FYI - NIST to release public guidance on “minimum elements” for a cryptographic bill of materials (CBoM) within 270 days per new Presidential Order: NSPM-12.
https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks<https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/?utm_source=wh_social_share_button>/ Bob From: [email protected] <[email protected]> on behalf of toscalix <[email protected]> Date: Monday, June 22, 2026 at 1:03 PM To: Stewart, Kate <[email protected]>; [email protected] <[email protected]> Cc: [email protected] <[email protected]>; [email protected] <[email protected]>; [email protected] <[email protected]> Subject: [EXT] [spdx-tech] Request for a slot in the tech-team meeting, from the Cryptography Team This Message Is From an Untrusted Sender You have not previously corresponded with this sender. Treat with caution. If you feel this is suspicious, please report it via "Report Suspicious Email" button in Outlook. Hello Kate and Alexios, At the Cryptography Team we are facing two challenges where we welcome SPDX Tech team input. We request a slot on any of the coming Tech Team meetings to describe them and collect your feedback. ## Parameters description There are two proposals on the table to describe cryptographic algorithm parameters (vs properties). Each one of the two apply a different solution to the same challenge due to applying two different approaches: * On one side, we have a proposal that established a general syntax for expressing parameters, applied to each one of the algorithms (.yaml files). * On the other, a proposal that describes a common syntax on a single file and applies to every algorithm. Both has merits and present challenges. Before taking a decision on which way to go, we would like to present them and collect your opinion about it. You can find a detailed description of both approaches here: https://urldefense.us/v2/url?u=https-3A__github.com_spdx_cryptographic-2Dalgorithm-2Dlist_issues_39&d=DwIFAw&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=yyf_tMRBY80wjAUP82gpfmv0fTJk5mALsolNn8pXnYc&m=dIpewX7umCURzeL9EVLRRM9LzjtRKdeOcIG8HomZw0p2UDm7Tf8zy-Uq1FL1HI4U&s=uMrFhs-g53A6Y2JMhRinUd4yx8wQyJOZsDftaT7K5go&e= ## Attendance to the meetings The Cryptography group moved from a period with low attendance during its inception, to one with an increasing participation and, again, as our work becomes more detailed and complex, a decreased on the participation. In addition, we are reaching a point where we are suffering from the lack of cryptographers attending on regular basis. When they have actively participated, the efficiency of our work has increased noticeably. Once we leave the parameters discussion and implementation behind, we will face the structuring of the Quantum Readiness properties description. We think that, given the impact of the topic, this is will be a great opportunity to revert the current situation. We will need help to make it happen. Best Regards -- Agustin Benito Bethencourt Toscalix Consulting https://urldefense.us/v2/url?u=http-3A__www.toscalix.com_about&d=DwIFAw&c=Al8V6E3U0yBSSEuVtdZbGtsvjPA49U3WmtZAsdW0D_Q&r=yyf_tMRBY80wjAUP82gpfmv0fTJk5mALsolNn8pXnYc&m=dIpewX7umCURzeL9EVLRRM9LzjtRKdeOcIG8HomZw0p2UDm7Tf8zy-Uq1FL1HI4U&s=l0WxWku15p-7rJbmZZ7fMpj2ugkudNE7Xp6ukIZzDqc&e= -=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#6190): https://lists.spdx.org/g/Spdx-tech/message/6190 Mute This Topic: https://lists.spdx.org/mt/119927391/21656 Group Owner: [email protected] Unsubscribe: https://lists.spdx.org/g/Spdx-tech/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
