ProcessQuantum Computing
Building a cryptographic inventory before post-quantum migration
A cryptographic inventory is a maintained record of where your organization uses public-key cryptography, what each use protects, who owns it and how long that protection must last. It is the first step of a post-quantum migration because nothing can be prioritized, budgeted or tested until it exists. This page sets out the discovery methods, the fields worth recording, a way to rank systems by exposure, and how the result becomes a migration roadmap.
On this page
- Why the inventory sits on the critical path of post-quantum work
- The inventory loop from scope to migration backlog
- Where public-key cryptography hides in a typical estate
- Discovery methods compared: what each finds and what it misses
- Running the first inventory cycle in six steps
- Ranking by shelf-life and exposure rather than by system count
- A payments processor runs its first inventory cycle
- Government timelines that can anchor an internal migration plan
- Questions and answers
- Sources
Why the inventory sits on the critical path of post-quantum work
NIST has published three post-quantum standards: ML-KEM for key establishment in FIPS 203, and ML-DSA and SLH-DSA for signatures in FIPS 204 and FIPS 2054. Choosing replacement algorithms is no longer the hard part. Knowing where RSA, elliptic-curve Diffie-Hellman, ECDSA and EdDSA are used today, often inside products and libraries nobody configured on purpose, is.
Government guidance puts discovery first for that reason. The joint CISA, NSA and NIST factsheet asks organizations to start a quantum-readiness roadmap with cryptographic discovery and an inventory of quantum-vulnerable systems, including software and firmware update signatures2.
ColdAI's quantum computing hub describes post-quantum planning as starting here: inventory public-key usage, prioritize long-lived sensitive data, then plan a crypto-agile transition1. The method below is one way to run that first step.
The inventory loop from scope to migration backlog
- Set scope and owners
Decide which estates and suppliers the cycle covers and who owns each.
- Discover usage
Combine code, certificate, network, key-store and supplier evidence.
- Record in a CBOM
Write each finding as a structured entry linked to the component using it.
- Rank by exposure
Score entries on shelf-life, exposure and effort to change.
- Build the backlog
Turn ranked entries into upgrades, protocol changes, supplier asks or accepted risks.
- Re-scan on change
Repeat discovery on each release and procurement.
Where public-key cryptography hides in a typical estate
The coverage list for a first cycle: places where quantum-vulnerable algorithms commonly turn up.
Discovery methods compared: what each finds and what it misses
| Method | What it finds well | What it misses | Who runs it |
|---|---|---|---|
| Source and dependency scanning | Crypto API calls, hard-coded algorithms and vulnerable library versions in code you build | Closed-source products and runtime configuration | Application security team in the CI/CD pipeline |
| Certificate and PKI inventory | Algorithms, key sizes, issuers and expiry dates of issued certificates | Raw keys used outside certificates and embedded device keys | PKI or identity team |
| Network traffic analysis | Negotiated key exchange and cipher suites actually in use on the wire | Data at rest, signing and anything not observable on monitored links | Network security or SOC |
| Host and binary scanning | Crypto libraries and keys present on servers, endpoints and images | Usage inside firmware and appliances you cannot scan | Infrastructure and endpoint teams |
| Supplier questionnaires | Embedded cryptography inside products and the vendor's migration roadmap | Anything the supplier does not know or will not disclose | Procurement with third-party risk |
The CISA, NSA and NIST factsheet warns that discovery tools may not identify cryptography embedded inside products and advises asking vendors for lists of it2.
Running the first inventory cycle in six steps
Fix scope and accountability
Choose the estates for this cycle, usually internet-facing services, PKI and systems holding the most sensitive long-lived data. Name a business and a technical owner for each, because ranking later needs both.
Run automated discovery in parallel
Start source, host, certificate and network scanning at the same time and keep raw results with their timestamps. Correlate findings with existing asset, identity and endpoint inventories rather than building a separate asset list2.
Send supplier questionnaires early
Ask each critical supplier which algorithms their product uses, whether they are configurable and when post-quantum options will ship. Answers take longest to arrive, so send them at the start.
Normalize findings into a CBOM
Record each use as a structured entry. The CycloneDX Cryptography Bill of Materials (CBOM) describes algorithms, keys and certificates and their relationships to software components, which keeps the record machine-readable and comparable across scans8.
Add business context to every entry
Technical findings cannot be ranked alone. For each entry add the system's criticality, what the cryptography protects, its data shelf-life (how long protection must last), its external exposure and its agility: whether change means configuration, an upgrade, new hardware or a supplier release.
Rank and hand over to the roadmap
Score each entry, agree the top tier with risk owners and convert it into backlog items: upgrades, protocol changes, supplier commitments or documented risk acceptance.
Ranking by shelf-life and exposure rather than by system count
The threat that makes timing urgent is harvest now, decrypt later: an adversary records encrypted traffic or data today and decrypts it once a capable quantum computer exists2. Key establishment protecting long-lived secrets is therefore more urgent than a signature that only needs to be valid for a few minutes, even if both use the same algorithm family.
Michele Mosca framed the timing as three durations: how long data must stay secure, how long migration will take, and how long until a cryptographically relevant quantum computer exists; if the first two together exceed the third, you are already late9. Applied per entry, long shelf-life, external exposure and low agility rise to the top. Signatures rise for another reason: firmware roots of trust can take years to replace in fielded devices.
The EU's coordinated roadmap applies the same logic, advising that data needing confidentiality for at least ten years should be protected against quantum attack no later than the end of 20307. Symmetric encryption is a separate, smaller task: the NCSC states that symmetric cryptography is not significantly affected by quantum computers and that AES with keys of 128 bits or more remains suitable10.
A payments processor runs its first inventory cycle
Government timelines that can anchor an internal migration plan
Planning anchors from public guidance, useful for calibrating urgency with a board. Sector regulators may apply them differently; confirm your obligations with counsel. This is not legal advice.
Timelines for migration to post-quantum cryptography (NCSC guidance)
United KingdomApplies whenPublished as guidance for organizations planning their migration6.
Transition to Post-Quantum Cryptography Standards (NIST IR 8547, initial public draft)
United StatesApplies whenSystems that follow NIST cryptographic standards, including US federal systems5.
A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography
European UnionApplies whenAddressed to Member States, with expectations that flow to operators of critical services7.
Questions and answers
Can automated discovery tools find every use of cryptography?
No. CISA's strategy for automated discovery tools notes that most of the nine inventory data items requested of US federal agencies cannot be collected with currently available automated tools and must be gathered manually3. Tools are strong on certificates, network handshakes and code you build, and weak on closed products, embedded devices and configuration that only appears at runtime. Plan for supplier questionnaires and owner interviews alongside scanning.
Does symmetric encryption such as AES need replacing for post-quantum readiness?
Generally not. The NCSC states that symmetric cryptography is not significantly affected by quantum computers, and AES with keys of at least 128 bits remains suitable10. The inventory should still record symmetric keys, because many are wrapped or exchanged using RSA or elliptic-curve keys, and those wrapping steps are what must migrate.
Where do blockchain and distributed ledger signatures fit in a cryptographic inventory?
Treat ledger account keys and transaction signatures as their own inventory class. They usually rely on elliptic-curve signatures, they protect assets rather than secrets, and changing them requires protocol support plus a key-rotation path for every account holder. ColdAI's post-quantum signature performance research page covers how to measure what a post-quantum signature would cost a ledger.
How often should a cryptographic inventory be refreshed?
Continuously for code you build, by running dependency and source scanning in the delivery pipeline, and on every procurement or major release for products you buy. Review business context and rankings in your annual risk cycle. An inventory refreshed only for audits is out of date as soon as the next release ships.
Sources
- Quantum Computing: prepare for quantum on two fronts — ColdAI
- Quantum-Readiness: Migration to Post-Quantum Cryptography (factsheet) — CISA, NSA and NIST · checked 10 October 2026
- Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools — Cybersecurity and Infrastructure Security Agency · checked 10 October 2026
- NIST Releases First 3 Finalized Post-Quantum Encryption Standards — National Institute of Standards and Technology · checked 10 October 2026
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards — National Institute of Standards and Technology · checked 10 October 2026
- Timelines for migration to post-quantum cryptography — National Cyber Security Centre (UK) · checked 10 October 2026
- A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography — European Commission and NIS Cooperation Group · checked 10 October 2026
- Cryptography Bill of Materials (CBOM) — OWASP CycloneDX · checked 10 October 2026
- Cybersecurity in an era with quantum computers: will we be ready? — Michele Mosca, IACR Cryptology ePrint Archive · checked 10 October 2026
- Next steps in preparing for post-quantum cryptography — National Cyber Security Centre (UK) · checked 10 October 2026