The question at hand
Your cryptographic inventory tool just finished its scan, identifying 847 cryptographic implementations across your environment. You export the report, share it with your team, and start planning your post-quantum migration timeline.
But here's the uncomfortable question: what about the cryptographic assets the tool didn't find?
This isn't a theoretical problem. Organizations often discover that automated CBOM (Cryptographic Bill of Materials) tools miss entire categories of cryptographic implementations. The debate isn't whether automation belongs in your cryptographic asset management program. It's whether automation alone gives you the visibility you need to satisfy ISO/IEC 27001 Annex A control 8.24 (use of cryptography) or build a defensible risk treatment plan.
The case for automation-first
Automated CBOM tools solve a real problem: scale. You can't manually inventory every cryptographic implementation across a modern technology stack. The math doesn't work.
A single microservices architecture might use TLS for inter-service communication, encrypted databases, signed container images, and cryptographic key management services across hundreds of instances. Manual documentation falls behind within hours of deployment. Automation gives you continuous discovery instead of a point-in-time snapshot that's obsolete before you finish writing it.
Standardized CBOM formats also make consolidation possible. When your network scanning tool, application security platform, and infrastructure-as-code analyzer all export to the same format, you can merge inventories without custom integration work. That standardization matters when you're preparing for regulatory requirements like DORA, which explicitly pushes financial institutions toward structured cryptographic asset visibility.
The automation-first argument is simple: you need the scale automation provides before you can layer on anything else. Start with comprehensive automated discovery, then refine.
The case for expert-guided discovery
The counter-argument starts with a single observation: legacy systems, operational technology, and custom-built implementations often sit outside the reach of automated scanners.
Your automated tool scans modern cloud infrastructure beautifully. It identifies every TLS certificate, every encrypted S3 bucket, every key rotation policy in your AWS environment. But it doesn't see the proprietary encryption implementation your team built five years ago for a specific compliance requirement. It doesn't inventory the cryptographic functions embedded in the industrial control system running your manufacturing line. It doesn't catch the custom key derivation function in the legacy application you're still running because migration keeps getting pushed to next quarter.
These aren't edge cases. They're the cryptographic implementations that create the most risk in a post-quantum transition, because they're the ones you'll discover last.
The expert-guided camp argues that automation creates a false sense of coverage. You look at your CBOM report, see hundreds of discovered assets, and assume you've got comprehensive visibility. You build your migration roadmap based on that inventory. Then, mid-migration, you discover entire systems that weren't included. Your timeline doubles. Your budget request goes back to the CFO.
Risk management means knowing where your blind spots are. If you know your automated tools don't cover operational technology, you can plan manual discovery for those environments. If you know custom implementations require code review, you schedule it. But if you treat an incomplete inventory as complete, you're building your entire risk treatment plan on a foundation that doesn't hold.
Where practitioners actually land
Most compliance teams don't pick sides in this debate. They layer approaches.
You start with automated discovery because you need the scale. Your CBOM tool scans your cloud infrastructure, your network perimeter, your application layer. That gives you a baseline inventory and catches the obvious implementations.
Then you add expert review for the categories automation misses. Your security architects review custom code. Your operations team documents the cryptographic functions in legacy systems. Your vendor management process requires cryptographic disclosure from third-party suppliers.
The practical challenge isn't choosing between automation and expertise. It's maintaining the inventory over time. Your environment changes constantly. New services deploy. Applications update. Dependencies shift. A point-in-time inventory, whether automated or manual, goes stale.
Continuous discovery means your automated tools run on a schedule, not once during the initial assessment. It means your change management process includes cryptographic impact analysis. It means your Secure Development Lifecycle requires developers to document cryptographic dependencies before code ships.
This is where the "automation gives you scale, but you need expert insights into what makes sense to migrate" principle becomes operational. Your automated inventory tells you what you have. Your cryptographic expertise tells you what it means, what the migration priority should be, and where the risk concentrates.
Our take
Automation is necessary but not sufficient for cryptographic asset visibility.
You can't satisfy ISO/IEC 27001 control 8.24 with a manual spreadsheet, and you can't build a defensible post-quantum migration plan without automated discovery at scale. But you also can't rely solely on tools that miss legacy systems, custom implementations, and operational technology.
The right approach treats automated CBOM tools as your foundation, not your ceiling. Run automated discovery continuously. Export to standardized formats. Merge inventories across tools. But also document the categories your automation doesn't cover. Schedule manual review for those blind spots. Build your risk treatment plan around the gaps, not just the discovered assets.
If you're preparing for a SOC 2 Type II examination or an ISO/IEC 27001 surveillance audit, your assessor will ask how you maintain cryptographic inventory. "We run an automated CBOM tool quarterly" is a starting point, not a complete answer. The complete answer includes how you identify what the tool misses, how you validate the results, and how you keep the inventory current as your environment changes.
The biggest risk isn't the cryptographic assets you haven't migrated yet. It's the ones you don't know exist.



