SCANOSS and IBM: raising the bar on cryptographic intelligence

Raising the bar on cryptography

Want to know what cryptography is actually running in your code?

TL;DR

SCANOSS and IBM are collaborating to close the gap between detecting cryptography in source code and confirming how it is actually implemented. Most tools stop at detection. This partnership combines SCANOSS’s scale with IBM’s cryptographic depth to give organisations a cryptographic inventory they can act on, not just file.

Why are SCANOSS and IBM collaborating on cryptographic intelligence?

In December 2025, SCANOSS and IBM announced a strategic collaboration to strengthen cryptographic detection and post-quantum readiness across the software supply chain. The premise is straightforward: SCANOSS’s scanning capability finds cryptography across large codebases quickly; IBM’s cryptographic expertise raises confidence in what that scan finds. Detection at scale and depth of analysis are usually a trade-off. This collaboration exists specifically to close that gap.

That matters because regulation is no longer asking for a report. The Cyber Resilience Act requires manufacturers to demonstrate control over the security properties they ship, including cryptography. DORA extends similar obligations to financial entities. NIST’s post-quantum standards, formalised through FIPS 203, 204, and 205, set the technical baseline migration planning now has to answer to. Every one of these frameworks asks the same underlying question: what cryptography is in this system, and is it still fit for purpose. An organisation cannot answer that question convincingly on detection alone.

What does SCANOSS and IBM’s collaboration actually improve?

Most cryptographic detection today works by scanning source code for keywords and patterns tied to known algorithms. This is fast, and it scales to large codebases where manual review is impossible. It is also, on its own, a ceiling. A keyword match confirms an algorithm is referenced. It does not confirm how that algorithm is configured, whether the implementation is sound, whether it sits in a deprecated library, or whether the usage pattern introduces a weakness the reference alone would not reveal.

This is precisely where SCANOSS and IBM’s combined approach is designed to add value. SCANOSS’s detection identifies where cryptography exists across an estate. IBM’s enterprise-grade cryptographic expertise is aimed at verifying how it is implemented once found, turning a list of locations into an inventory with confidence attached to each entry. The distinction is between finding cryptography and understanding it, and it is the second question that regulators, auditors, and security teams increasingly need answered before they can act on a Cryptography Bill of Materials rather than simply produce one.

Why does this matter now?

The urgency isn’t abstract, and SCANOSS and IBM aren’t the only ones treating it as immediate. NXP Semiconductors is already building post-quantum cryptography into its products, prioritising automotive, industrial IoT, and identity applications. Thales’s 2025 Data Threat Report: Critical Infrastructure Edition found that 63% of critical infrastructure professionals are anxious about post-quantum risk, specifically the threat of data captured today being decrypted once quantum capability catches up and over half of respondents are already prototyping or evaluating post-quantum cryptography algorithms in response.

Neither example is a cryptographic inventory story on its own. What they share with the SCANOSS and IBM collaboration is the same premise: post-quantum readiness has moved from compliance talking point to active design and procurement decision. An organisation that cannot answer what cryptography its own software depends on is not positioned to have that conversation.

What should security and compliance teams do next?

A cryptographic inventory is only as useful as the confidence behind each entry. Before choosing a migration path or remediation priority, teams need to know not just what produced their CBOM, but whether each finding was a keyword match or a verified result. Full coverage with shallow confidence is not more useful than partial coverage that has actually been checked, and the gap between the two is exactly what SCANOSS and IBM’s collaboration is built to close.

SCANOSS’s source-level detection, strengthened through the collaboration with IBM, gives teams both the breadth to find cryptography across a full codebase and a route to verified confidence in what they find.

Talk to SCANOSS about turning your cryptographic inventory into something regulators and auditors can actually rely on. 

Book a conversation →