PRODUCT GUIDE

quick start

Local software · limited supported scope

CryptoProof Quick Start: Create a questionnaire draft

CryptoProof helps a software vendor draft answers to a customer's cryptography questionnaire. It reads an Excel questionnaire and a CBOM (an inventory of cryptographic assets in a product). It fills only bounded answers supported by the supplied evidence and leaves other questions unresolved. Your team reviews every row before creating a final Evidence Pack.

This is an Early Access candidate, not a published general-availability product. Read the supported scope before using a customer workbook. The steps below use only the synthetic files in the local review bundle.

Before you start

Follow local installation to install the wheel in a dedicated Python environment. Open PowerShell in the extracted review bundle folder, which contains sample/, docs/, and wheel/. Activate that environment or use its python.exe as $py:

$py = 'C:\path\to\your\venv\Scripts\python.exe'
& $py -m cryptoproof --version

If you are running from the source repository instead, use release-sample/ in place of sample/, set $env:PYTHONPATH = 'src', and point $py at a Python 3.10+ installation with the dependencies specified in pyproject.toml.

1. Check the questionnaire

Preflight reads the original Excel file and reports which columns it will use. It does not change the file.

& $py -m cryptoproof preflight `
  --questionnaire sample/sample-questionnaire.xlsx `
  --output preflight.json

This first check reports MAPPING_REQUIRED: the nonempty Read me sheet must be reviewed before it is ignored. The bundle includes sample/sample-mapping.json, an acknowledgement made for this exact synthetic sheet content. Rerun:

& $py -m cryptoproof preflight `
  --questionnaire sample/sample-questionnaire.xlsx `
  --mapping sample/sample-mapping.json `
  --output mapped-preflight.json

The second check reports READY, 28 questions, and Read me under acknowledged_ignored_sheets. For a real workbook, inspect every sheet yourself. Use map for an unfamiliar question sheet or ignore --confirm-no-questions only after confirming a non-question sheet contains no questions. An acknowledgement stops working if that sheet's content changes.

2. Create a draft

& $py -m cryptoproof compile `
  --cbom sample/sample-product.cdx.json `
  --questionnaire sample/sample-questionnaire.xlsx `
  --mapping sample/sample-mapping.json `
  --output answered-sample.xlsx

The original sample XLSX is untouched. Open answered-sample.xlsx, a draft copy of the original template, and the sibling answered-sample-cryptoproof/ directory with the evidence, limitations, and review files. The synthetic example processes 28 questions and writes 11 draft answers. No submission ZIP is produced at this step.

StatusMeaningYour next action
VERIFIEDA narrow fact is supported by the supplied CBOMCheck its evidence and product scope
PARTIALSome evidence exists, but does not prove the full claimReview the stated limitation
UNKNOWNThere is not enough evidenceFind other evidence or leave unresolved
OWNER_INPUT_REQUIREDA company decision or policy answer is neededAsk an authorized person in your organization
OWNER_APPROVEDA previously approved company answer was reusedRecheck its wording, scope, and expiry

Even VERIFIED refers only to the supplied CBOM. CryptoProof does not certify compliance or prove that every cryptographic asset was discovered.

3. Review before any submission

Read answered-sample-cryptoproof/review-required.json and the evidence manifest. A vendor reviewer must decide what to approve or leave unresolved for every question. The self-service guide explains column mapping, approved company answers, per-row review, and the separate finalize command that produces the final ZIP. Do not send the draft workbook or draft ZIP to a customer.