Practical, accurate guides to PCI DSS 4.0.1 Requirement 12.3.3 — the mandate that you keep a documented, annually-reviewed inventory of the cipher suites and protocols you run. Read the guides, then run the free scan to see your own.
What 12.3.3 actually requires, what counts as a cryptographic inventory under PCI DSS, how to build one, and the findings QSAs flag most.
What a CycloneDX CBOM is and why a machine-readable, diffable bill of materials is the evidence artifact a QSA will actually accept.
Why early TLS is deprecated, how it shows up under 12.3.3, and how to find every endpoint and config still negotiating it.
Point CipherM at your code, configs, and live TLS and see your cryptographic inventory in minutes.
The full breakdown of the requirement and how CipherM turns it into a QSA-ready evidence pack.
Every date from the June 2026 executive order and OMB M-26-15 — who it binds, and the inventory artifacts that satisfy it.
September 21, 2026 is the last day 140-2 certs count for new systems — which modules go Historical and what to do first.
A fixed-scope, two-week Rapid Assessment: we scan, review by hand, and hand you a CycloneDX CBOM plus a QSA-ready 12.3.3 evidence pack.