Free tools Windows power users keep installed
One-click scans. No signup required.
A cryptographic inventory is a record of where and how cryptography is used across an organization—not just a list of approved algorithms. Because the evidence comes from applications, devices, services, certificates, and asset records that may differ in coverage and detail, building a useful inventory means discovering, connecting, and validating those records.
What is a cryptographic inventory?
NIST defines it as “a descriptive record of the cryptography used across an organization’s systems, applications, services, devices, and data flows.” NIST’s post-quantum cryptography migration FAQ describes a broad inventory, not merely an algorithm checklist.
That distinction matters. An algorithm inventory is narrower; a cryptographic-asset inventory can also encompass keys, certificates, protocols, libraries, hardware security modules (HSMs), and other components that provide or depend on cryptographic protection. The practical question is not only “Which algorithms are present?” but “Where are they used, what do they protect, and which systems rely on them?”
What records belong in it?
- Algorithms and implementations: the algorithm and relevant implementation details or parameters.
- Protocols and services: examples include TLS, SSH, VPNs, code signing, email encryption, and certificate-based authentication.
- Key metadata: key type, owner, associated algorithm, application, expiration, and lifecycle status. Record metadata—not secret key material.
- Certificates and chains: certificate records and their relationships to services or systems.
- Dependencies and protected data: the systems and components that use cryptography, plus the data it protects, especially sensitive or long-lived data.
Why is it a reconciliation problem?
Cryptographic use is distributed across software, hardware, and services. NIST frames discovery for post-quantum cryptography (PQC) migration as finding where and how quantum-vulnerable public-key algorithms are used across those environments. NIST’s migration guidance treats inventory tools as a way to understand where cryptography protects important data and digital systems.
Recommended Free Tools
#1 Best Overall
Those environments do not necessarily produce equivalent records. CISA notes that software asset management information can vary in fidelity because vendor reporting differs and standardization is lacking; its strategy also calls for automated discovery and inventory, including algorithm information and associated key lengths. CISA’s quantum-readiness roadmap supports the need to reconcile evidence from multiple sources. “Reconciliation problem” is a useful description of that task, not a formal label used by CISA.
A scanner result, a certificate store, a vendor’s software record, and a service owner’s configuration may each show only part of the picture. A usable inventory connects those pieces, distinguishes observed facts from inferences, and makes gaps and conflicts visible. No single feed should be assumed complete.
How do you inventory cryptography across an organization?
The precise collection methods depend on the environment; the following workflow is a practical way to organize discovery and validation rather than a universal mandated standard.
- Set the scope. Identify in-scope systems, applications, services, devices, and data flows. Decide what counts as a cryptographic dependency, including components that rely on another service for protection.
- Collect from multiple discovery surfaces. Bring together software and source or dependency information, service and protocol configurations, certificate records, and evidence from hardware or service owners. Discovery should span software, hardware, and services.
- Capture usable context. Link each cryptographic asset to the system or component that uses it. Record relevant parameters, ownership, and lifecycle information where available. Do not collect secret key material.
- Normalize and reconcile the records. Align names and identifiers, connect assets to dependent components, and retain the source and confidence for each finding. Investigate missing or conflicting entries instead of silently choosing one version.
- Use the result to prioritize analysis. Identify systems that need closer review or transition planning. An inventory informs PQC readiness; it does not itself complete a migration.
What makes a record actionable? CBOM and relationships
A cryptographic bill of materials (CBOM) is a structured way to document cryptographic assets and their relationships to software components. CycloneDX describes CBOM as a means to improve visibility into assets such as algorithms, keys, and certificates, and to help identify deprecated or weak cryptography and dependencies that may need upgrades. CycloneDX’s CBOM overview explains the approach.
Structure helps preserve the detail behind a finding. For an algorithm, CycloneDX’s algorithm use case illustrates fields such as asset type, primitive, parameter-set identifier, mode, execution environment, implementation platform, certification level, supported cryptographic functions, security-level fields, and object identifier (OID). These examples do not mean every field is mandatory in every deployment.
For example, “RSA present” or “AES present” may be too vague to assess. Relevant parameters, use, environment, and the component relying on the algorithm can determine what the finding means and what further work is needed. The goal is not to fill every possible field indiscriminately; it is to retain enough context to trace a finding and make a decision.
Rank #4
How should you assess an inventory approach?
Compare approaches by the quality and usefulness of the evidence they produce, not just by whether they generate a list.
- Coverage: Which software, hardware, services, protocols, and data flows can it observe?
- Record detail: Can it retain relevant algorithm parameters, functions, modes, environment details, certificates, and key lifecycle metadata?
- Relationships: Can it connect a cryptographic asset to the application, service, or dependent component that uses it?
- Fidelity and provenance: Can users tell what was directly observed, what was inferred, which source reported it, and where reporting may be incomplete?
- Maintainability: Can findings be refreshed and gaps routed to responsible owners as systems and cryptographic assets change?
A scanner or workbook can be a useful starting aid, but neither by itself proves that an inventory is complete. NIST says the PQC Coalition’s inventory workbook can help establish a centralized inventory at the system or asset level; it is a starting point, not a validated complete solution or a requirement that every organization use the same workbook. NIST’s FAQ discusses the workbook.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




