Inventory guide

How to Build a Cryptographic Inventory for PQC Migration

A post-quantum cryptography programme starts with discovery. Use this guide to list quantum-vulnerable cryptography across public endpoints, APIs, VPNs, certificates, signing workflows, suppliers and long-lived sensitive data.

Updated: 19 June 2026|14 min read

System and owner

Name the service, business owner, technical owner and environment.

Cryptographic use

Record whether cryptography is used for TLS, mTLS, VPN, signing, key wrapping, SSH, identity or stored data.

Algorithm evidence

Capture RSA, ECDH, ECDSA, DH, DSA, certificate chain, key size, curve and library evidence where known.

Data lifetime

Prioritise data that must remain confidential or authentic for years.

Supplier dependency

Record which CDN, cloud, identity, certificate, HSM, SaaS or managed-service provider controls the cryptography.

PQC migration status

Track unknown, assessed, pilot-ready, blocked, planned or migrated status.

What the Inventory Must Answer

A useful cryptographic inventory is not just a list of certificates. It should answer where cryptography is used, which algorithm or protocol is involved, what business process depends on it, who operates it and how difficult migration will be.

NIST NCCoE describes PQC migration as work that requires understanding quantum-vulnerable public-key algorithms in hardware, software and services, then developing roadmaps for prioritised migration. That is exactly what the inventory is for.

The first pass does not need perfect tooling. Start with externally visible systems, supplier questionnaires and known key stores. Improve the inventory as automated discovery tools and supplier evidence become available.

Systems to Include

Public endpoints

  • -Websites
  • -APIs
  • -VPN portals
  • -Customer login pages
  • -Partner callback URLs

Internal services

  • -mTLS service mesh
  • -Databases
  • -Object storage
  • -Message queues
  • -SSH and administration paths

Trust and signing

  • -Code signing
  • -Document signing
  • -Firmware signing
  • -Certificate authorities
  • -JWT or SAML signing keys

Suppliers

  • -CDN and WAF
  • -Cloud providers
  • -Identity providers
  • -Managed service providers
  • -Trust service providers

Five-Step Inventory Process

  1. 1. Start with externally visible systems. Scan public domains and APIs first because they are easy to verify and often controlled by a CDN, gateway or hosting provider.
  2. 2. Map cryptographic use cases. Separate key establishment, encryption at rest, digital signatures, certificate chains, identity tokens and administrative access.
  3. 3. Add data lifetime and exposure. Rank systems by how long the data or signature must remain protected, and whether traffic can be captured today.
  4. 4. Collect supplier evidence. Ask providers which NIST-standardised PQC algorithms they support, what is enabled by default and what dates are committed.
  5. 5. Turn the inventory into a migration backlog. Assign priority, owner, next action and evidence URL so the inventory can drive implementation rather than sit as a spreadsheet.

Download the Inventory Template

The CSV template gives your team a starting structure for owners, algorithms, suppliers, data lifetime, PQC status and next actions. Add a saved free scan URL as evidence for public endpoints.

Primary References

Cryptographic Inventory FAQ

What is a cryptographic inventory?

A cryptographic inventory is a structured list of where cryptography is used, what algorithms and protocols are involved, what data is protected, who owns the system and what must change for migration.

Why is a cryptographic inventory needed for PQC?

Post-quantum migration cannot be planned safely until the organisation knows where quantum-vulnerable public-key algorithms are used in hardware, software, services, suppliers and signing workflows.

Can a website scan replace a cryptographic inventory?

No. A public website scan is a strong first evidence item, but a full inventory must also include private APIs, VPNs, internal systems, signing keys, identity providers and suppliers.

Free readiness account

Keep This Guide Connected to a Real Website Scan

A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.

No cardStart the free evidence path without a paid plan.
Saved scanKeep the public endpoint result after the browser session.
Rescan laterRerun after TLS, header or provider changes.

Prefer to scan first? Open the free quantum security scanner.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.