Cryptoramic

Environments

Cryptography in IoT and OT estates, and what an inventory has to capture

For a device estate the question is not "which algorithm?" but "update, replace, gateway, or accept?" The inventory has to support that decision.

Per device model, four inputs lead to one of four actions Resource bounds, update mechanism and authority, key provisioning and field life versus support feed a decision per device model: update the firmware, replace the device, put a gateway in front, or accept the risk. What the inventory must record Resource boundsflash · RAM · max frame size Update mechanism and authoritywho can update, until when Key provisioningcan keys be replaced? Field life versus supportfifteen years in the field, five of support Per model,not per unit One of four actions Update the firmware Replace the device Put a gateway in front Accept the risk, on record A permanent no is not a temporary no. Hardware limits never change; a missing firmware feature might. Record which one you found.
  1. Existing evidence

    Start with images, configuration and saved traffic where direct access is constrained.

  2. Approved collection

    Choose remote scanning, run-once agents or offline collection with the system owner.

  3. Remaining gaps

    Record what could not be observed and ask the supplier for evidence.

Four inventory attributes lead to one of four actions per device model.

Four actions per device model

The PKI Consortium’s IoT use case frames the operator’s problem precisely. When cryptography standards change, for each device model in an estate the operator chooses between four actions: update the firmware, replace the device, put a gateway in front of it, or accept the risk. A cryptographic inventory for a device estate is useful only if it supports that choice.

That is a different decision from post-quantum migration in IT, and the work treats it as a separate profile branch for fleet remediation rather than a variant of the migration profile.

What makes devices different

The draft profile therefore proposes attributes such as resource bounds, update mechanism and authority, key provisioning and replaceability, the cryptography termination point (device, gateway or both) and integration constraints.

The Cryptoramic host inventory with columns for manufacturer, device type, constrained device and device age next to the asset count per host.
Hosts · Illustrative assessment data

What TNO found

TNO’s 2025 market survey of CADI tooling for the Dutch government found the category less mature for operational technology than for IT: little OT tooling to tie into, and some providers with no interest in OT. It nevertheless considered CADI highly relevant for OT because of its role in vital infrastructure, and recommended more cooperation among stakeholders and clearer regulation on cryptographic inventory.

An honest approach

Nobody observes a fleet of constrained devices the way a scanner observes a server estate, and a tool that claims to should be asked how. What can be done today:

  1. Inventory what you can reach without touching devices. Firmware images, gateway configurations, the certificates and keys provisioned through the platform, and the traffic devices produce at a mirror point. Each of these is a source a discovery tool can read.
  2. Record the device-level attributes from the people who know them. Resource bounds, update authority and field life come from the vendor and the operator, not from a scan. Treat them as context attached to the model.
  3. Decide per model, not per unit. Devices are a class. The inventory should group findings by model and firmware version so the four-way decision is made once per class and applied to the units.
  4. Ask suppliers for a device CBOM as the profile matures. Until then, ask the questions the draft profile lists; they are the questions you will need answered anyway.

Cryptoramic can read firmware and disk images, captured traffic and gateway configurations, and attaches supplier evidence to identified products and versions. It does not run on constrained devices and does not claim visibility it cannot get. See the operational technology page for what a scoped assessment in such an environment looks like.

Frequently asked questions

Why is cryptographic inventory harder for IoT and OT than for IT?

Many devices have limited memory and processing power, stay in service for years and are difficult to update. The manufacturer may know what it shipped without knowing how each device is configured today. An inventory needs to capture those differences.

What did TNO find about CADI tooling for OT?

The 2025 survey found discovery tools less mature for operational technology than for IT. It also found fewer existing OT tools to connect them to. TNO still considered cryptographic discovery important for OT because these systems support critical infrastructure.

What should a device inventory record beyond algorithms?

Record whether the device can be updated, who controls updates, how long support lasts and whether keys can be replaced. Also capture limits such as memory and processing power, and whether cryptography runs on the device or a gateway. These details help determine whether a migration is practical.

Back to perspectives

Start with the devices you can already observe.

Discuss an assessment

Product screenshot

Illustrative assessment data