In a significant advancement, Entrust has introduced new capabilities to its Cryptographic Security Platform (CSP), aimed at transforming Cryptographic Bill of Materials (CBOMs) data into actionable insights for organisations.
This development is particularly pertinent for sectors such as government agencies, financial institutions, healthcare, and critical infrastructure operators, which are contending with increasing cyber threats, shorter certificate lifecycles, increasing machine and AI identities, evolving compliance mandates, and preparing for a shift to post-quantum cryptography.
Evolving compliance requirements
A thorough understanding of cryptographic location and dependency is crucial as compliance requirements evolve. Recent U.S. Executive Order and EU regulations like DORA and NIS2, which demand CBOMs-based inventories, highlight the pressing need for organisations to grasp their cryptographic assets, dependencies, and risk exposures.
The platform allows organisations to pinpoint cryptographic assets that might be vulnerable
The enhanced CSP enables organisations to connect cryptographic discovery and inventory with governance, automation, and post-quantum migration planning, thereby allowing them to identify and address risks more effectively within complex systems. With newly added CBOM import/export functionalities, it aids in constructing comprehensive cryptographic inventories and turning this visibility into operational measures.
On-premises deployment options
The platform allows organisations to pinpoint cryptographic assets that might be vulnerable or non-compliant, understand their dependencies, evaluate linked risks, and prioritise remediation efforts. Additionally, these new features can be accessed via on-premises or as-a-service deployment, offering greater flexibility. “A CBOM is more than a static inventory,” stated Michael Klieman, Global Vice President of Product Management at Entrust.
“Security teams need to connect CBOM data with the systems and applications that depend on cryptography, understand where risk is concentrated and determine what actions to take next.” This development supports organisations in transitioning from merely documenting cryptographic assets to actively governing and securing them.
Reducing cryptographic risk
Establishing visibility into cryptographic assets and dependencies must translate into governance
Establishing visibility into cryptographic assets and dependencies must translate into governance, operational resilience, and future cryptographic adaptability.
The CSP connects cryptographic discovery with targeted actions, enhancing governance and mitigating cryptographic risks. Organisations can now develop exhaustive cryptographic inventories, correlate discovered assets and dependencies, and reinforce governance across various keys and certificates.
Scaling operations and preparing for the future
With new Ansible-based capabilities, organisations can automate certificate lifecycle management across diverse environments, accommodating growing certificate volumes in public and private PKI infrastructures. This helps reduce manual interventions and minimises service interruptions. Additionally, preparing for post-quantum cryptography necessitates understanding existing cryptographic usages and their dependencies. The platform's expanded support for composite algorithms supports phased post-quantum migration strategies, while SPIRE-based capabilities address trusted identities for AI agents and non-human workloads.
By unifying cryptographic inventory, governance, automation, and post-quantum readiness, Entrust enables organisations to take informed actions and build a solid operational foundation for sustained crypto-agility. "Knowing where cryptography lives isn't enough anymore," said Jennifer Glenn, Research Director for Information and Data Security, IDC. "The rising number of certificates and cryptographic material, coupled with the need to transition to post-quantum algorithms, means organisations should connect cryptographic inventory, governance, automation, and readiness to effectively manage crypto-agility as standards continue to evolve."
Entrust announces new capabilities for its Cryptographic Security Platform (CSP) that help organisations turn Cryptographic Bill of Materials (CBOMs) data into action.
Government agencies, financial institutions, healthcare organisations, and other critical infrastructure operators are navigating increased cyber threats, shorter certificate lifecycles, the rapid growth of machine and AI identities, evolving compliance requirements, and the transition to post-quantum cryptography.
Evolving compliance requirements
Managing these changes depends on a comprehensive view of where cryptography resides and how assets and systems depend on it. Growing focus on cryptographic inventory and post-quantum readiness from industry groups, standards bodies, and regulators around the world, including the recent U.S. Executive Order and the EU’s DORA and NIS2 regulations requiring CBOMs-based inventories, reinforces the need for organisations to understand their cryptographic assets, dependencies and risk exposure.
Organisations can now connect cryptographic discovery and inventory with governance, automation and post-quantum migration planning, helping them identify and address risks across complex environments. With new CBOM import and export capabilities, the Cryptographic Security Platform helps organisations build more complete cryptographic inventories, understand dependencies, and translate cryptographic visibility into operational action.
On-premises deployment options
For example, organisations can identify cryptographic assets that may be vulnerable or noncompliant, determine which systems and applications depend on them, assess the associated risk, and prioritise remediation efforts. Additionally, the platform can now be deployed as-a-service or on-premises, giving organisations a faster and more flexible way to access the new CBOM capabilities while retaining on-premises deployment options.
“A CBOM is more than a static inventory,” said Michael Klieman, Global Vice President of Product Management at Entrust. “Security teams need to connect CBOM data with the systems and applications that depend on cryptography, understand where risk is concentrated and determine what actions to take next. The addition of CBOM support to the platform helps organisations move from documenting cryptographic assets to actively governing and securing them.”
Reducing cryptographic risk
Once organisations establish visibility into cryptographic assets and dependencies, they must translate that insight into governance, operational resilience, and readiness for future cryptographic change. CSP helps connect discovery with action across each of these areas:
- Strengthen governance and reduce cryptographic risk: Organisations cannot manage cryptographic risk without understanding where cryptography exists and how assets, systems and applications depend on it. New CBOM import and export capabilities, combined with cryptographic discovery, compliance, and operational health capabilities, help organisations build more complete inventories, correlate inventory data with discovered assets and dependencies, and strengthen governance across keys, certificates, and secrets across the enterprise.
- Scale certificate operations across complex environments with new Ansible-based capabilities: As certificate volumes grow across public and private PKI environments, organisations need automation that can keep pace with increasingly complex infrastructure. New Ansible-based capabilities extend certificate lifecycle automation, enabling teams to automate certificate deployment and management across highly customised environments at scale, reduce manual effort, and help minimise service disruptions.
- Prepare for post-quantum and emerging identity requirements with expanded support for composite algorithms and SPIRE-based capabilities: Preparing for post-quantum cryptography starts with understanding where cryptography exists and which systems depend on it. Expanded support for composite algorithms helps organisations pursue phased post-quantum migration strategies while new SPIRE-based capabilities support trusted identities for AI agents and other non-human workloads. CSP is now available as a service or for on-premises deployment, giving organisations greater flexibility to meet operational, security, and data sovereignty requirements.
Data sovereignty requirements
By connecting cryptographic inventory, governance, automation, and post-quantum readiness in a unified platform, Entrust helps organisations turn cryptographic visibility into action and build the operational foundation for long-term crypto-agility.
"Knowing where cryptography lives isn't enough anymore. The number of certificates and other cryptographic material is growing rapidly. Machine and AI identities are multiplying, and the deadline to transition to post-quantum algorithms is closing in. Security teams cannot treat cryptographic inventory as a static exercise. Organisations that connect cryptographic inventory, governance, automation, and post-quantum readiness will be better positioned to manage crypto-agility as standards evolve," said Jennifer Glenn, Research Director for Information and Data Security, IDC.