On Oct 5, 2026, OPSWAT will roll out CBOM (Cryptographic Bill of Materials) and AIBOM (AI Bill of Materials) alongside its existing SBOM (Software Bill of Materials) capabilities. Both are generally available in MetaDefender Core™ V5.23 or later. The release extends software component analysis to include cryptographic assets, AI model provenance, and declared-license information.
CBOM: Identify Cryptography and Plan What Needs to Change
Post-quantum migration starts with a practical question: Which cryptography does our software rely on, and what needs replacing? CISOs, cryptography specialists, and migration teams need an inventory of cryptographic assets within their software to determine this.
OPSWAT CBOM helps teams:
- Inventory cryptographic assets. Identify algorithms, cryptographic libraries, certificates, protocols, and related key material in supported files
- Assess classical and quantum risk separately. Distinguish cryptographic weaknesses under current standards from exposure to quantum attacks, with unknown classifications where reference data is insufficient
- Review replacement recommendations. Identify post-quantum alternatives where available, with recommendations tied to their purpose, such as ML-KEM for key establishment and ML-DSA for signatures
- Configure cryptographic risk blocking. Optionally block files containing cryptographic assets classified as unsafe


CBOM complements SBOM’s investigation of software packages and vulnerabilities by providing the cryptographic details needed for post-quantum migration planning. Refer to official OPSWAT CBOM documentation or contact our Support team.
AIBOM: Review AI Model Provenance and Licensing
Before adopting a model, AI governance and Legal teams need to establish what the file is, which repositories are known to publish it, and what license information is available. OPSWAT AIBOM provides evidence for those reviews without requiring an external network lookup.
OPSWAT AIBOM helps teams:
- Identify model artifacts. Recognize supported AI model files and read available metadata from their contents
- Match publishing repositories offline. Use a local catalogue to identify known repositories that publish the exact same model bytes, without contacting external services
- Surface declared-license information. Report available licenses declared by model registries to support governance and licensing reviews
- Apply model-license restrictions. Optionally block files when a model’s resolved license matches a selected restriction, independently of software-package license rules


Repository matching requires the latest engine package. Refer to official OPSWAT AIBOM documentation or contact our Support team.
One Workflow, the Right Report for Each Team
CBOM and AIBOM are enabled by default, while their blocking controls are opt-in. Teams can collect findings before deciding which restrictions to enforce.
CycloneDX and SPDX remain dedicated to SBOM export and enrichment workflows. For unified results containing SBOM, CBOM, and AIBOM, export the complete result as JSON or PDF, or export each inventory separately. Whether investigating a vulnerable package, scoping a cryptographic migration, or reviewing an AI model, teams can use one analysis workflow and share the findings relevant to each decision.

