{
  "slug": "cbom-secure",
  "name": "CBOM Secure",
  "vendor": "Encryption Consulting",
  "researched_at": "2026-09-26",
  "product_status": {
    "summary": "Active. CBOM Secure V1.1 was released in June 2026 and the release page was updated in August 2026. V1.1 added AWS discovery, CrowdStrike Falcon host sync, a Source Code Visualizer, a PQC chart, an AI/MCP module, Docker deployment and in-app docs. No rename, acquisition or discontinuation found. No major release after August 2026 found.",
    "url": "https://www.encryptionconsulting.com/cbom-secure-v1-1/"
  },
  "cells": {
    "C1": {
      "score": 10,
      "anchor": "10: >=7 surfaces documented with algorithm+parameter depth and PQC/hybrid detection",
      "urls": [
        "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
        "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
        "https://www.encryptionconsulting.com/cryptographic-posture-management/"
      ],
      "quote": "20+ production sensors inventory cryptographic assets across cloud platforms, hardware security modules, KMIP servers, TLS endpoints, directory services, databases, file systems, source code, and binaries.",
      "rationale": "8 surfaces are documented: TLS (a), certs/PKI/AD (b), source code in 7 languages (c), PE/ELF binaries (d), HSM/KMIP (e), AWS/Azure/GCP KMS (f), agent for OS trust stores/hosts (g), and database TDE plus keystores (h). Key size is captured, and the datasheet says 'hybrid TLS (X25519MLKEM768) detected in production'.",
      "delta_vs_published": 0.5
    },
    "C2": {
      "score": 7,
      "anchor": "between 6 (standard export, no integrity) and 8 (standard export + documented integrity mechanism)",
      "urls": [
        "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
        "https://www.encryptionconsulting.com/cryptographic-posture-management/",
        "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf"
      ],
      "quote": "Audit artifacts generated in CycloneDX 1.6 and 1.7.",
      "rationale": "CycloneDX 1.6/1.7 export is documented. 'Cryptographically verifiable' integrity is claimed only for the audit trail, not the CBOM export, and no mechanism is named. No public sample or signature found.",
      "delta_vs_published": -1
    },
    "C3": {
      "score": 8,
      "anchor": "8: continuous or scheduled monitoring with documented change alerts AND tamper-evident history",
      "urls": [
        "https://www.encryptionconsulting.com/cryptographic-posture-management/",
        "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/",
        "https://www.encryptionconsulting.com/cbom-secure-v1-1/"
      ],
      "quote": "A tamper-proof audit trail records every asset change in a cryptographically verifiable log: what changed, when, and by whom.",
      "rationale": "Continuous monitoring that detects configuration changes, email/Teams alerting and a tamper-evident change log are documented. No detection latency is published (needed for 9), and the log's mechanism (hash chain or signature) is not named.",
      "delta_vs_published": -1
    },
    "C4": {
      "score": 7,
      "anchor": "between 6 (categorical levels from algorithm plus context) and 8 (numeric score including HNDL/data lifetime)",
      "urls": [
        "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
        "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
        "https://www.encryptionconsulting.com/cbom-inventory-to-intelligence/"
      ],
      "quote": "Four risk bands: Critical, High, Low, Safe. Scoring weighs algorithm strength, expiry, key reuse, cipher mode, IV/nonce handling, KDF parameters, quantum exposure.",
      "rationale": "A per-asset 0-100 score and bands are documented, but the listed factors have no data-lifetime or HNDL term. HNDL/TNFL 'enrichment' appears only on the vendor blog page cbom-inventory-to-intelligence, with no mechanism and no stated combination into the numeric score. No weights are published.",
      "delta_vs_published": -2
    },
    "C5": {
      "score": 4,
      "anchor": "4: accuracy or false-positive handling described, no metric",
      "urls": [
        "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/",
        "https://www.encryptionconsulting.com/cbom-secure-v1-1/",
        "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf"
      ],
      "quote": "Rather than treating every discovered asset as an equal risk, this level of precision ensures your team focuses remediation efforts on real-world exposure, eliminating false positives",
      "rationale": "False-positive reduction through dormant/conditional/active reachability is described. No precision, recall or benchmark is documented in the URLs searched or in a web search for CBOM Secure accuracy metrics. The V1.1 'Testing and Validation Evidence' section gives outcome claims only (70-80% audit time, >90% incident reduction).",
      "delta_vs_published": -2
    },
    "C6": {
      "score": 5,
      "anchor": "between 4 (guidance only) and 6 (one-way ticket/export plus guidance)",
      "urls": [
        "https://www.encryptionconsulting.com/cryptographic-discovery-inventory-functionalities/",
        "https://www.encryptionconsulting.com/cryptographic-posture-management/",
        "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf"
      ],
      "quote": "Integrate with SIEM, GRC, and ticketing platforms to streamline remediation workflows.",
      "rationale": "Ticketing integration is named once, with no named system (no Jira/ServiceNow) and no mechanism; the datasheet does not mention ticketing. Remediation guidance and CertSecure Manager integration are documented. No automated remediation or verified closure is documented.",
      "delta_vs_published": 0
    },
    "C7": {
      "score": 8,
      "anchor": "8: executive and technical reports with documented compliance mapping",
      "urls": [
        "https://www.encryptionconsulting.com/cryptographic-posture-management/",
        "https://www.encryptionconsulting.com/wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf",
        "https://www.encryptionconsulting.com/cryptographic-discovery-inventory/"
      ],
      "quote": "Reporting includes dashboards built from 29 widgets and 52 built-in KPIs, on-demand compliance evidence, alerting via email and Microsoft Teams, and full inventory export in CycloneDX.",
      "rationale": "A per-framework mapping table is published (SP 800-131A, FIPS 140-3, CNSA 2.0, CMMC, PCI DSS 4.0, NIST IR 8547, FedRAMP). The datasheet lists role-based dashboards and a REST API with OpenAPI for every widget/KPI. No sample report was found, so 10 is not met.",
      "delta_vs_published": -1
    }
  },
  "total": 7.37,
  "published_total": 8.21,
  "urls_that_failed": [
    "https://docs.encryptionconsulting.com/ (HTTP 525)",
    "https://www.encryptionconsulting.com/cbom-secure-datasheet/ (HTTP 404; the datasheet was found at /wp-content/downloads/EC_CBOM_Secure_Datasheet.pdf)",
    "https://www.encryptionconsulting.com/cbom-secure/ and /products/cbom-secure/ redirect to /cbom-secure-deployment-models/ (not a product page)"
  ],
  "notes": "Evidence is vendor product pages, vendor knowledge-base/blog articles on the vendor's own domain, and the datasheet PDF (created 2026-01-12, modified 2026-06-12). Press-wire copies (PRNewswire/StreetInsider) were not cited; the same statements appear on /cbom-secure-v1-1/. The brief's S06 source (/cbom-secure-deployment-models/) does not contain the CycloneDX 1.6/1.7 statement; that statement is on /cryptographic-discovery-inventory/. The brief's S04 figures ('seventy libraries, eight hundred patterns') are confirmed as '70+ libraries' and '880+ function patterns' on the vendor site. Inconsistencies across vendor pages: 29 widgets/52 KPIs vs 30+/50+; 'Eighteen production sensors' vs '20+'; four bands 'Critical, High, Low, Safe' (datasheet) vs 'Critical, High, Medium, Low, and Safe' (posture page); the datasheet body says CycloneDX 1.6 while its output section says 1.6 and 1.7. The per-asset HNDL scoring claim rests only on a vendor blog article with no mechanism. No public sample CBOM, report or accuracy data exists in the pages fetched. Pages were fetched with curl from the research host and quoted from the extracted text."
}
