Skip to main content
Automated CBOM Tools Miss What Matters MostCryptography & Encryption
5 min readFor Compliance Officers

Automated CBOM Tools Miss What Matters Most

Your cryptographic inventory looks complete. Your scanning tools ran green. Your dashboard shows 100% coverage across production environments. Then a routine audit uncovers three legacy authentication systems, a custom-built encryption module in your ERP platform, and operational technology running cryptographic protocols your scanners never touched.

This isn't a hypothetical gap. It's a pattern Matous Vambersky sees repeatedly as a post-quantum cryptography consultant working with organizations automating their cryptographic bill of materials (CBOM) programs.

The Challenge

Organizations often discover major gaps in cryptographic inventory once they automate discovery. The problem isn't that automation finds nothing; it's that teams mistake partial visibility for complete coverage. Legacy systems and custom-built implementations often sit outside the reach of automated scanners, creating blind spots that automation alone can't close.

The risk increases when you build migration roadmaps from incomplete inventories. Teams planning post-quantum cryptography transitions or cryptographic modernization projects underestimate the work ahead because their CBOM doesn't reflect reality. Some discover mid-migration that entire systems were left out, forcing schedule delays and budget revisions after the project is already underway.

Regulatory pressures from DORA and U.S. executive orders are pushing CBOM adoption across defense and public sector organizations, but the push toward automation creates its own compliance exposure. If your CBOM submission to an auditor or contracting officer omits critical systems, you've documented an incomplete security posture.

Systems That Evade Automated Tools

Three categories of systems consistently evade automated CBOM tools:

Legacy systems run outdated protocols or proprietary implementations that modern scanners don't recognize. These systems often handle critical functions but weren't built with standardized cryptographic libraries that automated tools can fingerprint.

Operational technology environments have network segmentation, air gaps, or specialized protocols that prevent standard scanning approaches. Your IT-focused CBOM tools weren't designed to inventory the cryptographic components in building management systems, industrial control networks, or embedded devices.

Custom-built implementations involve development teams writing their own encryption routines, wrapping commercial libraries in proprietary code, or integrating cryptography into applications without using discoverable patterns. These implementations don't announce themselves through standard APIs or library signatures.

The constraint isn't just technical. Vambersky points to a risk management gap: "The biggest risk is this false feeling of safety, this false feeling of visibility. You should always have a risk management approach. If you know where the blind spots are, you can prepare for it."

Organizations working under DFARS 252.204-7012 or preparing for Cybersecurity Maturity Model Certification assessments face an additional constraint. Your CBOM isn't just an internal inventory; it's evidence of your ability to identify and protect cryptographic assets handling Controlled Unclassified Information (CUI). An incomplete CBOM suggests you can't fully account for where CUI moves through encrypted channels or how your key management practices apply across all systems.

The Recommended Approach

Vambersky's recommended approach treats automation as a foundation, not a solution. Start with automated discovery to establish baseline coverage and scale, but layer expert analysis on top to identify what the tools missed.

Prioritize external-facing assets and data in transit for initial automation. These systems typically use standardized protocols and libraries that scanners recognize. You'll get quick wins and establish patterns for what complete coverage looks like in well-instrumented environments.

Then apply expert review to find gaps. This means interviewing application owners, reviewing architecture diagrams, examining custom code repositories, and walking data flows with the teams who built them. The goal isn't to replace automation; it's to understand where automation reaches its limits in your specific environment.

Vambersky emphasizes the continuous nature of the work: "The challenge isn't generating some inventory document. The challenge is the continuous discovery, the ability to maintain the cryptographic inventory up to date."

This requires process discipline beyond running periodic scans. When development teams deploy new applications, your CBOM update process needs to catch custom cryptographic implementations before they go to production. When you acquire another company or onboard a new operational technology environment, expert review should run in parallel with automated discovery.

Use a standardized format to merge cryptographic inventories from different sources. This becomes critical when you're combining automated scan results with manually documented legacy systems and custom implementations. Standardized formats make it easier to identify duplicates, spot coverage gaps, and maintain a single authoritative CBOM that auditors and contracting officers can review.

Results and Metrics

Organizations using this hybrid approach discover blind spots before auditors do. Vambersky notes that teams find entire systems left out of initial automated inventories, but the specific scale and impact vary by organization.

The value shows up in migration planning accuracy. When your CBOM reflects actual cryptographic asset deployment, including the systems automation missed, your post-quantum cryptography transition timelines and budgets align with the work required. You're not discovering surprise scope mid-project.

Lessons Learned

Vambersky's core lesson centers on expectations: "Automation gives you the scale, but then you need to put in your expert insights into what makes sense to migrate."

Organizations that started with automation-only approaches would prioritize expert review earlier, particularly for legacy and custom systems. Waiting until an audit or migration project reveals gaps means you've already made decisions based on incomplete information.

Teams would also invest more heavily in CBOM maintenance processes from the start. Treating CBOM as a point-in-time deliverable rather than a continuous inventory program creates the conditions for gaps to reappear even after you've found and documented them once.

Takeaways for Your Team

Don't confuse automated coverage with complete coverage. Your scanning tools will find the systems they're designed to find, but legacy implementations, operational technology, and custom code require different discovery approaches.

Document your blind spots explicitly. If you know automation doesn't reach certain environments, state that limitation in your CBOM program documentation. This shifts the conversation from false confidence to risk-informed decision making.

Layer expert analysis over automated discovery, especially before major initiatives like post-quantum cryptography migrations or CMMC assessments. The time to find missing systems is during planning, not during execution.

Build CBOM maintenance into your change management and deployment processes. New applications, acquired systems, and infrastructure changes all create opportunities for cryptographic assets to enter your environment without entering your inventory.

If you're preparing CBOM documentation for regulatory compliance, recognize that completeness matters more than speed. An incomplete automated inventory submitted quickly creates more compliance risk than a thorough hybrid inventory that takes longer to compile.

Your automated tools aren't wrong. They're just not enough.

You Might Also Like