Migration Planning / Crypto BOM (CBOM) Builder
§5.3What this is for: Build a CBOM slice from an SBOM, library posture, or HSM inventory; feeds the Assets pipeline.
What a good answer looks like: A CBOM you can regenerate. A hand-built one is accurate for a week; a generated one is accurate for as long as you keep generating it.
Worked example: Switch to SBOM → CBOM and pick the payments-service sample: its five components, OpenSSL 1.1.1w and a non-FIPS Bouncy Castle among them, each get a FIPS, ESV, PQC and posture reading, and one click downloads a CycloneDX 1.7 CBOM.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Three linked views, SBOM to CBOM, library posture and hardware FIPS 140-3 inventory, produce a CBOM slice: the point is a bill of materials you can regenerate, not one built by hand.
- GRC / Risk & Compliance
- Map an SBOM into a CBOM, record library posture and the HSM inventory with CMVP references, then Download CycloneDX 1.7: it is the inventory evidence that feeds the assets pipeline and the audit checklist's 'CBOM generated' item.
Three linked views over the software and hardware inventory: map an SBOM into a crypto-focused slice, inspect your library posture, and track Level 3 status for every HSM your keys live in.
Illustrative data for teaching. Cert numbers, firmware revisions, and PQC support claims below are educational snapshots, not live records. Verify against the NIST CMVP database and the vendor's product page before quoting.
| Library | Latest | EoL | FIPS 140-3 | ESV (SP 800-90B) | PQC | High CVEs (1y) | Posture |
|---|---|---|---|---|---|---|---|
OpenSSL OpenSSL Project | 3.5.0 LTS | 2030-04-08 | FIPS active | not validated | ML-KEM, ML-DSA, SLH-DSA in OpenSSL 3.5; none is in the approved-algorithm list of #4985 | 1 | |
OpenSSL OpenSSL Project | 1.1.1w | 2023-09-11 | historical #3622 (Canonical Ubuntu 18.04 OpenSSL module; FIPS 140-2, historical)sample | not validated | None | 3 | |
BoringSSL / BoringCrypto Google | 20250310 | active | FIPS active | ESV active | Hybrid X25519MLKEM768 in Chrome/Android production; ML-DSA experimental; no PQC algorithm in the approved-algorithm list of #5244 | 0 | |
liboqs Open Quantum Safe | 0.12.0 | active | not validated | not validated | All NIST PQC families (ML-KEM, ML-DSA, SLH-DSA, Falcon, FrodoKEM, HQC, Classic McEliece) | 0 | |
wolfCrypt FIPS wolfSSL | 5.2.1 | active | FIPS active | ESV active | ML-KEM, ML-DSA available in the library; not yet inside the FIPS 140-3 boundary (CMVP #4718 shows no PQC mechanisms) | 0 | |
Bouncy Castle FIPS (Java) Legion of the Bouncy Castle | 2.0.0 | active | FIPS active | ESV active | ML-KEM, ML-DSA available (non-FIPS path); #4943 lists LMS SigVer as its only approved PQC-family algorithm | 2 | |
Mbed TLS TrustedFirmware / Arm | 3.6.2 LTS | 2027-07-01 | not validated | not validated | Experimental ML-KEM; no FIPS path | 1 | |
RustCrypto suite Rust Crypto project | rsa-0.10, ed25519-dalek-2.x | active | not validated | not validated | ml-kem, ml-dsa crates (beta); SLH-DSA in progress | 0 | |
AWS-LC / aws-lc-rs Amazon Web Services | 1.38.x | active | FIPS active (PQC) | ESV active | ML-KEM (KeyGen, Encap/Decap) approved on #5298 and #5314; ML-DSA available in the library but not in their approved-algorithm list | 0 |
Illustrative values for teaching purposes. Verify live against the NIST CMVP validated-modules list and vendor pages.
Download a schema-valid CycloneDX 1.7 CBOM of the current view — a real machine-readable artifact for Dependency-Track, scanners, or auditors (PQC and classical algorithms both emit as cryptographic-asset components).
CBOM - Export
Save the CBOM slice to your Command Center under the Management Tools zone, or export as markdown / PDF / DOCX.
- /migrate — full product catalog
- /assess — crypto inventory step— Step 3 — current crypto in use
- /assess — data sensitivity step— Step 4 — criticality + sensitivity
- /library — CBOM specifications
Try it
Why does the tool prefer a CBOM you can regenerate over a hand-built one?
Next step
Next in Migration Planning: Crypto Vulnerability WatchCrypto Vulnerability Watch is the next Migration Planning tool in the Command Center.