Cryptographic Discovery & Inventory
Find where cryptography is actually used across enterprise technology and establish accountable ownership.
What this capability solves
PQC migration fails when organizations do not know which algorithms, certificates, libraries, protocols and embedded dependencies protect their systems.
Technology is implemented as an operating capability: architecture, integration, governance, assurance, people, procedures and measurable outcomes are designed together.
Capability model
Modular building blocks allow the scope to start with a focused pilot and expand into an enterprise operating model.
Network Discovery
TLS, SSH, VPN, certificates, protocol versions and externally observable crypto.
Configuration Discovery
Server, cloud, middleware, database and application cryptographic settings.
Code / Dependency Review
Crypto libraries, SDKs, build dependencies and application use of cryptographic APIs.
PKI / Key Sources
Certificate authorities, HSMs, KMS, key stores, code-signing and trust anchors.
Device / Appliance Inventory
Network appliances, OT, IoT, firmware and vendor-managed cryptographic dependencies.
Ownership Mapping
Link findings to business service, technical owner, data class, vendor and lifecycle.
How the capability fits together
Final topology, control placement and deployment model are validated during discovery and detailed design.
Controls & governance
- Approved cryptographic profile registry
- Hybrid-first transition where compatibility requires it
- No untested algorithm replacement in production
- Key/certificate lifecycle and fallback controls
- Vendor and firmware dependency tracking
- Independent test evidence for critical systems
- Exception ownership and retirement dates
Priority use cases
- Enterprise PQC baseline
- Critical-system inventory
- M&A crypto due diligence
- Regulated long-lived data
- IoT/OT estate discovery
Key deliverables
- Crypto asset register
- Discovery evidence
- Owner mapping
- Unknown/unowned findings
- Initial remediation backlog
Integration considerations
- CMDB/asset inventory
- PKI/HSM/KMS
- Network/security platforms
- Application/CI-CD dependencies
- Cloud and SaaS configuration
- IoT/OT device inventory
- GRC/remediation workflow
Phased delivery
Each phase ends with evidence, acceptance criteria and a decision gate before broader scale-out.
