Certificate lifecycle management automates issuing, renewing and revoking certificates. Cryptographic asset discovery and inventory covers keys, algorithms, libraries, signatures and suppliers as well. Why post-quantum migration needs the second, and how the two fit together.
A software bill of materials lists components. A cryptographic bill of materials lists the algorithms, keys, certificates and protocols a system depends on. Learn how the two relate, what CycloneDX supports, and why the PKI Consortium is defining CBOM profiles.
CADI stands for cryptographic asset discovery and inventory. Learn what it covers, how it relates to CBOM, crypto-agility and cryptographic posture management, and what to look for in a tool.
The PKI Consortium's PQC migration profile turns "can this interface become quantum-safe?" into fields a supplier can declare and an operator can plan with. What the profile asks for, and how an observed inventory fits beside it.
Six practical questions to connect supplier PQC roadmaps with the products, versions and configurations you use, and identify the evidence needed for migration planning.
Devices run for fifteen years, ship with fixed flash and RAM, and are updated by parties that are neither vendor nor operator. What the PKI Consortium's IoT CBOM work and TNO's survey say, and how to inventory such estates honestly.
Container images carry certificates, keys, trust stores and cryptographic libraries that a network scan never sees. How image-layer discovery works, what it finds, what it cannot prove, and when a registry is a useful first scope.
Complete inventories take years, stay incomplete and rarely lead to action. Start with a golden image, a container registry or one network segment, and let ownership follow the evidence.
TNO surveyed cryptographic asset discovery and inventory (CADI) tools for the Dutch government in 2025. A summary of its findings on maturity, cost, European origin, integration and OT, and what they mean for your first inventory.