System and owner
Name the service, business owner, technical owner and environment.
A post-quantum cryptography programme starts with discovery. Use this guide to list quantum-vulnerable cryptography across public endpoints, APIs, VPNs, certificates, signing workflows, suppliers and long-lived sensitive data.
Name the service, business owner, technical owner and environment.
Record whether cryptography is used for TLS, mTLS, VPN, signing, key wrapping, SSH, identity or stored data.
Capture RSA, ECDH, ECDSA, DH, DSA, certificate chain, key size, curve and library evidence where known.
Prioritise data that must remain confidential or authentic for years.
Record which CDN, cloud, identity, certificate, HSM, SaaS or managed-service provider controls the cryptography.
Track unknown, assessed, pilot-ready, blocked, planned or migrated status.
A useful cryptographic inventory is not just a list of certificates. It should answer where cryptography is used, which algorithm or protocol is involved, what business process depends on it, who operates it and how difficult migration will be.
NIST NCCoE describes PQC migration as work that requires understanding quantum-vulnerable public-key algorithms in hardware, software and services, then developing roadmaps for prioritised migration. That is exactly what the inventory is for.
The first pass does not need perfect tooling. Start with externally visible systems, supplier questionnaires and known key stores. Improve the inventory as automated discovery tools and supplier evidence become available.
The CSV template gives your team a starting structure for owners, algorithms, suppliers, data lifetime, PQC status and next actions. Add a saved free scan URL as evidence for public endpoints.
A cryptographic inventory is a structured list of where cryptography is used, what algorithms and protocols are involved, what data is protected, who owns the system and what must change for migration.
Post-quantum migration cannot be planned safely until the organisation knows where quantum-vulnerable public-key algorithms are used in hardware, software, services, suppliers and signing workflows.
No. A public website scan is a strong first evidence item, but a full inventory must also include private APIs, VPNs, internal systems, signing keys, identity providers and suppliers.
A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.
Prefer to scan first? Open the free quantum security scanner.