Vista Platform / CBOM & compliance

Build a CBOM
you can stand behind.

Evaluate the cryptography in your inventory against clear controls. Resolve findings, verify new observations, and generate a scoped Cryptographic Bill of Materials with traceable evidence.

Defined scopeVisible findingsVerifiable artifact
From inventory to defensible evidence03 / VISTA
From inventory to defensible evidenceInventory, defined scope, and policy evaluation connect to a dated CycloneDX CBOM with provenance and a content hash. This illustrates the workflow; CBOM generation is on demand and does not guarantee compliance. INVENTORYSCOPEPOLICY CRYPTOGRAPHICCBOMCycloneDX 1.7ScopeDefined + versionedEvidenceSource + freshnessInventoryObserved componentsIntegrityCanonical content hashSHA-256
Dated record · explainable boundary · generated on demand

01 / Improve the inventory. Preserve the truth.

A cleaner CBOM starts
with a better cryptographic estate.

A CBOM documents what was observed. Vista helps your team improve that underlying inventory through evaluation and remediation, while keeping remaining issues and coverage gaps explicit.

  1. 01

    Define scope

    Choose the assets and cryptographic inventory included in the evidence boundary.

  2. 02

    Evaluate

    Apply relevant framework controls to the observed inventory.

  3. 03

    Remediate

    Assign failing findings, address configurations, and record decisions.

  4. 04

    Re-observe

    Collect updated evidence and review the resulting evaluation.

  5. 05

    Generate

    Create an on-demand, dated CBOM against the chosen Scope.

“Clean” means addressing issues and explaining exceptions and gaps. Exporting a CBOM does not fix findings or certify organizational compliance.

02 / Framework → control → measurement

Understand why
a control passes or fails.

Frameworks organize requirements into controls. Typed measurements test those controls against observed inventory, producing findings you can investigate down to the asset or cryptographic configuration.

Browse published controls in plain language, review preview scores, and activate relevant frameworks. Asset and certificate changes trigger incremental evaluation; scores reflect the severity of findings.

Illustrative control evaluation

FrameworkCryptographic best practices
ControlUse supported TLS versions
Measurement against inventoryObserved protocol meets the rule
PassFindingNot assessed
Missing assessment evidence is never a passing result.

03 / Apply the right policies

A shared evaluation engine.
Frameworks for your operating needs.

Included in Core

Start with the baseline.

Evaluate inventory using bundled frameworks for cryptographic best practices, PQC readiness, certificate hygiene and expiry, inventory hygiene, and lifecycle.

  • Inspect controls and their measurements
  • Review preview scores and activate frameworks
  • Investigate findings and assessment coverage
  • Follow changes through continuous evaluation

Enterprise

Apply organizational requirements.

Add the regulated content bundle with controls mapped to SOC 2, PCI-DSS, ISO/IEC 27001, NIST CSF, and IEC 62351-3. Author custom policies for internal requirements.

  • Use the same inventory and evaluation engine
  • Define custom controls and measurements
  • Apply governed threshold overrides
  • Include compliance attestation in CBOM artifacts

Framework results describe the implemented controls evaluated against available inventory evidence. They support compliance work; they do not establish full compliance with a standard or replace an independent audit. Enterprise regulated content must be enabled by the operator.

04 / A record with a boundary and a timestamp

More than a component list.

01

A defined, versioned Scope

Capture the Scope identity, version, and name so reviewers can understand the inventory boundary used at generation.

02

Canonical cryptographic inventory

Produce a frozen CycloneDX 1.7 artifact from the cryptographic components matching that Scope.

03

Generation & freshness

Record when the artifact was created and its input-data freshness metadata. Review detailed coverage in the underlying inventory.

04

Content integrity

Hash canonical CycloneDX bytes with SHA-256. Verify the artifact against its recorded hash.

05

Formats for different reviewers

Download canonical CycloneDX, or SPDX JSON and PDF projections created from that same source.

06

A connected evidence trail

Return to underlying inventory records for source evidence and context. The CBOM itself does not embed raw capture or device-response data.

05 / Enterprise evidence

Show what changed.
Explain what conformed.

Add HMAC signing for tamper-evidence, compliance-attestation layers for evaluation results, and comparison between artifacts to support migration and remediation reviews.

HMAC verification requires the shared secret or access to the verification endpoint. It is not a public-key signature. The hash and signature cover canonical CycloneDX bytes, not PDF or SPDX renderings.

Before

Establish a baseline.

Generate a scoped artifact with the inventory and evidence available at that time.

Between

Change the estate.

Resolve findings, record exceptions, and gather fresh observations.

After

Compare the evidence.

Generate another artifact and review differences with Enterprise comparison.

Edition guide

Know what your team gets.

CBOM and compliance capabilities by edition
CapabilityCoreEnterprise / MSP
Scoped CBOM generation & content hashesIncludedIncluded
CycloneDX, SPDX & PDF downloadsIncludedIncluded
Bundled Core frameworks & evaluationIncludedIncluded
Regulated framework content—Included; operator-enabled
Custom policies & threshold overrides—Included
HMAC signing & compliance attestation—Included
Artifact comparison—Included

Questions about evidence

Clear scope. Honest conclusions.

Go deeper: What makes CBOM evidence traceable · Product documentation.

What is a Cryptographic Bill of Materials (CBOM)?

A CBOM is a structured record of cryptographic components and their context within a defined scope. Vista generates scoped CycloneDX CBOM artifacts from inventory evidence, with provenance, freshness information, and a content hash.

How is a CBOM different from an SBOM?

An SBOM describes software components and dependencies. A CBOM focuses on cryptographic components, such as algorithms, certificates, and related properties. They answer complementary questions: software composition and cryptographic use.

What makes a CBOM clean and useful?

A useful CBOM has an explicit scope, consistent identities, traceable observations, and visible unresolved findings. Cleaning the inventory means correcting records and investigating findings, not removing inconvenient evidence or claiming that an export proves compliance.

Does a CBOM prove that we are compliant?

A CBOM is a record of cryptographic inventory at a point in time. Enterprise attestation adds the evaluated control results. Neither is a certification or a substitute for the wider technical, operational, and organizational evidence an audit may require.

Do we need to resolve every finding before generating a CBOM?

No. You can generate a baseline while issues remain. Use it to establish the current state, organize remediation, and generate later artifacts to document progress. A missing attestation layer must not be interpreted as a passing result.

Are CBOMs generated automatically on a schedule?

Generation is on demand through the UI or API. Continuous inventory evaluation and CBOM generation are separate operations; Vista does not currently schedule recurring CBOM artifacts.

Can our own policies apply to the inventory?

Enterprise users can author custom policies with controls and typed measurements against inventory. Governed threshold overrides are also Enterprise; override authoring is provisioned through the API rather than a tenant self-service screen.

Can recipients verify a downloaded PDF’s signature?

Integrity verification applies to the canonical CycloneDX artifact. PDF and SPDX files are convenient projections. Enterprise HMAC signatures require access to the shared secret or the verification endpoint.

Self-hosted. Free and source-available.

Turn your inventory into defensible evidence.

Start with Core’s framework evaluation and CBOM generation. Add Enterprise when you need custom policies, regulated content, attestation, and comparison.

Stay in the loop

Keep up with Vista.

Get release notes, product updates, and opportunities to share feedback. Joining the mailing list is optional—Core is available without a subscription.

Join the mailing list