Migration Planning / Crypto BOM (CBOM) Builder

What this is for: Build a CBOM slice from an SBOM, library posture, or HSM inventory; feeds the Assets pipeline.

What a good answer looks like: A CBOM you can regenerate. A hand-built one is accurate for a week; a generated one is accurate for as long as you keep generating it.

Worked example: Switch to SBOM → CBOM and pick the payments-service sample: its five components, OpenSSL 1.1.1w and a non-FIPS Bouncy Castle among them, each get a FIPS, ESV, PQC and posture reading, and one click downloads a CycloneDX 1.7 CBOM.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Three linked views, SBOM to CBOM, library posture and hardware FIPS 140-3 inventory, produce a CBOM slice: the point is a bill of materials you can regenerate, not one built by hand.
GRC / Risk & Compliance
Map an SBOM into a CBOM, record library posture and the HSM inventory with CMVP references, then Download CycloneDX 1.7: it is the inventory evidence that feeds the assets pipeline and the audit checklist's 'CBOM generated' item.

Three linked views over the software and hardware inventory: map an SBOM into a crypto-focused slice, inspect your library posture, and track Level 3 status for every HSM your keys live in.

Illustrative data for teaching. Cert numbers, firmware revisions, and PQC support claims below are educational snapshots, not live records. Verify against the NIST CMVP database and the vendor's product page before quoting.

LibraryLatestEoLFIPS 140-3ESV (SP 800-90B)PQCHigh CVEs (1y)Posture
OpenSSL
OpenSSL Project
3.5.0 LTS2030-04-08FIPS active
#4985 (OpenSSL FIPS Provider; FIPS 140-3 L1, 11 Mar 2025)sampleNIST record
not validatedML-KEM, ML-DSA, SLH-DSA in OpenSSL 3.5; none is in the approved-algorithm list of #49851
OpenSSL
OpenSSL Project
1.1.1w2023-09-11historical
#3622 (Canonical Ubuntu 18.04 OpenSSL module; FIPS 140-2, historical)sample
not validatedNone3
BoringSSL / BoringCrypto
Google
20250310activeFIPS active
#5244 (BoringCrypto; FIPS 140-3 L1, 18 Apr 2026)sampleNIST record
ESV activeHybrid X25519MLKEM768 in Chrome/Android production; ML-DSA experimental; no PQC algorithm in the approved-algorithm list of #52440
liboqs
Open Quantum Safe
0.12.0activenot validatednot validatedAll NIST PQC families (ML-KEM, ML-DSA, SLH-DSA, Falcon, FrodoKEM, HQC, Classic McEliece)0
wolfCrypt FIPS
wolfSSL
5.2.1activeFIPS active
#4718 (wolfCrypt; FIPS 140-3 L1)sampleNIST record
ESV activeML-KEM, ML-DSA available in the library; not yet inside the FIPS 140-3 boundary (CMVP #4718 shows no PQC mechanisms)0
Bouncy Castle FIPS (Java)
Legion of the Bouncy Castle
2.0.0activeFIPS active
#4943 (BC-FJA v2.1.1; FIPS 140-3 L1)sampleNIST record
ESV activeML-KEM, ML-DSA available (non-FIPS path); #4943 lists LMS SigVer as its only approved PQC-family algorithm2
Mbed TLS
TrustedFirmware / Arm
3.6.2 LTS2027-07-01not validatednot validatedExperimental ML-KEM; no FIPS path1
RustCrypto suite
Rust Crypto project
rsa-0.10, ed25519-dalek-2.xactivenot validatednot validatedml-kem, ml-dsa crates (beta); SLH-DSA in progress0
AWS-LC / aws-lc-rs
Amazon Web Services
1.38.xactiveFIPS active (PQC)
#5298 / #5314 (AWS-LC 3, dynamic / static; FIPS 140-3 L1, June 2026)sampleNIST record
ESV activeML-KEM (KeyGen, Encap/Decap) approved on #5298 and #5314; ML-DSA available in the library but not in their approved-algorithm list0

Illustrative values for teaching purposes. Verify live against the NIST CMVP validated-modules list and vendor pages.

Download a schema-valid CycloneDX 1.7 CBOM of the current view — a real machine-readable artifact for Dependency-Track, scanners, or auditors (PQC and classical algorithms both emit as cryptographic-asset components).

CBOM - Export

Save the CBOM slice to your Command Center under the Management Tools zone, or export as markdown / PDF / DOCX.

Try it

Why does the tool prefer a CBOM you can regenerate over a hand-built one?

Next step

Next in Migration Planning: Crypto Vulnerability Watch

Crypto Vulnerability Watch is the next Migration Planning tool in the Command Center.