{
  "$schema": "http://cyclonedx.org/schema/bom-1.7.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.7",
  "serialNumber": "urn:uuid:b9803cb2-a31f-5383-9c14-55a7419e0404",
  "version": 1,
  "metadata": {
    "timestamp": "2026-10-06T00:00:00Z",
    "component": {
      "type": "application",
      "bom-ref": "subject",
      "name": "Sovereign custody CBOM starter blueprint",
      "description": "Where cryptographic inventories and keys are held: region, custodian and key control."
    },
    "properties": [
      {
        "name": "netrascale:blueprint:status",
        "value": "draft v0.1 - starter template, not a compliance determination"
      },
      {
        "name": "netrascale:blueprint:licence",
        "value": "CC-BY-4.0"
      }
    ]
  },
  "components": [
    {
      "type": "cryptographic-asset",
      "bom-ref": "alg-rsa-2048",
      "name": "RSA-2048",
      "cryptoProperties": {
        "assetType": "algorithm",
        "algorithmProperties": {
          "primitive": "pke",
          "parameterSetIdentifier": "2048",
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "cryptoFunctions": [
            "encapsulate",
            "decapsulate"
          ],
          "classicalSecurityLevel": 112,
          "nistQuantumSecurityLevel": 0
        },
        "oid": "1.2.840.113549.1.1.1"
      },
      "properties": [
        {
          "name": "netrascale:blueprint:guidance",
          "value": "Quantum-vulnerable. Record every use; plan replacement with ML-KEM (FIPS 203) for key establishment."
        }
      ]
    },
    {
      "type": "cryptographic-asset",
      "bom-ref": "alg-ecdsa-p256",
      "name": "ECDSA-P256",
      "cryptoProperties": {
        "assetType": "algorithm",
        "algorithmProperties": {
          "primitive": "signature",
          "parameterSetIdentifier": "P-256",
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "cryptoFunctions": [
            "sign",
            "verify"
          ],
          "classicalSecurityLevel": 128,
          "nistQuantumSecurityLevel": 0
        },
        "oid": "1.2.840.10045.4.3.2"
      },
      "properties": [
        {
          "name": "netrascale:blueprint:guidance",
          "value": "Quantum-vulnerable. Plan replacement with ML-DSA (FIPS 204) or SLH-DSA (FIPS 205)."
        }
      ]
    },
    {
      "type": "cryptographic-asset",
      "bom-ref": "alg-aes-256-gcm",
      "name": "AES-256-GCM",
      "cryptoProperties": {
        "assetType": "algorithm",
        "algorithmProperties": {
          "primitive": "ae",
          "parameterSetIdentifier": "256",
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "cryptoFunctions": [
            "encrypt",
            "decrypt"
          ],
          "classicalSecurityLevel": 256,
          "nistQuantumSecurityLevel": 5
        },
        "oid": "2.16.840.1.101.3.4.1.46"
      },
      "properties": [
        {
          "name": "netrascale:blueprint:guidance",
          "value": "Symmetric: considered quantum-resistant at 256-bit. Keep; confirm key management."
        }
      ]
    },
    {
      "type": "cryptographic-asset",
      "bom-ref": "alg-ml-kem-768",
      "name": "ML-KEM-768",
      "cryptoProperties": {
        "assetType": "algorithm",
        "algorithmProperties": {
          "primitive": "kem",
          "parameterSetIdentifier": "768",
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "cryptoFunctions": [
            "encapsulate",
            "decapsulate"
          ],
          "classicalSecurityLevel": 192,
          "nistQuantumSecurityLevel": 3
        }
      },
      "properties": [
        {
          "name": "netrascale:blueprint:guidance",
          "value": "Target state: NIST FIPS 203 key encapsulation (often deployed in hybrid with X25519)."
        }
      ]
    },
    {
      "type": "cryptographic-asset",
      "bom-ref": "alg-ml-dsa-65",
      "name": "ML-DSA-65",
      "cryptoProperties": {
        "assetType": "algorithm",
        "algorithmProperties": {
          "primitive": "signature",
          "parameterSetIdentifier": "65",
          "executionEnvironment": "software-plain-ram",
          "implementationPlatform": "generic",
          "cryptoFunctions": [
            "sign",
            "verify"
          ],
          "classicalSecurityLevel": 192,
          "nistQuantumSecurityLevel": 3
        }
      },
      "properties": [
        {
          "name": "netrascale:blueprint:guidance",
          "value": "Target state: NIST FIPS 204 digital signatures."
        }
      ]
    },
    {
      "type": "cryptographic-asset",
      "bom-ref": "proto-tls13",
      "name": "TLS 1.3 (external endpoints)",
      "cryptoProperties": {
        "assetType": "protocol",
        "protocolProperties": {
          "type": "tls",
          "version": "1.3",
          "cipherSuites": [
            {
              "name": "TLS_AES_256_GCM_SHA384"
            }
          ]
        }
      },
      "properties": [
        {
          "name": "netrascale:blueprint:guidance",
          "value": "Record each endpoint; note whether hybrid post-quantum key exchange is offered."
        }
      ]
    }
  ]
}