Overview
Integrations and Discovery
Integrations and Discovery
Inventory and PQC Readiness
Certificate Lifecycle Management
Guardium Cryptography Manager-Marketing Demo
IBM Guardium Cryptography Manager is an AI-driven cryptography management platform that provides centralized visibility and governance for cryptographic assets across AWS, hybrid, and multi-cloud environments. The solution discovers and inventories cryptographic keys, certificates, secrets, and algorithms across multiple AWS accounts and Regions, through native integrations. By consolidating cryptographic assets into a single inventory, Guardium Cryptography Manager helps teams identify expired or expiring certificates, non-rotating keys, weak or deprecated algorithms, and unmanaged or shadow cryptography that can increase security, compliance, and availability risk. Policy-driven workflows help simplify key and certificate lifecycle operations and guide remediation. The solution supports AWS Organizations to help reduce operational overhead, improve audit readiness, and support crypto-agility as encryption standards evolve. To accelerate adoption, Guardium Cryptography Manager provides a fast, frictionless onboarding experience, enabling teams to unlock cryptographic visibility and insights within hours using a BYOL (Bring Your Own License) model. Explore IBM Guardium Cryptography Manager Now. Enjoy 90 days of free access to get started. For detailed deployment instructions and prerequisites, refer to the Guardium Cryptography Manager Deployment Guide: https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=dgcmice-guardium-cryptography-manager-amazon-web-services-aws-marketplace
Highlights
- Centralized cryptographic visibility across AWS: Automatically discovers and inventories cryptographic keys, certificates, secrets, and algorithms across hybrid and multi-cloud environments, helping reduce blind spots and shadow cryptography.
- AI-driven risk detection and remediation: Identifies outdated or vulnerable algorithms and uses AI to recommend remediation actions or automate approved workflows, helping reduce operational risk and strengthen security posture.
- Quantum-safe readiness and compliance for AWS workloads: Supports crypto-agility and helps you prepare for quantum-era threats including harvest now, decrypt later attacks while generating audit-ready reports aligned with evolving standards.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
All orders are non-cancellable and all fees and other amounts that you pay are non-refundable. If you have purchased a multi-year subscription, you agree to pay the annual fees due for each year of the multi-year subscription term.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
GCM 2.0.2.0 - Enterprise Kubernetes Management for AWS EKS
IBM Guardium Cryptography Manager (GCM) 2.0.2.0 provides enterprise-grade cryptographic key management and data encryption on AWS through automated AWS CloudFormation deployment. The solution delivers a production-ready Amazon EKS environment with security controls, high availability, scalability, and automated infrastructure provisioning.
Option 1 : Deploying by using a CloudFormation template (Quick deployment) https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=marketplace-deploying-by-using-cloudformation-template-quick-deployment
What Gets Deployed Infrastructure:
- Amazon EKS cluster (Kubernetes 1.33)
- Multi-AZ VPC with three public subnets
- Network Load Balancer for secure access
- Worker nodes (32 vCPUs, 128 GB RAM each)
- Amazon EFS shared storage with multi-AZ replication
- Three encrypted 100 GiB gp3 EBS volumes
- IAM roles and security groups following least privilege
Application:
- IBM Guardium Cryptography Manager with 20+ microservices
- OIDC authentication
- MongoDB, PostgreSQL, Redis databases
- Automated encryption configuration
- Multi-Region AWS asset discovery
Post-Deployment: Automated Asset Discovery is a one-time AWS IAM role-based scan that discovers assets across 30+ AWS services (including EC2, EKS, RDS, DynamoDB, S3, and Lambda) based on the user's permissions. It extracts cryptographic artifacts and metadata, collects the inventory through REST APIs, exports it as CSV files, and ingests it into the GCM application for centralized cryptographic asset management. Subsequent discoveries are performed using AWS plugins, which can be deployed as an optional add-on. These plugins enable incremental or recurring asset discovery and synchronize newly discovered assets with the GCM application.
Option 2 : Deploying to an existing EKS cluster https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=marketplace-deploying-existing-eks-cluster
Summary IBM Guardium Cryptography Manager provides a production-ready cryptographic management platform on AWS with automated deployment, enterprise security, high availability, monitoring, and asset discovery through AWS CloudFormation.
CloudFormation Template (CFT)
AWS CloudFormation templates are JSON or YAML-formatted text files that simplify provisioning and management on AWS. The templates describe the service or application architecture you want to deploy, and AWS CloudFormation uses those templates to provision and configure the required services (such as Amazon EC2 instances or Amazon RDS DB instances). The deployed application and associated resources are called a "stack."
Version release notes
Initial AWS Marketplace release of IBM Guardium Cryptography Manager (GCM) 2.0.2.0, featuring automated deployment on Amazon EKS with support for both automated EKS provisioning and Bring Your Own (BYO) EKS clusters. Delivers a production-ready, highly available deployment with automated AWS CloudFormation provisioning, enterprise-grade security, integrated monitoring, and pre-configured networking, IAM, and operational resources. Please find the product release notes here : https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=release-notes
Additional details
Usage instructions
Usage Instructions for GCM 2.0.2.0 on AWS EKS : https://www.ibm.com/docs/en/guardium-cm/2.0.x?topic=deploying-guardium-cryptography-manager-in-cloud-environments
Resources
Support
Vendor support
IBM provides enterprise grade support for Guardium Cryptography Manager, including assistance with deployment, configuration, cryptographic discovery, lifecycle management, and ongoing operational guidance. Customers can reach IBM Support through standard IBM support channels or via enterprise support agreements. Please reach out to IBM Support here :
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products


