Learn More about Benny Czarny's Book Cybersecurity Upside Down

Learn More
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

Introducing OPSWAT CBOM and AIBOM

OPSWAT introduces Cryptographic Bill of Materials (CBOM) and AI Bill of Materials (AIBOM) alongside its existing Software Bill of Materials (SBOM) capabilities.
By Joseph Nguyen, Product Marketing Manager
Share this Post

On Oct 5, 2026, OPSWAT will roll out CBOM (Cryptographic Bill of Materials) and AIBOM (AI Bill of Materials) alongside its existing SBOM (Software Bill of Materials) capabilities. Both are generally available in MetaDefender Core™ V5.23 or later. The release extends software component analysis to include cryptographic assets, AI model provenance, and declared-license information.

CBOM: Identify Cryptography and Plan What Needs to Change

Post-quantum migration starts with a practical question: Which cryptography does our software rely on, and what needs replacing? CISOs, cryptography specialists, and migration teams need an inventory of cryptographic assets within their software to determine this.

OPSWAT CBOM helps teams:

  • Inventory cryptographic assets. Identify algorithms, cryptographic libraries, certificates, protocols, and related key material in supported files
  • Assess classical and quantum risk separately. Distinguish cryptographic weaknesses under current standards from exposure to quantum attacks, with unknown classifications where reference data is insufficient
  • Review replacement recommendations. Identify post-quantum alternatives where available, with recommendations tied to their purpose, such as ML-KEM for key establishment and ML-DSA for signatures
  • Configure cryptographic risk blocking. Optionally block files containing cryptographic assets classified as unsafe
Block a file whose cryptographic assets grade at or above the chosen risk
Identify and assess algorithms, libraries, certificates, protocols, or related key material against dual risk axes

CBOM complements SBOM’s investigation of software packages and vulnerabilities by providing the cryptographic details needed for post-quantum migration planning. Refer to official OPSWAT CBOM documentation or contact our Support team.

AIBOM: Review AI Model Provenance and Licensing

Before adopting a model, AI governance and Legal teams need to establish what the file is, which repositories are known to publish it, and what license information is available. OPSWAT AIBOM provides evidence for those reviews without requiring an external network lookup.

OPSWAT AIBOM helps teams:

  • Identify model artifacts. Recognize supported AI model files and read available metadata from their contents
  • Match publishing repositories offline. Use a local catalogue to identify known repositories that publish the exact same model bytes, without contacting external services
  • Surface declared-license information. Report available licenses declared by model registries to support governance and licensing reviews
  • Apply model-license restrictions. Optionally block files when a model’s resolved license matches a selected restriction, independently of software-package license rules
Choose licenses to block when they are detected on an AI model
Report the AI/ML models found in the scanned file; identify known repositories and licenses declared by the registry

Repository matching requires the latest engine package. Refer to official OPSWAT AIBOM documentation or contact our Support team.

One Workflow, the Right Report for Each Team

CBOM and AIBOM are enabled by default, while their blocking controls are opt-in. Teams can collect findings before deciding which restrictions to enforce.

CycloneDX and SPDX remain dedicated to SBOM export and enrichment workflows. For unified results containing SBOM, CBOM, and AIBOM, export the complete result as JSON or PDF, or export each inventory separately. Whether investigating a vulnerable package, scoping a cryptographic migration, or reviewing an AI model, teams can use one analysis workflow and share the findings relevant to each decision.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.