Cryptographic Exposure Discovery and PQC Readiness Mapping
A discovery, assessment, prioritization, and crypto-agility service that maps existing cryptographic use across the estate and plans a phased path toward post-quantum readiness.
- · NGOs
- · Institutes
- · Think tanks
- · Advanced R&D labs
- · Long-retention archives
- · Certificates
- · Key material
- · Protocol endpoints
- · Application inventories
- · Certificate stores
- · Protocol scans
- · Archive metadata
- · PKI
- · Key management
- · Applications and integrations
- Discovery inventories cryptographic assets across connected sources.
- Assets are classified by exposure and criticality.
- A prioritized readiness map informs a phased migration plan.
- Crypto-agility patterns are prepared for future algorithm change.
- · Migration plan approvals
- · Algorithm and policy changes
- · Cryptographic inventory
- · Exposure classification
- · Migration plan of record
- · Sensitive Data Classification and Routing
- · Evidence-Grade Audit and Provenance Capture
Cryptographic exposure discovery and PQC readiness mapping is a readiness capability, not a claim of completed migration.
A ten-year research archive is inventoried, its current cryptographic posture is classified, and a phased migration plan is drafted for beneficiary approval.
- · Access to relevant certificate and application inventories
- · Approve migration plans
- · Coordinate with system owners
- · This service is a readiness capability. It does not imply that beneficiary systems have already completed post-quantum migration.
- · The overlay itself is not a universally deployed post-quantum encryption layer.
Delivery model
Onboarding → Policy Definition → Controlled Rollout → Steady-State Assurance. Every phase produces named evidence artifacts.
- Phase 1Onboarding
Discovery across application inventories, certificate stores, protocol scans, and archive metadata. Named crypto stewards established.
- · Cryptographic asset inventory
- · Discovery-coverage report
- Phase 2Policy Definition
Exposure classification criteria, prioritization rubric, crypto-agility patterns, and migration authority are ratified.
- · Exposure classification of record
- · Crypto-agility pattern library
- Phase 3Controlled Rollout
Prioritized migration plan drafted and executed on selected pilot systems; hybrid transitional modes validated where supported.
- · Migration plan of record
- · Pilot validation report
- Phase 4Steady-State Assurance
Ongoing discovery refresh, migration progress reporting, and quarterly PQC readiness packs.
- · Quarterly PQC readiness pack
- · Discovery refresh log
Beneficiary scenarios
A long-retention research archive is inventoried, its current cryptographic posture classified as high-exposure under harvest-now-decrypt-later assumptions, and a phased migration plan is drafted using ML-KEM in hybrid mode with existing key material for beneficiary approval.
A certificate estate with multi-year validity is inventoried; exposure classification flags roots and intermediates with lifetime beyond credible cryptographic runway. A phased issuance program with crypto-agile patterns is planned with the PKI owner.
Engineering detail
Integration model+
Read-only discovery against PKI, key-management systems, application inventories, and protocol endpoints. Migration is executed by system owners with overlay-provided plans and evidence capture.
Data flows+
Discovery signals compose into an inventory; assets are classified by algorithm, retention, and exposure. A prioritized migration plan is drafted and executed with crypto-agility patterns preserved for future algorithm change.
Cryptographic components+
Inventory captures algorithm, key length, mode, and usage per asset. Migration targets NIST-selected PQC primitives (ML-KEM, ML-DSA, SLH-DSA) with hybrid transitional modes where the environment supports them.
Logging architecture+
Every discovery run, classification decision, migration plan version, and executed migration step is written to the evidence chain.
Deployment prerequisites+
Access to certificate and application inventories, named crypto stewards, and coordinated system owners for pilot migrations.
Operational limits+
This is a readiness capability; it does not itself deploy post-quantum encryption universally. Environment support for PQC and hybrid modes varies by vendor.
Governance model
- · Classification rubric changes require crypto-lead ratification.
- · Migration plans require named steward approval before execution.
- · Algorithm-choice changes require executive sponsor sign-off.
- · Pilot-to-production expansion requires validation-report review.
Assets that cannot migrate under current environment support are recorded with rationale, compensating controls, and re-review date.
Migration steps preserve prior key material and configuration for a defined window; rollback is coordinated with system owners and logged.
The beneficiary and system owners own migration execution and algorithm choice. The overlay inventories, classifies, and plans; humans decide.
Evidence and reporting outputs
- · Cryptographic asset inventory
- · Exposure classification of record
- · Prioritized migration plan
- · Pilot validation report
- · Crypto-agility pattern applied per asset
- · Exception register with re-review dates
- · Discovery refresh log
- · Quarterly PQC readiness pack
Grant scope
- · Discovery across an agreed asset scope
- · Classification rubric and prioritization
- · Migration plan authoring for pilot systems
- · Steady-state readiness reporting
- · Provide inventory and PKI access
- · Name crypto stewards
- · Execute migrations with system owners under ratified plans
Typical: 4-phase delivery over 12–20 weeks depending on estate size and PKI complexity.
- · Universal deployment of post-quantum encryption
- · Guarantee of vendor support for PQC primitives
- · PKI reissuance costs
Portfolio interlock
Predecessors, successors, and operational interlocks across the portfolio.
- · Sensitive Data Classification and Routing
- · Evidence-Grade Audit and Provenance Capture
- · Board-, Donor-, and Regulator-Ready Security Reporting
- · Vendor and Dependency Trust Monitoring
Risks and non-claims
Requires validation- · PQC primitives and hybrid modes remain subject to standards evolution; crypto-agility patterns are the mitigation.
- · Environment support varies; the exception register makes non-migratable assets explicit.
- · Discovery coverage is bounded by connected sources; the coverage report labels gaps.
