Skip to content
HEKA — See First. Defend First. Powered by KRYOS XS Hypercube
Post-quantum readiness

Cryptographic Exposure Discovery and PQC Readiness Mapping

A discovery, assessment, prioritization, and crypto-agility service that maps existing cryptographic use across the estate and plans a phased path toward post-quantum readiness.

Mission problem
Long-retention information and long-lived certificates require deliberate cryptographic planning, not one-time change.
Who it protects
  • · NGOs
  • · Institutes
  • · Think tanks
  • · Advanced R&D labs
Sensitive assets involved
  • · Long-retention archives
  • · Certificates
  • · Key material
  • · Protocol endpoints
Required inputs
  • · Application inventories
  • · Certificate stores
  • · Protocol scans
  • · Archive metadata
Connected systems
  • · PKI
  • · Key management
  • · Applications and integrations
How the service works
  1. Discovery inventories cryptographic assets across connected sources.
  2. Assets are classified by exposure and criticality.
  3. A prioritized readiness map informs a phased migration plan.
  4. Crypto-agility patterns are prepared for future algorithm change.
Human-review points
  • · Migration plan approvals
  • · Algorithm and policy changes
Evidence produced
  • · Cryptographic inventory
  • · Exposure classification
  • · Migration plan of record
Service interlocks
  • · Sensitive Data Classification and Routing
  • · Evidence-Grade Audit and Provenance Capture
Cryptographic Exposure Explorer
S1
Discover
S2
Inventory
S3
Classify exposure
S4
Prioritize
S5
Plan migration
S6
Validate
Current posture
Readiness assessment
Migration planning
Approved implementation

Cryptographic exposure discovery and PQC readiness mapping is a readiness capability, not a claim of completed migration.

Illustrative scenario
Illustrative: long-retention research archive

A ten-year research archive is inventoried, its current cryptographic posture is classified, and a phased migration plan is drafted for beneficiary approval.

Deployment prerequisites
  • · Access to relevant certificate and application inventories
Beneficiary responsibilities
  • · Approve migration plans
  • · Coordinate with system owners
Limitations and non-claimsRequires validation
  • · This service is a readiness capability. It does not imply that beneficiary systems have already completed post-quantum migration.
  • · The overlay itself is not a universally deployed post-quantum encryption layer.
Frequently asked
Do we get post-quantum encryption automatically?
No. The service inventories exposure and helps plan a prioritized, crypto-agile migration path.
How is harvest-now-decrypt-later addressed?
Long-retention datasets are prioritized in exposure classification; migration plans sequence high-retention material ahead of ephemeral traffic.
Which algorithms are targeted?
The migration map targets NIST-selected post-quantum primitives (e.g. ML-KEM/Kyber for key establishment, ML-DSA/Dilithium for signatures) with hybrid transitional modes where supported.

Delivery model

Onboarding → Policy Definition → Controlled Rollout → Steady-State Assurance. Every phase produces named evidence artifacts.

4-Phase Delivery Timeline
  1. Phase 1
    Onboarding

    Discovery across application inventories, certificate stores, protocol scans, and archive metadata. Named crypto stewards established.

    • · Cryptographic asset inventory
    • · Discovery-coverage report
  2. Phase 2
    Policy Definition

    Exposure classification criteria, prioritization rubric, crypto-agility patterns, and migration authority are ratified.

    • · Exposure classification of record
    • · Crypto-agility pattern library
  3. Phase 3
    Controlled Rollout

    Prioritized migration plan drafted and executed on selected pilot systems; hybrid transitional modes validated where supported.

    • · Migration plan of record
    • · Pilot validation report
  4. Phase 4
    Steady-State Assurance

    Ongoing discovery refresh, migration progress reporting, and quarterly PQC readiness packs.

    • · Quarterly PQC readiness pack
    • · Discovery refresh log

Beneficiary scenarios

Illustrative
Ten-year research archive

A long-retention research archive is inventoried, its current cryptographic posture classified as high-exposure under harvest-now-decrypt-later assumptions, and a phased migration plan is drafted using ML-KEM in hybrid mode with existing key material for beneficiary approval.

Illustrative
Long-lived certificate estate

A certificate estate with multi-year validity is inventoried; exposure classification flags roots and intermediates with lifetime beyond credible cryptographic runway. A phased issuance program with crypto-agile patterns is planned with the PKI owner.

Engineering detail

Integration model+

Read-only discovery against PKI, key-management systems, application inventories, and protocol endpoints. Migration is executed by system owners with overlay-provided plans and evidence capture.

Data flows+

Discovery signals compose into an inventory; assets are classified by algorithm, retention, and exposure. A prioritized migration plan is drafted and executed with crypto-agility patterns preserved for future algorithm change.

Cryptographic components+

Inventory captures algorithm, key length, mode, and usage per asset. Migration targets NIST-selected PQC primitives (ML-KEM, ML-DSA, SLH-DSA) with hybrid transitional modes where the environment supports them.

Logging architecture+

Every discovery run, classification decision, migration plan version, and executed migration step is written to the evidence chain.

Deployment prerequisites+

Access to certificate and application inventories, named crypto stewards, and coordinated system owners for pilot migrations.

Operational limits+

This is a readiness capability; it does not itself deploy post-quantum encryption universally. Environment support for PQC and hybrid modes varies by vendor.

Governance model

Approval gates
  • · Classification rubric changes require crypto-lead ratification.
  • · Migration plans require named steward approval before execution.
  • · Algorithm-choice changes require executive sponsor sign-off.
  • · Pilot-to-production expansion requires validation-report review.
Exception handling

Assets that cannot migrate under current environment support are recorded with rationale, compensating controls, and re-review date.

Rollback paths

Migration steps preserve prior key material and configuration for a defined window; rollback is coordinated with system owners and logged.

Beneficiary control boundaries

The beneficiary and system owners own migration execution and algorithm choice. The overlay inventories, classifies, and plans; humans decide.

Evidence and reporting outputs

  • · Cryptographic asset inventory
  • · Exposure classification of record
  • · Prioritized migration plan
  • · Pilot validation report
  • · Crypto-agility pattern applied per asset
  • · Exception register with re-review dates
  • · Discovery refresh log
  • · Quarterly PQC readiness pack

Grant scope

Included
  • · Discovery across an agreed asset scope
  • · Classification rubric and prioritization
  • · Migration plan authoring for pilot systems
  • · Steady-state readiness reporting
Beneficiary responsibilities
  • · Provide inventory and PKI access
  • · Name crypto stewards
  • · Execute migrations with system owners under ratified plans
Timeline

Typical: 4-phase delivery over 12–20 weeks depending on estate size and PKI complexity.

Explicit exclusions
  • · Universal deployment of post-quantum encryption
  • · Guarantee of vendor support for PQC primitives
  • · PKI reissuance costs

Portfolio interlock

Portfolio Interlock Web
01Access02Data class.03Threat corr.04Workflow05Evidence06Compliance07Reporting08Vendor09PQC readiness10Scenario/IR10-serviceportfolio

Predecessors, successors, and operational interlocks across the portfolio.

Natural predecessors
  • · Sensitive Data Classification and Routing
Natural successors
  • · Evidence-Grade Audit and Provenance Capture
  • · Board-, Donor-, and Regulator-Ready Security Reporting
Operational interlocks
  • · Vendor and Dependency Trust Monitoring

Risks and non-claims

Requires validation
  • · PQC primitives and hybrid modes remain subject to standards evolution; crypto-agility patterns are the mitigation.
  • · Environment support varies; the exception register makes non-migratable assets explicit.
  • · Discovery coverage is bounded by connected sources; the coverage report labels gaps.
Next
Discuss this service in your context