In March 2025 TNO completed a market survey and fit-gap analysis of cryptographic asset discovery and inventory (CADI) tooling, commissioned by CIO Rijk, the Dutch National Cyber Security Centre (NCSC) and the Ministry of Economic Affairs. The NCSC published the report in September 2025. It is classified TLP
, so anyone can read it, and it is one of the few independent, public assessments of this product category.The report is available from TNO Publications and from the NCSC. What follows is our reading of it. Cryptoramic was not among the surveyed products.
What TNO set out to answer
The study combined a workshop with technical and policy stakeholders in government, desk research and structured interviews with tool providers. From that input it drafted two sets of requirements: a minimum viable CADI tool and an ideal one. The purpose was practical: help government organizations choose and deploy tooling ahead of post-quantum migration, and identify where the market falls short.
The findings that matter to a buyer
Tools differ widely, in technique and in maturity. Some approximate the ideal for IT environments; none reach it. A buyer should expect to evaluate, not to pick from a settled category.
Precision costs effort. The report frames CADI deployment as a trade-off: the deeper and more precise the inventory, the more effort it takes to collect and maintain. That is an argument for choosing scope deliberately rather than aiming for everything at once.
Full-stack solutions are generally expensive and not European-made. For public bodies and regulated organizations in Europe this is a sovereignty and procurement concern as much as a budget one.
CADI has to fit existing asset management. IT asset management is already complex; a cryptographic inventory that does not align with the CMDB, vulnerability management and security tooling already in place adds another silo. Providers acknowledge this and integration is an ongoing focus.
Operational technology is behind. Tooling for OT is less mature than for IT, there is little OT tooling to integrate with, and some providers are not interested in OT at all. The report nevertheless considers CADI highly relevant for OT, given its role in vital infrastructure.
Do not wait. The report’s closing recommendation is to start building knowledge of cryptographic assets now, with the tools an organization already runs, rather than wait for the ideal tool or for external best practices. It also recommends a controlled test environment with a known ground truth so that tools can be compared on evidence.
What we take from it
Three of TNO’s gaps are design decisions in Cryptoramic. It is developed in the Netherlands and runs on your own infrastructure, which answers the origin and sovereignty question directly. It is built to sit beside existing tooling rather than replace it: ownership and application context can be included in the assessment, and existing CycloneDX and SPDX bills of materials can be imported, and findings can be exported as CycloneDX CBOMs. And it is made to start small: a single self-contained application, a first scan on one golden image or segment, a representative first scan.
Two of TNO’s points are cautions we share. Precision does cost effort, which is why we argue for starting with one owned scope instead of an estate-wide inventory. And OT discovery is a different problem from IT discovery; we describe what we can and cannot observe there on the operational technology page, and we do not claim parity.
How to use the report in a selection
- Take TNO’s minimum viable and ideal requirements as the starting checklist, then add the questions your own security review will ask, such as where data resides and what the scanner needs on a host.
- Follow TNO’s advice on ground truth: pick one scope where you know what cryptography is present, a golden image is ideal, and measure what each tool finds and what it misses.
- Weigh precision against effort explicitly. Ask each vendor what the first useful result costs in time and access, not only what the complete inventory would cost.
- Ask where the product is made and where your data goes. TNO raised it for government; it applies to any regulated organization.
Read what CADI means for the terminology, or see what discovery covers in Cryptoramic.
Frequently asked questions
What is the TNO CADI report?
It is a public study of tools that find and inventory cryptography, commissioned for the Dutch government. Published by the NCSC in September 2025, it compares the market with what organizations need from these tools. Its report number is TNO 2025 P11921.
Did the TNO survey recommend a specific CADI tool?
No. It found that no tool met all the requirements of an ideal solution. It recommended comparing tools in a controlled test environment where you already know what they should find.
Was Cryptoramic part of the TNO survey?
No. Cryptoramic was not among the surveyed products. The findings are useful because they describe the gaps buyers should test for, several of which Cryptoramic was designed to close.