Discovery Is Table Stakes for PQC. A CBOM Is Not Discovery.

PQC discovery is the entry requirement for any post-quantum cryptography (PQC) programme. An organisation that cannot show which cryptography it runs, where it runs and who owns it has no basis for prioritising, sequencing or reporting a migration. A Cryptographic Bill of Materials (CBOM) is often offered as proof that this work has been done. It is a different thing.
This article sets out the distinction, the governance consequences of confusing the two and three questions a programme sponsor can use to test the evidence. Terms are defined in the SITG-Consulting Lexicon.
PQC discovery and a CBOM are different things
A CBOM is a record of cryptographic assets. PQC discovery is the process that establishes which assets exist, where they run and who owns them. Producing the record without the process gives a well-formatted document and no reliable knowledge of the estate.
A programme without discovery has no standing to plan a post-quantum migration. It cannot prioritise, sequence, score risk or report to a board, because it does not know what it holds. That is why discovery is the entry requirement and not a differentiator.
Table stakes means the evidence has to stand up to challenge
Provenance is the test. A scanner result, a developer questionnaire, a vendor attestation and a manual spreadsheet produce the same CBOM field in the same format, with very different levels of assurance. Without recorded provenance, a CBOM cannot be audited. A regulator or board asking "how do you know?" receives a document and no answer.
SITG-Consulting has written separately on why cryptographic inventory matters for PQC readiness. The point here is narrower: an inventory is only as reliable as the method that produced it.
PQC discovery is recurring, and a CBOM is a snapshot
Code commits, container rebuilds, certificate renewals and cloud default changes move production away from the record from the moment it is generated. Discovery therefore needs a stated refresh cadence, a named owner and a defined scope. The cadence should follow the rate of change in each environment. Daily runs suit a continuous delivery pipeline, and they would be excessive for a mainframe estate.
Coverage gaps are where the exposure sits
Embedded libraries, hard-coded algorithms, undocumented machine identities, third-party modules and shadow services are absent from any CBOM built from declared inventories. A CBOM assembled from existing asset registers inherits the blind spots of those registers, so the migration risk sits in the assets that were never registered.
Dependencies determine migration order
Replacing a public-key algorithm is not a like-for-like swap. Trust chains, certificate hierarchies, protocol constraints, hardware limits and vendor roadmaps decide what can move and in what order. An asset list does not express those relationships. Discovery has to capture dependencies as well as instances, or the migration plan has no basis.
What thin discovery does to governance
If PQC discovery is skipped or thin, the programme's downstream outputs rest on unverified inputs. Risk scoring draws on an incomplete asset base, so the scores reflect what was found rather than what exists. Migration timelines assume a known scope, and any asset outside that scope invalidates the sequence the moment it surfaces. Cryptographic agility claims require proof that an organisation can rotate algorithms across its estate, which is not possible when parts of that estate have never been mapped. Board and regulator reporting carries the same weakness: the figures may be internally consistent, but they are drawn from partial evidence, so the assurance they convey is unfounded. Supplier assurance depends on the same discovery reaching third-party dependencies, and a programme that has not mapped its own cryptography cannot credibly assess a supplier's.
Each of these outputs can look correct on its own terms and still be wrong. Related SITG-Consulting analysis covers the cryptographic governance and control gap that PQC is exposing and why deploying PQC is not the same as proving it works.
Three questions for a programme sponsor
The first question is provenance: for each CBOM entry, what was the method of discovery and who verified it? If the method is undocumented or the verification was never performed, the entry is an assertion rather than evidence. The second is currency: when was each entry last confirmed, and what triggers a refresh? A CBOM with no refresh cadence is a historical document, not an operational record. The third is scope: which parts of the estate are out of scope, and who accepted that risk? Unscoped areas are not risk-free. They are areas where exposure has been acknowledged but not quantified.
If a programme sponsor cannot answer these three questions, PQC discovery has not been done. The organisation holds a CBOM and nothing beneath it.
Where to start
SITG-Consulting's PQC Discovery Sprint is a structured diagnostic of 20 to 30 days that establishes cryptographic visibility, quantifies quantum exposure and delivers a defensible PQC migration pathway.
For an independent view of an organisation's position, the PQC Readiness Assessment covers PQC strategy, cryptographic dependencies, third-party risk, external connections, governance structures and migration readiness.
The wider approach is set out in the cryptographic transformation and modernisation methodology.
The FAQ on quantum risk, PQC governance and cyber resilience collects related questions, and further analysis is on the SITG-Consulting blog.




Comments