Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

Why Your Cryptographic Inventory is Your Master Key: Enterprise PQC Guidance

Cryptographic Inventory is Your Master Key

You cannot protect what you cannot see. While most organizations focus on visible threats like malware and hackers, the hidden layer of cryptography is often an uncharted territory. It is the foundation that secures everything from your customer data to your financial transactions. If you do not know what cryptographic assets you have, where they are deployed, who owns them, and what quantum risk they carry, you are operating without the visibility required to manage your security with confidence. A cryptographic inventory is the master key: it provides a clear, continuously maintained view of every algorithm, key, certificate, and protocol in your digital environment. DORA Article 9 and PCI DSS Requirement 12.3.3 have made it a legal requirement since early 2025. NIST FIPS 203, 204, and 205, finalized August 2024, make it the technical prerequisite for PQC migration. The recommended action: build a continuously maintained cryptographic inventory today, because every compliance requirement and every migration initiative depends on it. For the discovery methodology that feeds the inventory, see You Can’t Secure What You Can’t See.

Quick Answer: Why Is a Cryptographic Inventory Your Master Key?

A cryptographic inventory is your master key because PQC migration cannot be planned without knowing which systems run quantum-vulnerable algorithms; DORA Article 9.2 and PCI DSS Requirement 12.3.3 mandate a documented inventory as an enforceable obligation; incident response to a cryptographic vulnerability or certificate expiration takes days without one and hours with one; and HNDL-exposed systems cannot be identified for priority migration without mapping algorithm use to data confidentiality lifetime. For the full PQC migration context, see Essential Steps for Post-Quantum Cryptography Readiness. For the CBOM format that structures the inventory, see Why a CBOM Is Essential Now More Than Ever.

Current Standards and Deadlines the Inventory Must Address

A cryptographic inventory is not useful as a generic asset list. It must be structured to support the specific compliance and migration decisions that depend on it. The inventory must enable tracking against the following active requirements:

Standard / RequirementWhat the inventory must trackStatus
DORA Article 9.2 and 7.4All cryptographic assets and all digital certificates with the devices that hold themEnforceable since January 17, 2025
PCI DSS Requirement 12.3.3All cipher suites and protocols with business justification, viability monitoring, and response strategyEnforceable since March 31, 2025
NIST IR 8547 (RSA/ECC deprecation)Every RSA and ECC key and certificate; key size and expiration dateDeprecation by 2030; disallowance by 2035
FIPS 203 (ML-KEM)Which key exchange operations use RSA or ECDH and must migrate to ML-KEMFinalized August 2024
FIPS 204 (ML-DSA)Which signing operations use RSA or ECDSA and must migrate to ML-DSAFinalized August 2024
CNSA 2.0 (NSS supply chain)All asymmetric algorithms in NSS-adjacent systemsNew acquisitions: January 2027

The Four Pillars of a Strategic Cryptographic Inventory

Building a comprehensive inventory is a monumental task, but it can be broken down into a structured, manageable process based on four key pillars that ensure no layer of your digital environment is overlooked.

  • Network and Infrastructure

    This pillar focuses on both your external and internal networks. You must document all cryptography visible from outside your perimeter, such as SSL/TLS certificates used for customer interactions. An inventory of these assets ensures you are using strong protocols like TLS 1.3 and renewing certificates before they expire, preventing interception of sensitive data. Internally, you must review encryption protocols for all data moving between your own systems and devices to flag outdated protocols and ensure proper configuration. Passive network traffic analysis is the only discovery method that reveals what cryptographic protocols are actually being negotiated in production, as opposed to what configurations say should be available.

  • IT Assets and Databases

    This pillar addresses data at rest on your endpoints, servers, and storage. It involves discovering how encryption is applied across all IT assets from employee laptops to IoT devices, and ensuring they use modern, strong algorithms like AES-256. For databases, which are prime targets for cyberattacks, you must analyze encryption mechanisms and key management practices. AES-128 provides a reduced security margin against Grover’s algorithm and AES-256 is preferred for post-quantum contexts.

  • Applications and Code

    This is where the most hidden cryptographic uses are found. Encryption is often embedded deep within an application’s logic. This pillar requires a thorough code review of both proprietary and third-party software to identify all encryption libraries and algorithms. The goal is to track legacy algorithms like MD5, SHA-1, or RSA and ensure they are replaced with modern alternatives. You need automated tools to scan your code and check software bills of materials (SBOMs) to spot weaknesses, because manual inspection cannot cover the full scope of cryptographic function calls across a large codebase. The Applied Quantum PQC Migration Framework estimates more than 320 cryptographic function calls in a single mobile banking application.

  • Policy and Governance

    This is the most crucial pillar for long-term success. It establishes the rules and workflows to ensure your inventory is continuously maintained, assigning clear accountability and integrating the process into existing workflows like procurement and change management. Without governance, an inventory becomes a one-time snapshot that quickly becomes obsolete. With proper policy, it transforms into a living asset that continuously protects your organization against quantum threats while enabling rapid response to emerging cryptographic requirements. PCI DSS Requirement 12.3.3 explicitly requires continuous maintenance, not a point-in-time snapshot.

Beyond a List: What to Document for a Proactive Plan

A truly comprehensive inventory goes beyond the four pillars by documenting several key layers of your IT system. The goal is to move from a simple asset list to a prioritized, actionable plan:

  • Data and Device Criticality: Go beyond a simple list by documenting the business value and criticality of all sensitive data and the hardware that processes it. This is how you connect technical details to business value and justify migration priorities to leadership.
  • Owners and Vendors: Identify who is accountable for each asset and document your vendors’ security environment, including their PQC roadmap and planned support timeline for quantum-safe algorithms. Vendor timelines are entirely outside your control; the only variable you can influence is when you begin the engagement.
  • Data Lifespan: Apply a shelf-life risk model to determine how long sensitive information needs to remain confidential. A medical record needs far more long-term protection than a temporary VPN session. This is critical for addressing the HNDL threat: systems transmitting data that must remain confidential beyond the point at which a quantum computer could realistically exist are HNDL-exposed and require earliest migration.
  • Quantum Vulnerability Status: Each asset should carry a quantum vulnerability rating: quantum-vulnerable (RSA, ECC, DH, DSA, all broken by Shor’s algorithm), quantum-safe (AES-256, SHA-3, ML-KEM, ML-DSA), or under review. This rating drives remediation prioritization and compliance reporting against NIST IR 8547 and CNSA 2.0 deadlines.
  • Risk Prioritization: Combine criticality, vulnerability status, data lifespan, and HNDL exposure to rank assets based on their remediation priority. This turns raw inventory data into a data-driven conversation with leadership about where to invest first.

This entire process is about turning raw data into a living, actionable map for your organization. It is how you move from a reactive security environment to a proactive one.

CBOM Secure

Gain complete visibility with continuous cryptographic discovery, automated inventory, and data-driven PQC remediation.

Overcoming the Challenges and Building Your Roadmap

Building a comprehensive inventory is not a simple task. Many organizations face a lack of visibility due to a knowledge gap, struggle with organizational silos that create fragmented ownership, and rely on manual processes that lead to obsolete data. A strategic approach turns these challenges into opportunities:

Move away from manual spreadsheets and use automated discovery tools to create a single pane of glass that provides a unified view of all cryptographic assets. This centralized intelligence provides the data-driven business case needed to secure executive sponsorship and a definitive map of your entire cryptographic environment.

To build your readiness plan, follow these practical steps:

  • Secure the Budget: Get formal buy-in from senior leadership to provide the necessary resources and backing for a project of this scale. Frame the investment in terms of the compliance obligations already in effect under DORA and PCI DSS and the CNSA 2.0 deadlines approaching for NSS environments and supply chains.
  • Establish a Dedicated Team: Create a cross-functional team with key stakeholders from IT, security, and application owners to ensure alignment and break down organizational silos.
  • Deploy Automated Discovery Tools: Use Static Analysis (SAST) and Dynamic Analysis (DAST) tools, passive network sensors, and Certificate Transparency log monitoring to continuously discover cryptographic assets and prevent inventory drift.
  • Design a Granular Data Model and Integrate with Existing Infrastructure: Define a technical blueprint that captures essential attributes including algorithm type, key sizes, use cases, and nested dependencies, then link your inventory to existing systems like cloud key vaults and HSMs to create a holistic, centralized view.
  • Integrate with DevSecOps: Embed the inventory process into your CI/CD pipelines for ongoing monitoring and policy enforcement. New deployments should automatically update the inventory before reaching production.
  • Engage Third-Party Vendors: Proactively communicate with your vendors to assess their PQC readiness and ensure they can support your migration timeline. Confirm your HSM vendor’s roadmap for FIPS 140-3 validated ML-KEM and ML-DSA firmware support.
  • Assess and Prioritize Assets: Use a quantitative risk model to map assets to their business context and prioritize remediation based on quantum susceptibility, HNDL exposure, data sensitivity, and regulatory deadline pressure.

PQC Advisory Services

Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

Algorithm and Interoperability Caveats Your Inventory Must Capture

A cryptographic inventory that does not capture the hardware and software dependencies constraining which algorithms can be swapped in is not sufficient for migration planning. The following caveats must be documented per asset:

  • HSM firmware support gaps: Many FIPS 140-3 validated HSMs do not yet support ML-KEM or ML-DSA. The inventory must capture the HSM model and firmware version for each cryptographic asset that uses an HSM, and track the vendor’s roadmap for PQC algorithm support and FIPS 140-3 re-validation timeline.
  • TLS library versions: TLS 1.3 implementations must be updated or patched to support PQC key exchange groups before a PQC TLS handshake can complete. The inventory must capture TLS library versions across all endpoints and services.
  • Key and signature size increases: ML-KEM and ML-DSA produce significantly larger public keys and ciphertexts than RSA or ECDSA. TLS handshake message sizes increase, which can cause fragmentation issues in certain network configurations. Certificate chains carrying PQC signatures are larger. The inventory must flag systems where these size increases will cause operational impact.
  • Hybrid mode requirements: Systems that must maintain interoperability with counterparties that have not yet migrated will require hybrid mode deployment during the transition period. The inventory must identify counterparty dependencies that constrain the migration timeline.

How Encryption Consulting Can Help You

Creating a cryptographic inventory is a complicated task, but you do not have to do it alone. At Encryption Consulting, we offer PQC Advisory Services and CBOM Secure, our automated cryptographic discovery and inventory platform, designed to help businesses build and maintain a continuously governed cryptographic inventory.

  • PQC Assessment: We find all your keys and digital assets, giving you a clear picture of your quantum risk and where to focus first. The deliverable is a complete cryptographic inventory enriched with quantum vulnerability status, ownership routing, and compliance gap tagging against DORA, PCI DSS 12.3.3, and CNSA 2.0.
  • PQC Strategy and Roadmap: Based on what we find, we help you build a custom, step-by-step plan to transition to quantum-safe algorithms without disrupting your business, aligned to NIST and CNSA 2.0 deadlines and your specific risk appetite.
  • Vendor Selection: We help you choose the right tools and technology by running proof-of-concepts on your most important systems, including confirming HSM vendor PQC roadmaps and TLS library readiness.
  • PQC Implementation: We help you smoothly integrate new, quantum-safe algorithms into your existing security setup, supporting hybrid deployment for backward compatibility during the transition period.

Conclusion

A cryptographic inventory is more than a security project; it is the foundational step for any organization seeking to prepare its digital assets for the future. DORA Article 9 and PCI DSS Requirement 12.3.3 make it a legal obligation today. NIST FIPS 203, 204, and 205 and CNSA 2.0 deadlines make it the technical prerequisite for PQC migration. HNDL exposure makes it the risk management action that cannot be deferred. By moving beyond a simple list and embracing a phased, data-driven approach, you can transform a complex challenge into a strategic advantage. The visibility and control gained from a comprehensive inventory allow you to manage business risk effectively, allocate resources efficiently, and build a resilient, crypto-agile infrastructure. For the discovery layers that build the inventory, see You Can’t Secure What You Can’t See. For the CBOM format that structures it, see Why a CBOM Is Essential Now More Than Ever. For the full migration planning steps and implementation checklist, see Unlocking the Quantum Era: Essential Steps for Post-Quantum Cryptography Readiness.

Frequently Asked Questions

What is a cryptographic inventory and what does it contain?

A cryptographic inventory is a comprehensive, continuously maintained record of every cryptographic asset in an organization’s environment: every algorithm and parameter set, key size and key type, certificate details, security protocol version and cipher suite, system deployment location, owner, quantum vulnerability status, compliance relevance, and migration status. It is structured to support PQC migration planning, regulatory compliance documentation, and incident response.

Why is a cryptographic inventory the prerequisite for PQC migration?

A cryptographic inventory is the prerequisite for PQC migration because you cannot migrate what you have not mapped. Knowing which algorithms to migrate to (NIST FIPS 203, 204, 205, finalized August 2024) is only half the problem. The other half is knowing which systems run RSA, ECDH, ECDSA, and Diffie-Hellman, and with what hardware and software dependencies that constrain the migration timeline. Without a baseline inventory, migration planning is guesswork.

What compliance requirements mandate a cryptographic inventory?

DORA Article 9.2 has required financial entities to maintain a documented cryptographic asset register since January 17, 2025. PCI DSS Requirement 12.3.3 has required a continuously maintained cipher suite inventory since March 31, 2025. Both are active enforcement obligations, not future roadmap items.

What is the Harvest Now, Decrypt Later threat and how does a cryptographic inventory address it?

HNDL is the strategy of collecting encrypted data today and archiving it until a quantum computer arrives to decrypt it. A cryptographic inventory addresses HNDL by identifying which systems transmit data with long-term confidentiality requirements encrypted under quantum-vulnerable algorithms. Those systems carry HNDL exposure and require earliest migration. Without a cryptographic inventory mapping algorithm use to data confidentiality lifetime, there is no systematic way to identify HNDL-exposed systems.

How do you maintain a cryptographic inventory continuously rather than as a point-in-time snapshot?

Continuous maintenance requires integration with automated discovery tooling, version control systems, and certificate management infrastructure. Automated tools continuously scan network traffic, code repositories, and certificate infrastructure. The inventory must be linked to the DevSecOps pipeline so new deployments automatically update it before reaching production. Certificate Transparency log monitoring continuously surfaces newly issued certificates including shadow certificates. PCI DSS Requirement 12.3.3 explicitly requires continuous maintenance; a point-in-time snapshot does not satisfy it.