ProcessQuantum Computing

Building a cryptographic inventory before post-quantum migration

A cryptographic inventory is a maintained record of where your organization uses public-key cryptography, what each use protects, who owns it and how long that protection must last. It is the first step of a post-quantum migration because nothing can be prioritized, budgeted or tested until it exists. This page sets out the discovery methods, the fields worth recording, a way to rank systems by exposure, and how the result becomes a migration roadmap.

Reviewed 8 min read

On this page
  1. Why the inventory sits on the critical path of post-quantum work
  2. The inventory loop from scope to migration backlog
  3. Where public-key cryptography hides in a typical estate
  4. Discovery methods compared: what each finds and what it misses
  5. Running the first inventory cycle in six steps
  6. Ranking by shelf-life and exposure rather than by system count
  7. A payments processor runs its first inventory cycle
  8. Government timelines that can anchor an internal migration plan
  9. Questions and answers
  10. Sources

Why the inventory sits on the critical path of post-quantum work

NIST has published three post-quantum standards: ML-KEM for key establishment in FIPS 203, and ML-DSA and SLH-DSA for signatures in FIPS 204 and FIPS 2054. Choosing replacement algorithms is no longer the hard part. Knowing where RSA, elliptic-curve Diffie-Hellman, ECDSA and EdDSA are used today, often inside products and libraries nobody configured on purpose, is.

Government guidance puts discovery first for that reason. The joint CISA, NSA and NIST factsheet asks organizations to start a quantum-readiness roadmap with cryptographic discovery and an inventory of quantum-vulnerable systems, including software and firmware update signatures2.

ColdAI's quantum computing hub describes post-quantum planning as starting here: inventory public-key usage, prioritize long-lived sensitive data, then plan a crypto-agile transition1. The method below is one way to run that first step.

The inventory loop from scope to migration backlog

boundariesraw findingsCBOM entriesprioritieschanges shippednext cycle01Set scope and owners02Discover usage03Record in a CBOM04Rank by exposure05Build the backlog06Re-scan on change
  1. Set scope and owners

    Decide which estates and suppliers the cycle covers and who owns each.

  2. Discover usage

    Combine code, certificate, network, key-store and supplier evidence.

  3. Record in a CBOM

    Write each finding as a structured entry linked to the component using it.

  4. Rank by exposure

    Score entries on shelf-life, exposure and effort to change.

  5. Build the backlog

    Turn ranked entries into upgrades, protocol changes, supplier asks or accepted risks.

  6. Re-scan on change

    Repeat discovery on each release and procurement.

Conceptual view of a repeating inventory cycle. It shows how outputs feed each other, not a timeline or a measured result.

Where public-key cryptography hides in a typical estate

The coverage list for a first cycle: places where quantum-vulnerable algorithms commonly turn up.

0 of 10 checked

Discovery methods compared: what each finds and what it misses

MethodWhat it finds wellWhat it missesWho runs it
Source and dependency scanningCrypto API calls, hard-coded algorithms and vulnerable library versions in code you buildClosed-source products and runtime configurationApplication security team in the CI/CD pipeline
Certificate and PKI inventoryAlgorithms, key sizes, issuers and expiry dates of issued certificatesRaw keys used outside certificates and embedded device keysPKI or identity team
Network traffic analysisNegotiated key exchange and cipher suites actually in use on the wireData at rest, signing and anything not observable on monitored linksNetwork security or SOC
Host and binary scanningCrypto libraries and keys present on servers, endpoints and imagesUsage inside firmware and appliances you cannot scanInfrastructure and endpoint teams
Supplier questionnairesEmbedded cryptography inside products and the vendor's migration roadmapAnything the supplier does not know or will not discloseProcurement with third-party risk

The CISA, NSA and NIST factsheet warns that discovery tools may not identify cryptography embedded inside products and advises asking vendors for lists of it2.

Running the first inventory cycle in six steps

  1. Fix scope and accountability

    Choose the estates for this cycle, usually internet-facing services, PKI and systems holding the most sensitive long-lived data. Name a business and a technical owner for each, because ranking later needs both.

    Output
    Scope statement and owner map
    Owner
    CISO or program lead
  2. Run automated discovery in parallel

    Start source, host, certificate and network scanning at the same time and keep raw results with their timestamps. Correlate findings with existing asset, identity and endpoint inventories rather than building a separate asset list2.

    Output
    Raw findings per method
    Owner
    Security engineering
  3. Send supplier questionnaires early

    Ask each critical supplier which algorithms their product uses, whether they are configurable and when post-quantum options will ship. Answers take longest to arrive, so send them at the start.

    Output
    Supplier responses and gaps
    Owner
    Procurement and third-party risk
  4. Normalize findings into a CBOM

    Record each use as a structured entry. The CycloneDX Cryptography Bill of Materials (CBOM) describes algorithms, keys and certificates and their relationships to software components, which keeps the record machine-readable and comparable across scans8.

    Output
    Versioned CBOM
    Owner
    Security architecture
  5. Add business context to every entry

    Technical findings cannot be ranked alone. For each entry add the system's criticality, what the cryptography protects, its data shelf-life (how long protection must last), its external exposure and its agility: whether change means configuration, an upgrade, new hardware or a supplier release.

    Output
    Context-enriched register
    Owner
    System and data owners
  6. Rank and hand over to the roadmap

    Score each entry, agree the top tier with risk owners and convert it into backlog items: upgrades, protocol changes, supplier commitments or documented risk acceptance.

    Output
    Ranked migration backlog
    Owner
    Risk committee and architecture board

Ranking by shelf-life and exposure rather than by system count

The threat that makes timing urgent is harvest now, decrypt later: an adversary records encrypted traffic or data today and decrypts it once a capable quantum computer exists2. Key establishment protecting long-lived secrets is therefore more urgent than a signature that only needs to be valid for a few minutes, even if both use the same algorithm family.

Michele Mosca framed the timing as three durations: how long data must stay secure, how long migration will take, and how long until a cryptographically relevant quantum computer exists; if the first two together exceed the third, you are already late9. Applied per entry, long shelf-life, external exposure and low agility rise to the top. Signatures rise for another reason: firmware roots of trust can take years to replace in fielded devices.

The EU's coordinated roadmap applies the same logic, advising that data needing confidentiality for at least ten years should be protected against quantum attack no later than the end of 20307. Symmetric encryption is a separate, smaller task: the NCSC states that symmetric cryptography is not significantly affected by quantum computers and that AES with keys of 128 bits or more remains suitable10.

A payments processor runs its first inventory cycle

Government timelines that can anchor an internal migration plan

Planning anchors from public guidance, useful for calibrating urgency with a board. Sector regulators may apply them differently; confirm your obligations with counsel. This is not legal advice.

Timelines for migration to post-quantum cryptography (NCSC guidance)

United Kingdom

Applies whenPublished as guidance for organizations planning their migration6.

  • Complete discovery and set migration goals with an initial plan by 20286.
  • Carry out the highest-priority migration activities by 20316.
  • Complete migration of all systems, services and products by 20356.

Transition to Post-Quantum Cryptography Standards (NIST IR 8547, initial public draft)

United States

Applies whenSystems that follow NIST cryptographic standards, including US federal systems5.

  • Proposes deprecating quantum-vulnerable algorithms at the 112-bit security level after 20305.
  • Proposes disallowing quantum-vulnerable signature and key-establishment algorithms after 20355.

A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography

European Union

Applies whenAddressed to Member States, with expectations that flow to operators of critical services7.

  • First steps, including cryptographic inventories, by the end of 20267.
  • Transition of high-risk use cases no later than the end of 20307.
  • Transition of medium-risk use cases by the end of 20357.

Questions and answers

Can automated discovery tools find every use of cryptography?

No. CISA's strategy for automated discovery tools notes that most of the nine inventory data items requested of US federal agencies cannot be collected with currently available automated tools and must be gathered manually3. Tools are strong on certificates, network handshakes and code you build, and weak on closed products, embedded devices and configuration that only appears at runtime. Plan for supplier questionnaires and owner interviews alongside scanning.

Does symmetric encryption such as AES need replacing for post-quantum readiness?

Generally not. The NCSC states that symmetric cryptography is not significantly affected by quantum computers, and AES with keys of at least 128 bits remains suitable10. The inventory should still record symmetric keys, because many are wrapped or exchanged using RSA or elliptic-curve keys, and those wrapping steps are what must migrate.

Where do blockchain and distributed ledger signatures fit in a cryptographic inventory?

Treat ledger account keys and transaction signatures as their own inventory class. They usually rely on elliptic-curve signatures, they protect assets rather than secrets, and changing them requires protocol support plus a key-rotation path for every account holder. ColdAI's post-quantum signature performance research page covers how to measure what a post-quantum signature would cost a ledger.

How often should a cryptographic inventory be refreshed?

Continuously for code you build, by running dependency and source scanning in the delivery pipeline, and on every procurement or major release for products you buy. Review business context and rankings in your annual risk cycle. An inventory refreshed only for audits is out of date as soon as the next release ships.

Sources

  1. Quantum Computing: prepare for quantum on two fronts — ColdAI
  2. Quantum-Readiness: Migration to Post-Quantum Cryptography (factsheet) — CISA, NSA and NIST · checked 10 October 2026
  3. Strategy for Migrating to Automated Post-Quantum Cryptography Discovery and Inventory Tools — Cybersecurity and Infrastructure Security Agency · checked 10 October 2026
  4. NIST Releases First 3 Finalized Post-Quantum Encryption Standards — National Institute of Standards and Technology · checked 10 October 2026
  5. NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards — National Institute of Standards and Technology · checked 10 October 2026
  6. Timelines for migration to post-quantum cryptography — National Cyber Security Centre (UK) · checked 10 October 2026
  7. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography — European Commission and NIS Cooperation Group · checked 10 October 2026
  8. Cryptography Bill of Materials (CBOM) — OWASP CycloneDX · checked 10 October 2026
  9. Cybersecurity in an era with quantum computers: will we be ready? — Michele Mosca, IACR Cryptology ePrint Archive · checked 10 October 2026
  10. Next steps in preparing for post-quantum cryptography — National Cyber Security Centre (UK) · checked 10 October 2026

More in Quantum Computing

Back to Quantum Computing

Next step

Scope your first cryptographic inventory cycle

Send a short description of the estates you want covered, the scanning or certificate tooling you already run and your most critical suppliers. We will reply with a proposed scope, the discovery methods that fit it and the fields your register should hold.

Discuss an inventory scope