Working Groups

Members

The PKI Consortium brings together leading organizations committed to trustworthy digital identities and secure communication.

Browse all members →

Working GroupsCBOM

CBOM Profiles Working Group Charter

This Working Group Charter has been created according to the "Working Groups" section of the Bylaws of the PKI Consortium ("PKIC"). In the event of a conflict between this Charter and any provision in either the Bylaws or the IPR Policy, the provision in the Bylaws or IPR Policy shall take precedence.

Summary of the Working Group

Summary
Name CBOM Profiles
Abbreviation CBOM
Chair(s) Michael Osborne (IBM)
Vice Chair William (Bill) Turner (Independent)
Communication Private mailing list, Virtual meetings, Community discussions, GitHub
Meeting schedule Virtual meetings: approximately 1 per month
Membership eligibility All Member types of the PKIC that express the interest in this Working Group
Voting structure According to the PKIC Bylaws
Expiration This Working Group is chartered indefinitely until it is dissolved
Members

A

Automate certificate lifecycle management with AppViewX for efficiency, security, and compliance!

AppViewX develops products for machine identity management, PKI, and cryptographic automation.

Passionate for what’s next

As a full-service business advisory and accounting firm. Aprio’s associates work as integrated teams across advisory, audit, tax, managed, and private client se…

B

A world-leading centre of excellence in applied post-quantum cryptography. Specialist partner to boards and regulated businesses on the post-quantum transition…

We Manage and Verify Cyber Trust Across Cyberspace PTI

C

We built applications and PKI related solutions for our clients. Some of them are developed completely by us and we also integrate third-party solutions of our…

CNA provides a broad range of standard and specialized insurance products and services for businesses and professionals in the U.S., Canada and Europe.

Helping people on their path to better health.

Helping organizations achieve ubiquitous trust online

CertiPath focuses on the use of digital identity in the modern connected world

Cisco is a worldwide technology leader. Our purpose is to power an inclusive future for all through software, networking, security, computing, and more solution…

As a global media and tech company, Comcast reaches hundreds of millions of customers, viewers, and guests with world-class connectivity and platforms and belov…

CryptiQ helps discover, assess and migrate vulnerable encryption across your company systems to quantum-safe NIST standards.

Easy to use, easy to deploy, easy to sustain cybersecurity foundations - today and tomorrow.

Crypto4A Technologies Inc. develops and delivers quantum-safe hardware security modules designed to meet the highest standards of cryptographic security. Its fl…

Software vendor, spin-off of French institutes of research (INRIA, CNRS, Sorbonne University), founded in 2019, CryptoNext Security provides solutions to manage…

Empowering Secure Cryptographic Solutions

Cryptomathic's robust cryptographic solutions protect sensitive information from unauthorized access. Trusted by global organizations across all industries.

Cyber Quanta is a member of the PKI Consortium participating in the CBOM Profiles Working Group.

KRYPTOS is the perfect solution for anyone who wants to securely store data in the cloud, network or any local disk. You can always share your encrypted data wi…

CyberTrust consulting is a boutique cybersecurity company that specialises in PKI, PQC consulting and Identity Security.

Ensure comprehensive protection with Cystel’s IT & OT Security Solutions. Safeguard assets and meet compliance standards in the evolving cyber landscape.

D

Data-Warehouse provides a german native cryptographic inventorisation and management plattform with outstanding discovery capabilities PCert(TM) since more than…

Specialist in Public Key Infrastructure (PKI), Digital Signatures, and Trustworthy Systems (TWS)

Digitorus is a software development and consultancy company specialized in Public Key Infrastructure (PKI), Digital Signatures, and Trustworthy Systems (TWS) th…

E

Cryptography services in BeNeLux mostly focused on the PKI ecosystem.

Securing a world in motion

Entrust is dedicated to securing identities, data, and transactions around the globe

eMudhra, a Digital Trust Service Provider (TSP), specializes in delivering comprehensive digital security solutions and services. This role is pivotal in ensuri…

F

Prepare for the quantum era with F5. Secure apps, APIs, and data with post-quantum cryptography across hybrid multicloud environments.

FEDLIN builds the controls a compliance platform only monitors — and runs them: SOC 2, NIST 800-53 Rev 5, and post-quantum key exchange.

Facti is a Brazilian nonprofit foundation dedicated to research, development, innovation, and capacity building in information and communication technologies. I…

Fidelity International offers investment solutions and retirement expertise to institutions, individuals and their advisers around the world. We bring together…

G

Lead change with digital confidence and advanced technology

We are GSE, transforming companies into the digital era with secure, reliable certification services.

Secure. Build. Grow.

GolaCyber is a startup vendor providing PKI and PQC technology and services in the Australian market. Our mission is to help Australian Organisations become Qua…

I

THINK

For more than a century, IBM has been a global technology innovator, leading advances in AI, automation and hybrid cloud solutions that help businesses grow.

part of HID Global

IdenTrust, part of HID Global, is a leading provider of digital certificates that establish the basis for trusted identity solutions recognized by financial ins…

Developer of applied cryptography solutions with 100+ years of man experience

i4p is a Hungarian company, who is first to offer secure multi-party cryptography (MPC) in the certified HSM. Their products are Common Criteria EAL4+ certified…

K

Your trustworthy partner in building a secure digital world

KIR is a key entity of the Polish payment system infrastructure. Based on state-of-the-art technologies, we build solutions for digital processes in business an…

Science for Impact

With passion, curiosity, creativity, and freedom, while firmly rooted in social responsibility, we contribute to the shaping of a sustainable and resilient futu…

Keystone Intelligence - Turning Knowledge into Sustainable Global Impact.

A shared, verifiable model of reality — identity, ownership, authority and history — for people, organisations and AI. The Reality Infrastructure for the human–…

M

Methics provides software products for mobile signature solutions to operators and application providers. Methics offers carrier grade products to answer the ne…

Explore Microsoft products and services for your home or business. Shop Surface, Microsoft 365, Xbox, Windows, Azure, and more. Find downloads and get support.

N

Namirial is a global leader in Qualified Trust Services and Digital Transaction Management (DTM). Its solutions enable businesses, citizens, and public administ…

Simplify your finances with our services including bank accounts, mortgages, credit cards, savings, and loans. Access your accounts with 24/7 online banking.

Quantum-ready cryptographic risk intelligence — CBOM, PQC readiness scoring, and verifiable certification.

NetraScale builds cryptographic risk intelligence platforms for regulated sectors. We serve financial market infrastructure, critical infrastructure operators,…

Nextwave (Thailand) is Thailand's Leading Cyber Security and Digital Transformation Software distributor in Thailand, with 20 years of experiences in the field…

Driving OPEN SOURCE Innovation for the FUTURE

NgKore is an open-source community driving innovation across Quantum Safe Network, Post-Quantum Cryptography (PQC), eBPF, 5G Advanced, 6G, O-RAN, NTN, AI/ML, Bl…

O

Securing What Matters From Silicon to AI

OmniTrust secures the connected world from silicon to AI through unified Trust Lifecycle Management across devices, identities, and cryptography.

P

Expertise in developing structured assessment methodologies for organisations in financial services, telecommunications, data centres, and critical national inf…

We enable cyber transformation. Our best-of-breed platforms, world-class threat intelligence and expert services deliver what’s next in cybersecurity.

Security Beyond Sight

Delivering enterprise-grade smartcard personalization and printing services to government agencies and financial institutions requiring the highest security sta…

Q

Rewriting Reality With Quantum Tech

QClairvoyance is a deep-tech startup working on developing next-generation applications that leverage Post-Moore computing architectures, specifically in the fo…

Quantum-Secure, Qrypt makes everlasting encryption accessible to all by reimagining how data is encrypted, transmitted, and stored.

QSE pioneers quantum-resilient encryption solutions to protect data for businesses, governments, and individuals ensuring a secure digital future

S

SAP develops Enterprise software and b2b applications.

SITG Consulting delivers board‑ready insights on quantum risk, resilience, and survival mandates. Read The Quantum Time Bomb and more. Transformation, Integrity…

SafeLogic provides validated & interoperable cryptography software that satisfies FIPS 140, CMMC v2.0, FedRAMP, and PQC requirements. Request consultation.

SeguriData is a Mexican technology company specializing in Public Key Infrastructure (PKI), digital signatures, digital identity, and data protection

Cryptographic Authentication & Identity

Sixscape is dedicated to making Cryptographic Authentication and Secure Messaging Simple, to enable secure digital transformation, IoT deployment and allow 5G t…

T

Securing The World's Migration To Post-Quantum Encryption

We're working with leading PQC experts to provide software for PQC migrations.

Join Australia's largest mobile network, view our plans for NBN broadband internet, mobile phones, 5G & on-demand streaming services.

Building a future we can all trust

Thales is a global technology leader with more than 77,000 employees on five continents. The Group is investing in digital and “deep tech” innovations - Big Dat…

Explore enterprise machine identity automation with Thryam. Replacing operational burden with complete automation.

Engineered for institutional scale. Tridecal orchestrates high-concurrency frameworks, Post-Quantum Cryptography to deliver resilient, sovereign ecosystems for…

Custom development and code-level compliance auditing from a working engineer and standards author.

Tyche Institute is a non-profit research association in Tallinn, Estonia, working on AI governance, evidence, auditability, and open research.

V

VIAVI Solutions offers security performance test solutions prior to deployment. SASE, PQC.

W

Wells Fargo is a financial institution that operates its own private PKI and relies on many public PKI, with a strong interest in industry standards (e.g. ASC X…

|

Introduction

A Cryptographic Bill of Materials (CBOM) describes the cryptographic assets present within a system, product, or organization. As CBOM adoption grows, a recurring problem emerges: there is no shared, neutral guidance on how to define a profile — a constrained, use-case-specific specification of what a CBOM should contain, how its fields should be interpreted, and what validation rules apply.

Today, profile definition happens implicitly inside individual standards efforts. This couples the act of defining a profile to the ontology, governance, and release cadence of whichever standard hosts it. The result is inconsistency across industries, duplicated effort, and profile design decisions becoming entangled in the politics of standards bodies.

The goal of this Working Group is to develop a clear, neutral approach to defining CBOM profiles — independent of any single base standard. The approach is deliberately designed so that a profile defined using PKIC guidance maps simply onto industry BOM standards such as SPDX and CycloneDX, rather than competing with them. The PKIC output is intended to become the reference any industry consults when it wants to create a profile for a particular use case.

The CBOM profile methodology must be easy to adopt. It must be clear and understandable across different cryptographic environments, use cases, and industries, and it must be open and freely available to anyone.

Scope

The scope of this Working Group is to:

  • Define and maintain a methodology for specifying CBOM profiles, independent of any single base BOM standard
  • Define and maintain mapping guidance that ensures profiles can be expressed simply in industry BOM standards, with SPDX and CycloneDX as the initial mapping targets
  • Develop one or two reference profiles as worked examples that demonstrate the methodology
  • Define relevant PKI-focused CBOM profiles, as a domain in which the PKIC holds direct subject matter expertise
  • Explore cooperation with relevant open-source and standards initiatives — including the Linux Foundation (PQCA, SPDX) and the OWASP Foundation (CycloneDX) — so that the profile methodology can be supported by practical tooling
  • Collect feedback from participants and interested parties regarding the methodology, mapping guidance, and reference profiles
  • Collaborate on reviews and revisions of the methodology and reference profiles

Out of scope is:

  • Developing or maintaining a base BOM standard or cryptographic ontology — the Working Group builds on existing standards rather than replacing them
  • Defining profiles for every possible industry use case — the Working Group provides the method and examples; industries author their own profiles using it
  • Certifying or validating third-party profiles

Objectives and goals

The objective is to provide a documented, neutral methodology for defining CBOM profiles, together with mapping guidance to industry BOM standards and a small set of reference profiles that demonstrate the method in practice.

The methodology should achieve the following:

  • Allow any industry or organization to define a CBOM profile for its use case in a consistent, repeatable way
  • Keep profile definition simple by separating it from complex base-standard ontologies
  • Ensure that a profile, once defined, maps cleanly onto SPDX, CycloneDX, and potentially other BOM standards
  • Promote consistency in profile design across industries, reducing duplicated and divergent effort
  • Provide a neutral venue for profile methodology, insulating design decisions from the governance politics of any single standards body
  • Establish reference PKI profiles that reflect the PKIC's core domain expertise
  • Enable the methodology to be supported by tooling through cooperation with external initiatives, rather than requiring the Working Group to develop and maintain tooling itself

Summary of the planned activities

To achieve the objectives and goals, the Working Group will gather feedback from its Members, participants, and interested parties on the structure of the profile methodology, leading to a robust and recognized approach.

Activities carried out by the Members of this Working Group include:

  • Regular meetings and discussions on the development of the profile methodology and related changes
  • Collecting information and feedback from interested parties regarding the methodology, mapping guidance, and reference profiles
  • Contributing to the definition of the profile methodology, including its structure, required elements, and validation conventions
  • Developing mapping guidance to SPDX, CycloneDX, and other relevant BOM standards
  • Authoring one or two reference profiles, including PKI-focused profiles, as worked examples
  • Liaising with relevant standards bodies and open-source initiatives — including the Linux Foundation (PQCA, SPDX) and the OWASP Foundation (CycloneDX) — to keep mapping guidance current and to enable tooling support for the methodology
  • Creating awareness about the CBOM profile methodology, its adoption, and how to use it
  • Preparing and publishing the deliverables of this Working Group

Change in activities described in this Working Group Charter must follow the "Decision process" described in this document.

Summary of the deliverables

Based on the objectives, goals, and planned activities of this Working Group, the initial deliverables are:

  • A documented methodology for defining CBOM profiles
  • Documented mapping guidance describing how profiles defined with the methodology are expressed in SPDX, CycloneDX, and other relevant BOM standards
  • One or two documented reference profiles demonstrating the methodology, including at least one PKI-focused profile
  • Documented guidelines on how to use the methodology to author a new profile
  • Blog posts and articles to create better awareness about the methodology, its adoption, and how to use it

Where the Working Group identifies tooling needs, it will seek to address them through cooperation with relevant external initiatives, rather than maintaining tooling directly. Any tooling produced through such cooperation will be published under the same licensing terms as the other deliverables.

All deliverables are licensed under the Creative Commons Attribution 4.0 International (CC BY 4.0) or MIT license and hosted within a public repository under the PKIC GitHub organization.

The change in deliverables described in this Working Group Charter must follow the "Decision process" described in this document.

Means of communication

A private mailing list is used for communication between Working Group Members.

Interested parties can contribute using the community discussions on GitHub, and Working Group Members will actively participate in those discussions.

Planning and action items are managed as issues within the same repository where the deliverables are published.

Membership and participation

Organizations that are eligible to join this Working Group follow the membership process as described in the Bylaws of the PKIC, section "Membership".

In accordance with the IPR policy, Members that choose to participate in this Working Group must declare their participation prior to participating by contacting the Chair of this Working Group.

The Chair of this Working Group must establish a list for declarations of participation and manage it in accordance with the PKIC Bylaws and the IPR policy and agreement.

Non-members can participate using the community discussions.

Decision process

The decision process follows Bylaws of the PKIC, with reference to sections "Voting" and "Working Group".

All decisions in this Working Group shall be made by substantial consensus (as determined by the Working Group Chair) of all PKIC Members including interested parties. If substantial consensus cannot be reached (or upon the request of any three PKIC Members), the matter will be submitted for decision by the Executive Council.

IPR policy

This Working Group is subject to the Intellectual Property Rights Agreement, Code of Conduct and Bylaws of the PKIC, including the Antitrust Policy.

Antitrust policy

In accordance with the PKIC antitrust policy, as stated by the PKIC Bylaws, an antitrust statement should be applied and read at the start of all Working Group meetings, in substantially the form written in PKIC Bylaws, chapter "Antitrust Policy".

Other applicable policies

Any relevant PKIC policies defined by the Bylaws must be followed if not specifically excluded by this Working Group Charter.