Entrust Enhances Cryptographic Security Platform with Actionable CBOM Capabilities
Entrust's updated Cryptographic Security Platform now operationalizes Cryptographic Bill of Materials (CBOM) data, enabling organizations to better manage machine identities, compliance, and the transition to post-quantum cryptography.

Entrust has significantly bolstered its Cryptographic Security Platform (CSP) by introducing new capabilities designed to transform Cryptographic Bill of Materials (CBOM) data into actionable security insights. This enhancement addresses the escalating challenges faced by organizations, including government agencies, financial institutions, and healthcare providers, who are grappling with a heightened threat landscape, rapidly shortening certificate lifecycles, the proliferation of machine and AI identities, evolving regulatory demands, and the critical shift towards post-quantum cryptography.
The growing emphasis on cryptographic inventory and readiness for quantum threats, driven by global industry groups, standards bodies, and regulators like the U.S. Executive Order and EU's DORA and NIS2 regulations, necessitates a comprehensive understanding of an organization's cryptographic assets and their dependencies. Entrust's CSP aims to provide this clarity, enabling organizations to connect cryptographic discovery and inventory with robust governance, automation, and strategic planning for post-quantum migration.
With the introduction of new CBOM import and export functionalities, the platform empowers organizations to construct more complete cryptographic inventories. This allows for a deeper understanding of interdependencies between cryptographic assets and the systems they protect. The ultimate goal is to translate this enhanced visibility into concrete operational actions, such as identifying vulnerable or noncompliant cryptographic assets, assessing associated risks, and prioritizing remediation efforts across complex IT environments.
"A CBOM is more than a static inventory," stated Michael Klieman, Global Vice President of Product Management at Entrust. "Security teams need to connect CBOM data with the systems and applications that depend on cryptography, understand where risk is concentrated and determine what actions to take next. The addition of CBOM support to the platform helps organizations move from documenting cryptographic assets to actively governing and securing them."
The platform's enhancements focus on strengthening governance and reducing cryptographic risk by correlating inventory data with discovered assets and dependencies. This unified approach helps organizations manage keys, certificates, and secrets more effectively across the enterprise. Furthermore, Entrust has expanded its certificate lifecycle automation with new Ansible-based capabilities, designed to manage growing certificate volumes in complex public and private PKI environments at scale, thereby reducing manual effort and minimizing service disruptions.
In preparation for post-quantum cryptography and emerging identity requirements, CSP now offers expanded support for composite algorithms, facilitating phased migration strategies. New SPIRE-based capabilities are also integrated to support trusted identities for AI agents and other non-human workloads. To accommodate diverse operational needs, the CSP is now available as a service or for on-premises deployment, offering greater flexibility and control over security and data sovereignty.
By integrating cryptographic inventory, governance, automation, and post-quantum readiness into a single, cohesive platform, Entrust aims to equip organizations with the tools necessary to achieve 'crypto-agility.' This means being able to adapt quickly and effectively as cryptographic standards evolve and new threats emerge, ensuring long-term resilience against future cyber risks.
Jennifer Glenn, Research Director for Information and Data Security at IDC, commented on the evolving landscape, noting, "Knowing where cryptography lives isn’t enough anymore. The number of certificates and other cryptographic material is growing rapidly. Machine and AI identities are multiplying, and the deadline to transition to post-quantum algorithms is closing in. Organizations that connect cryptographic inventory, governance, automation, and post-quantum readiness will be better positioned to manage crypto-agility as standards evolve."