Back to DashboardStrategyPhase 2 · CBOMintermediate30 min

CycloneDX Cryptography Registry

One canonical name per cryptographic mechanism — resolve the same algorithm or curve across HSM, certificate, protocol and library notations.

Why this matters: Every discovery tool names the same mechanism differently; the registry is the shared vocabulary that makes a CBOM — or any crypto inventory — queryable across tools.

Start here: Paste a messy identifier such as CKM_ECDSA_SHA256 into the Algorithm Name Normalizer: it resolves the HSM, JWT or scanner name to its one canonical family.

For your role

Executive / Business Leader
One canonical name per mechanism is what lets a CBOM from several scanners be read as one inventory; the two lookups show the problem and the fix in a minute.
GRC / Risk & Compliance
Resolve an HSM, JWT or scanner identifier to its canonical family with the Algorithm Name Normalizer: the same mechanism named three ways is the reconciliation problem in every crypto inventory audit.
Developer / Engineer
Use the Algorithm Name Normalizer and the Curve Identifier Lookup to map the identifiers your libraries and tokens emit to the CycloneDX registry names a CBOM expects.
Security Architect
The registry is the shared vocabulary between discovery tools, HSMs, certificates and libraries; the lookups show where PQC families sit in it.
IT Ops / DevOps
Resolve the names your scanners and HSM logs emit to the registry's canonical entries so the same key does not appear as three assets.
Practice in the Simulation

Why a registry, not just a spec

◆ practitionerThe same cryptographic mechanism gets a different name from every angle you look at it — CKM_ECDSA_SHA256 to an HSM, OID 1.2.840.10045.4.3.2 to a certificate, ES256 to a JWT, code point 0x0403 to TLS 1.3. A CBOM (or any inventory) built from several discovery tools inherits all of these inconsistent names — and nothing lines up until you normalize them.

● standardCycloneDX v1.7 answers this with the Cryptography Registry: one versioned, machine-readable list of canonical algorithm-family and elliptic-curve names, each backed by its standardization reference (RFC, FIPS, IEEE, ISO).

What's inside: families and curves

● standard96 algorithm families across 14 primitive types — signatures, key encapsulation, key agreement, block and stream ciphers, authenticated encryption, MACs, hashes, XOFs, KDFs, key-wrap and DRBGs — each with standardization references and naming-pattern templates for its parameterized variants (e.g. key length, hash choice).

● standard246 elliptic curves across 15 standardization categories (NIST, SECG, Brainpool, ANSSI, BLS, GOST, X9.62/X9.63 and more) — each entry carries its OID, algebraic form (Weierstrass, Edwards, Montgomery), and cross-referenced aliases, so P-256, secp256r1 and prime256v1 are recorded as the same curve.

PQC is a first-class citizen, not a footnote

● standardML-KEM, ML-DSA, SLH-DSA, XMSS and LMS are registered algorithm families alongside RSA, ECDSA and AES — not a separate or bolted-on list. For a PQC-readiness review, that means one place to check whether a mechanism a scanner found is quantum-safe, quantum-vulnerable, or a stateful hash-based signature that needs its own state-management scrutiny.

◆ practitionerPQC makes normalization harder, not easier: ML-DSA registers one OID per parameter set (RFC 9881's id-ml-dsa-44/65/87), so a single family fans out into several distinct identifiers a tool must still resolve back to “ML-DSA”.

Broader than CBOM, broader than CycloneDX

● standardThe registry ships as its own versioned JSON + JSON Schema, decoupled from the CycloneDX specification release cycle — it can add a new algorithm family without waiting for the next CycloneDX version.

◆ practitionerIt is explicitly designed for use outside CBOM or CycloneDX entirely: an SPDX-based scanner, a homegrown inventory format, or a compliance dashboard can all adopt the same canonical names — CBOM is simply CycloneDX's own consumer of it.

Using it in practice

◆ practitionerEvery discovery source you already run — HSM query, certificate scan, source-code scanner, network capture — hands you a mechanism name in its own notation. The registry is the lookup table that resolves each one to a single canonical family or curve before it goes into your inventory, which is what makes a policy-as-code check (quantum-safe / quantum-vulnerable / unknown) match reliably across sources.

Check your understanding

17 questions on CycloneDX Cryptography Registry, each with its answer and the reason.

Take the quiz

Next step

Produce the artifact: Crypto BOM (CBOM) Builder

This module belongs to phase 2 (CBOM); Crypto BOM (CBOM) Builder produces a deliverable of that phase in the Command Center.

Learning module content can be inaccurate. Please double-check its information. Report inaccuracies in PQC Today GitHub Discussions.