Where quantum-vulnerable cryptography lives across the wire-payment lifecycle — and what to migrate first. A machine-readable inventory built with payments-domain context, not a generic scan.
Generic discovery tells you that you run RSA-2048. It can't tell you it's the signature on a pacs.009 liquidity transfer BIS Project Leap just stress-tested, or that the real harvest-now-decrypt-later exposure is the RSA key-wrap on a 10-year payment archive.
Each stage is linked in the CBOM's dependency graph to the crypto assets beneath it — so you can trace, for any point in the flow, exactly which quantum-vulnerable assets it relies on.
Every asset in the CBOM carries a DOCUMENTED / INFERRED confidence label with a note on exactly what is known vs assumed. Cyber Centre ITSM.40.001 (2031/2035) applies to Payments Canada and Interac by best-practice analogy and oversight expectations, not direct federal mandate.
| cbom/payment-estate-cbom.json | The CycloneDX 1.6 CBOM — 31 assets, 23 quantum-vulnerable (26 documented / 5 inferred). |
| data/crypto-inventory.yaml | Human-editable source of truth. |
| scripts/generate_cbom.py | YAML → CBOM generator (single-source-of-truth design). |
| docs/migration-priorities.md | What breaks / can be hybridised + Project Leap analysis. |
Reference model, not a real institution. Every key, certificate, and endpoint is illustrative. Third-party figures should be verified against the cited primary sources.