Enterprise Resource Security Mastering Cryptographic Key Lifecycles
Top News

From Passive to Active Cryptographic Inventory – Three Years of Research for a New Generation of Cryptographic Management

September 14, 2026

New Research Project: From Passive to Active Cryptographic Inventory

New research project by MTG and CryptoNext Security: We're building the cryptographic inventory of tomorrow—evolving from a static asset list into an active tool for automation, risk management, and post-quantum migration.

As part of the EU roadmap for quantum-safe cryptography, Germany’s Federal Office for Information Security (BSI) recommends establishing a cryptographic inventory by the end of 2026. We’re taking it a step further: together with our partner CryptoNext Security, we’re launching a new three-year research project that turns a classic cryptographic inventory into an active cryptographic inventory—featuring automated risk detection, smart certificate management, and a solid foundation for post-quantum migration.

We’re excited to announce funding approval for this German-French collaborative project through Germany’s Central Innovation Programme for SMEs (ZIM) and France’s Bpifrance. At the heart of the project lies a key question for the future of IT security: How do you turn a static overview of your cryptographic landscape into an active tool for security, automation, and post-quantum migration?

Why Now? Cryptography Is Becoming a Blind Spot

As IT, OT, and IoT systems become increasingly interconnected, the number of cryptographic objects within organizations is growing fast. Certificates, keys, algorithms, and protocols are now embedded in countless applications, devices, and infrastructures—with increasingly complex dependencies between them. At the same time, regulatory requirements are piling up: the EU Cyber Resilience Act (CRA), NIS2, DORA, and the upcoming migration to post-quantum cryptography (PQC) are all pushing organizations to finally gain visibility into their cryptography.

This is exactly where a cryptographic inventory comes in: it reveals which certificates, keys, and cryptographic algorithms are in use—the foundation for any risk management or migration planning effort. Such an inventory is often documented in the form of a Cryptography Bill of Materials (CBOM)—a structured, machine-readable record of cryptographic assets that is increasingly becoming a standard format for transparency and traceability. However, a classic cryptographic inventory tends to remain passive: it documents the current state but doesn’t actively intervene in processes.

Our Goal: From Passive to Active Cryptographic Inventory

An active cryptographic inventory shouldn’t just know what exists—it should understand relationships and derive concrete actions from them. Changes to certificates, keys, or systems are no longer viewed in isolation, but in the context of the entire cryptographic infrastructure. Building on this, processes are automated: above all certificate management, but also risk analysis and post-quantum migration planning.

CryptoNext Security (CNS) and MTG are pooling their respective expertise for this effort. Over the next three years, we’ll research, develop, and validate this approach in a practical demonstrator—with the clear goal of building a European, sovereign, and post-quantum-resilient cryptographic infrastructure for complex industrial, OT, and IoT environments.

Set the Course for Your Post-Quantum Migration Now

Wondering how well-prepared your organization already is for post-quantum migration? We can help, drawing on our expertise in PKI, CLM, and crypto-agility—from your first cryptographic inventory to fully automated certificate management.

Get in touch and schedule a consultation

Frequently Asked Questions (FAQs)

What is a Cryptographic Inventory?

A cryptographic inventory is a structured overview of the cryptography deployed across an IT, OT, or IoT environment. It captures items such as certificates, keys, cryptographic algorithms, and protocols, and shows which systems and applications use them. A comprehensive cryptographic inventory lays the groundwork for crypto-agility and a well-planned post-quantum migration.

Why do organizations need a cryptographic inventory for post-quantum migration?

You can only migrate to post-quantum cryptography in a targeted way if you know which cryptographic methods and objects are in use across your infrastructure. A cryptographic inventory provides that transparency, helping you identify affected systems, assess risk, and prioritize migration efforts. Under the EU roadmap for quantum-safe cryptography, organizations are expected to establish a cryptographic inventory by the end of 2026.

What is an active cryptographic inventory, and how does it differ from a classic cryptographic inventory?

A classic cryptographic inventory primarily documents which cryptographic objects exist. An active cryptographic inventory goes further: it maps dependencies, analyzes risk, and provides the information needed for automated processes. In our joint research project, CryptoNext Security and MTG are exploring how such an active cryptographic inventory can support organizations with certificate management, risk analysis, and post-quantum migration going forward.

What is CBOM (Cryptography Bill of Materials)?

A CBOM is a structured, machine-readable inventory of all of an organization's cryptographic assets—comparable to a Software Bill of Materials (SBOM), but for cryptography. It documents algorithms, keys, and certificates, providing a standardized foundation on which a cryptographic inventory can be built.

WordPress Cookie Plugin by Real Cookie Banner