Entrust adds CBOM support to cryptographic platform
Wed, 23rd Sep 2026 (Today)
Entrust has expanded its Cryptographic Security Platform with support for Cryptographic Bill of Materials data. The update adds CBOM import and export, composite algorithm support, and a choice of SaaS or on-premises deployment.
The move comes as organisations face tighter regulatory and security demands around cryptographic inventories, including requirements under DORA and NIS2 and guidance on post-quantum migration.
The changes are intended to help security teams move beyond static lists of cryptographic assets and towards managing risk and planning remediation across their estates. The updated platform is designed to show where cryptography sits in systems and applications, what depends on it, and which assets may be vulnerable or out of compliance.
That reflects a broader shift in cybersecurity. Financial institutions, healthcare groups, government agencies, and other critical infrastructure operators are dealing with larger volumes of certificates, shorter certificate lifecycles, and a rapid increase in machine and AI-related identities, while preparing for the eventual move to post-quantum cryptography.
Inventory pressure
Cryptographic inventories have become more pressing as regulators and standards bodies require firms to document assets, dependencies, and risk exposure. Security teams have often treated inventory work as a compliance exercise, but the challenge is growing because environments change constantly and spreadsheets quickly become outdated.
Entrust is aiming to address that by linking discovery and inventory tools with governance and automation functions. Its CBOM support lets organisations import and export cryptographic inventory data, correlate it with discovered assets and dependencies, and identify where remediation should be prioritised.
The platform also now includes Ansible-based functions for certificate lifecycle automation. These are intended to help teams manage certificate deployment and administration across customised public and private PKI environments with less reliance on manual processes.
Another part of the update is support for composite algorithms, which are relevant to phased post-quantum migration strategies. The platform also includes SPIRE-based functions aimed at establishing trusted identities for AI agents and other non-human workloads.
Customers can deploy the platform either as a service or on premises. The hosted option broadens access for organisations that want to adopt the new functions more quickly, while the on-premises model remains available for those with operational or data sovereignty requirements.
Michael Klieman, Global Vice President of Product Management at Entrust, said visibility alone is no longer enough for security teams.
"A CBOM is more than a static inventory," said Michael Klieman, Global Vice President of Product Management at Entrust. "Security teams need to connect CBOM data with the systems and applications that depend on cryptography, understand where risk is concentrated, and determine what actions to take next. The addition of CBOM support to the platform helps organizations move from documenting cryptographic assets to actively governing and securing them."
Broader trend
The announcement points to a wider concern in cybersecurity over crypto-agility: the ability to change cryptographic methods without major disruption as standards and threats evolve. That issue has become more urgent with the prospect that quantum computing could weaken or break some currently used cryptographic algorithms.
For many organisations, the first task is still to understand where cryptography is used across applications, infrastructure, certificates, keys, and secrets. The harder part is linking that visibility to action, especially when systems have deep and sometimes poorly documented dependencies.
Research firms have also highlighted the operational burden created by the growth of digital certificates and non-human identities. As the number of connected services, workloads, and automated processes rises, security teams face more pressure to track trust relationships and renew cryptographic material without causing outages.
Jennifer Glenn, Research Director for Information and Data Security at IDC, said inventory work must now feed directly into governance and migration planning.
"Knowing where cryptography lives isn't enough anymore. The number of certificates and other cryptographic material is growing rapidly. Machine and AI identities are multiplying, and the deadline to transition to post-quantum algorithms is closing in. Security teams cannot treat cryptographic inventory as a static exercise. Organisations that connect cryptographic inventory, governance, automation, and post-quantum readiness will be better positioned to manage crypto-agility as standards evolve," said Glenn.