“You cannot protect what you cannot see.”
That simple principle becomes difficult when the thing you need to see is hidden inside a pile of applications, APIs, cloud workloads, certificates, hardware, libraries and third-party products.
Cryptography is everywhere in modern enterprises, but it is rarely managed as one connected asset. A company may know which apps it runs – without knowing exactly which algorithms, certificates, keys, protocols or cryptographic libraries those applications depend on. That is where a Cryptographic Bill of Materials (CBOM) becomes valuable. NIST describes a cryptographic inventory as a record of cryptography used across systems, applications, services, devices and data flows.
For Indian companies preparing for post-quantum cryptography (PQC), however, creating a CBOM is only the beginning. The real difficulty is in keeping it complete, accurate and useful. This guide talks about some of the key CBOM challenges organisations need to address.
1. Finding cryptography across the entire IT environment
The first challenge is discovery. Cryptographic assets may exist in several parts of your systems:
- Application source code
- APIs and microservices
- Cloud environments
- Databases and servers
- Network devices
- HSMs and key-management systems
- Certificates and PKI infrastructure
- Third-party software and libraries
- Legacy and embedded systems
A simple scan is not as detailed to provide the complete picture. NIST’s migration work specifically focuses on discovering where and how cryptography is being used across hardware, software and services because companies can otherwise lack visibility into their cryptographic dependencies.
2. Legacy systems create major blind spots
Modern applications are relatively easier to scan than older systems. Indian enterprises often operate a mix of modern cloud applications, on-premise infrastructure, proprietary software and long-running business systems. Some may use cryptography that is undocumented or embedded deep inside applications and appliances.
Recent industry analysis also highlights legacy systems and custom implementations as areas where automated CBOM discovery can miss assets. This creates a very risky situation: an incomplete CBOM can look complete. If an organisation misses a critical dependency, its PQC migration plan may also miss the system that depends on it.
3. Keeping CBOM data accurate and current
A CBOM is not a document that can be created once and placed in a folder. Applications and libraries change, certificates expire, algorithms can be replaced, cloud infrastructure might be added or removed and sometimes, new vendors enter the environment.
CERT-In’s Technical Guidelines on SBOM, QBOM, CBOM, AIBOM and HBOM Version 2.0 call for firms to maintain an accurate and up-to-date CBOM for relevant systems. The guidelines also recommend recognised formats like SPDX or CycloneDX. This makes continuous monitoring and automated updates important.
4. Understanding what each cryptographic asset actually does
Simply knowing that an application uses RSA or ECC is not enough. Security teams also need context:
- Where is the algorithm being used?
- What data does it protect?
- Which application depends on it?
- What is the key size?
- Which protocol or certificate is involved?
- Who owns the asset?
- How critical is the system?
- What would happen if it had to be replaced?
This is one reason a CBOM should support, not replace, a broader cryptographic inventory. A CBOM provides a standardised machine-readable representation, while the wider cryptographic inventory adds business context needed for migration planning.
5. Third-party and supply-chain dependencies are hard to map
Your organisation may not control the cryptography inside every product it uses. A banking application, SaaS platform, payment system, IoT device or enterprise software package may rely on cryptographic libraries and components supplied by another organisation.
That creates an important question: What happens when your vendor cannot tell you which cryptography its product uses?
CERT-In’s CBOM guidance places emphasis on supplier transparency, including requirements around CBOM information for software, systems and devices involving cryptographic technologies. For Indian companies, supplier questionnaires and requirements should thus become part of the CBOM process.
6. Making CBOM useful beyond compliance
The biggest of the CBOM challenges may be turning inventory data into action. A CBOM should help security and technology teams answer practical questions:
- Which systems use quantum-vulnerable cryptography?
- Which certificates or algorithms need attention?
- Which applications are affected by a newly discovered crypto vulnerability?
- Which vendors need clarification?
- What should be migrated first?
- Can the organisation prove its current cryptographic posture?
How can Indian enterprises overcome these CBOM challenges?
A practical approach is to avoid trying to inventory everything at once. Start with critical applications and expand gradually:
- Discover cryptographic assets across code, infrastructure, certificates and dependencies.
- Consolidate findings into a standard CBOM format.
- Validate automated findings against application and infrastructure owners.
- Add context such as business criticality, ownership and data sensitivity.
- Monitor continuously as systems and cryptographic components change.
- Prioritise quantum-vulnerable and high-impact assets.
- Build a phased PQC migration roadmap.
This approach aligns with the direction of current NIST migration work and India’s growing focus on cryptographic transparency.
Conclusion
The hardest part of CBOM is creating a complete, accurate and continuously useful view of cryptography across a changing technology environment. For Indian firms, that visibility can support stronger cryptographic governance, faster response to crypto-related vulnerabilities and a more structured path toward PQC readiness.
If your organisation is struggling with CBOM challenges, CyberNX offers reliable CBOM solutions that can help you discover cryptographic assets across code, networks, identify quantum-vulnerable algorithms, support continuous monitoring and build application-level migration roadmaps. Check out our CBOM solutions and start building a clearer path from cryptographic discovery to PQC readiness.
CBOM challenges FAQs
What is a CBOM?
A Cryptographic Bill of Materials is a structured inventory of cryptographic assets and their relationships. It can include algorithms, certificates, keys, protocols, libraries and other cryptographic dependencies.
What are the main CBOM challenges?
The main challenges include discovering hidden cryptography, covering legacy systems, maintaining accurate data, understanding business context, managing third-party dependencies and turning inventory findings into a practical PQC migration plan.
Is CBOM the same as a cryptographic inventory?
Not exactly. A CBOM is a standardised, machine-readable representation of cryptographic assets. A broader cryptographic inventory can include additional business context such as ownership, criticality and migration priorities.
Why does CBOM matter for post-quantum readiness?
Organisations need to know where quantum-vulnerable cryptography is being used before they can decide what to replace. A CBOM can provide visibility that supports risk assessment and migration planning.




