Cryptography inventory
CBOM
A structured record of every algorithm, key, certificate, protocol, library and vendor dependency in an organisation. It is the mandatory first step of a post-quantum migration, because you cannot replace what you cannot enumerate.
In practice
Often produced as a cryptographic bill of materials alongside a conventional SBOM.
Related terms
The ability to change cryptographic algorithms, parameters or libraries without redesigning the systems that depend on them. Agility is what turns the next migration from a rewrite into a configuration change.
The practice of recording encrypted traffic today in order to decrypt it once a quantum computer becomes available. It is the one quantum risk already in progress, and it makes long-life confidential data the first migration priority.
NIST's report on transitioning to post-quantum standards, which proposes deprecating RSA-2048 and ECDSA-P256 by 2030 and disallowing them by 2035. It is the clearest published deadline for retiring classical public-key cryptography.
The NSA's post-quantum algorithm suite and transition timeline for US national-security systems, built around ML-KEM and ML-DSA. Its dates are widely used as a pacing signal even by organisations it does not bind.