials into their workflows.
-- Resources. Budgets for security tooling are frequently constrained and competing with other business priorities.
-- Unavailable vendors. The longer firms delay PQC migration efforts, the more CBOM solution providers’ lead times and prices can be expected to increase – which should incentivize acting sooner.
The CBOM by itself will not accomplish migration and implementation, Hamman stresses. Due to the complexities of upstream and downstream workflow dependencies, fragmented system and software architecture and vendor relationships, the project requires clear ownership and accountability to succeed.
A CBOM is neither silver bullet nor panacea, Hamman says. He defines it as “the diagnostic foundation for understanding where an organization’s digital trust resides; where that trust is vulnerable; and what must change.”
It is the critical operational bridge between recognizing that the quantum threat is real and executing against that. And at its best, the CBOM is not static, but instead becomes a continuous monitor of cryptographic situational awareness. It will connect discovery, business context, risk prioritization, vendor accountability, crypto-agility, and remediation – toward the goal of making better and faster risk decisions, Hamman maintains.
To effectuate a CBOM, Bentley says, cyber and risk professionals must prioritize actionable, contextualized security strategies to ensure that assets remain secure within dynamic environments, while also enabling a long-term security strategy.