CBOM.net

Post-quantum planner

Know what to migrate first.

Load a CBOM and get a phased migration plan mapped to NIST post-quantum standards. Everything runs in your browser — nothing is uploaded.

JSON · CycloneDX 1.6–1.7

Migration posture

1 asset to act on

Assessed locally
critical
0
high
1
medium
1
low
1

Priorities follow the harvest-now-decrypt-later threat: key establishment and signatures first, then symmetric key sizes and protocol configuration. Readiness labels are explanatory heuristics from asset names — verify against current NIST guidance before acting.

Phased plan

Your migration sequence

Phase 2 · Migrate public-key cryptography

1

Algorithms a cryptographically relevant quantum computer would break — plan the move to ML-KEM and ML-DSA.

  • RSA-2048Plan migrationalgorithm

    Plan digital-signature migrationML-DSA (FIPS 204)

Phase 3 · Strengthen and track

1

Larger key sizes, protocol configuration inventories, and missing detail to gather.

  • TLS 1.3Strengthenprotocol

    Inventory the algorithms negotiated inside itHybrid post-quantum key exchange where available

Ongoing · Monitor

1

Assets that already meet post-quantum expectations — re-check as standards evolve.

  • AES-256-GCMMonitoralgorithm

    No change requiredAES-256 is considered sufficient

No account · no upload · no retention