CBOM is an advanced verification and code testing service designed to identify, catalogue, and assess all cryptographic assets used within software source code and its dependencies, including algorithms, certificates, keys, protocols, libraries, and cryptographic implementations.
Using reachability analysis and dependency mapping, the CBOM provides visibility into both direct and hidden cryptographic risks across modern software supply chains
Governments and standards bodies worldwide are now transitioning towards post-quantum cryptography, with migration periods already underway and expected to continue between 2028 and 2035.
Many software applications, including software escrow deposits created today, still rely on cryptographic standards such as RSA and ECC that are expected to become vulnerable to future quantum attacks in time. Putting at risk many services and data.
This creates a long-term security and continuity challenge for businesses dependent on third-party software.
The CBOM provides visibility into those risks today, enabling organisation’s to better understand and plan future migration requirements.
The Escrow Company’s CBOM assessment produces three core deliverables:
Detailed Technical Results
Delivered in CycloneDX 1.6 format (JSON/XML) with full file paths, line references, and cryptographic call graph context.
Human-Readable Excel Report
Designed for technical and operational review teams.
Executive Summary Report
A high-level summary for both the Depositor and Beneficiary outlining:

Left: Cryptographic inventory. Right: Example Migration Roadmap
The CBOM service can be applied to:
We scope and analyze this based on the number of code repositories and number of unique applications and can be scaled as required.
The Escrow Company is a trusted 3rd party that specializes in source code verification and audits. We can quickly analyze software and technology builds to support an M&A due diligence process.
While a CBOM itself does not migrate applications to post-quantum cryptography, it provides the visibility and awareness needed to begin planning and prioritising the transition to a secure state.
For clients of third-party systems , performing this as part of a SaaS escrow arrangement adds an additional layer of assurance around the long-term supportability of critical software systems and partnership with a critical supplier.
For software vendors, it demonstrates proactive cryptographic governance and software supply chain transparency.
As organisations prepare for the transition towards post-quantum cryptography, visibility into cryptographic dependencies is becoming an increasingly important component of long-term software resilience and continuity planning.