Skip to content
Cyber Defense Technologies

Insights

Building a Cryptographic Inventory: The First Step to Quantum Readiness

You cannot migrate cryptography you cannot find. How to discover where cryptography is used across networks, software, certificates and devices, what to record, and how to turn the inventory into a migration plan.

By Cyber Defense Technologies January 20, 2026 5 min read

Every organization planning for post-quantum cryptography faces the same first question: where is our cryptography? The honest answer, for most, is "we don't fully know."

Cryptography is embedded in almost everything: TLS on web servers and load balancers, VPNs, SSH, email, databases, disk encryption, code signing, identity systems, hardware security modules, smart cards, IoT devices, and countless libraries inside applications. Much of it was configured by vendors or developers years ago and never documented.

A cryptographic inventory changes that. Federal agencies have been directed to maintain one, and it is the foundation of any credible quantum readiness plan.

Building a cryptographic inventory

  1. 1

    Discover

    Scan networks, code, certificates, libraries and devices for cryptography in use.

  2. 2

    Record

    Capture algorithm, key size, purpose, owner, data protected and how long it must stay secret.

  3. 3

    Prioritize

    Rank by data lifespan, exposure to interception and difficulty of change.

  4. 4

    Plan

    Decide how each item will migrate: vendor update, configuration change or redesign.

  5. 5

    Maintain

    Keep the inventory current as systems, vendors and standards change.

What to record

For each use of cryptography, capture:

  • System and component: where it is used
  • Purpose: key exchange, encryption, digital signature, hashing, authentication
  • Algorithm and parameters: such as RSA-2048, ECDH P-256, AES-256 or SHA-256
  • Protocol: TLS version, IPsec, SSH, S/MIME
  • Implementation: library, product or hardware module, and version
  • Data protected: what information, and its sensitivity
  • Data lifespan: how long that information must remain confidential or trustworthy
  • Exposure: whether the traffic crosses networks an adversary could intercept
  • Owner: the person or team responsible
  • Change path: configuration change, vendor update, code change or hardware replacement

The last three fields turn a technical list into a plan.

Where to look

No single tool finds everything. Effective discovery combines several sources.

Network traffic

Passive analysis of network traffic reveals protocols, versions and cipher suites in use between systems. Active scanning of services identifies what servers offer and accept.

Certificates and keys

Certificate discovery across internal and external services, certificate authorities and key management systems shows algorithms, key sizes, expiration dates and owners. Many organizations find far more certificates than they expected.

Code and libraries

Static analysis of source code, and software composition analysis of dependencies, reveals which cryptographic libraries and functions applications use. Look for hardcoded algorithms that would require code changes to replace.

Endpoints and servers

Configuration management and endpoint tools can report operating system cryptographic settings, installed libraries and disk encryption.

Devices and hardware

Network equipment, hardware security modules, smart cards, printers, IoT and operational technology often contain cryptography that software tools cannot see. Asset inventories and vendor documentation fill the gap.

Vendors and services

Cloud services, SaaS applications and managed services use cryptography you do not control. Ask vendors to document what they use and their post-quantum plans.

Prioritizing

With an inventory in hand, rank systems by:

  1. Data lifespan: information that must stay secret for many years is exposed to harvest-now, decrypt-later collection today.
  2. Exposure: traffic crossing the internet or other networks an adversary could monitor is at greater risk than traffic confined to protected segments.
  3. Criticality: systems that support essential missions or protect the trust of others, such as certificate authorities and code signing, deserve early attention.
  4. Difficulty: long lead-time items, such as hardware replacement and custom code, need to start early even if they are not the highest risk.

Common challenges

  • Scale. Large organizations may find tens of thousands of cryptographic uses. Start with high-priority systems and expand.
  • Ownership gaps. Many uses have no clear owner. Assigning owners is part of the work.
  • Vendor opacity. Some vendors cannot or will not say what they use. Record the gap and address it in procurement.
  • Drift. New systems appear constantly. Without maintenance, the inventory decays quickly.

Keeping it current

Build inventory updates into existing processes:

  • Procurement: require vendors to disclose cryptography and post-quantum roadmaps.
  • Change management: include cryptographic changes in change requests.
  • Development: add cryptographic library checks to build pipelines.
  • Periodic discovery: rerun network and certificate discovery on a schedule and reconcile differences.

A worked example

A mid-sized agency begins its inventory with its internet-facing services. Certificate discovery finds 400 certificates, 60 of them unknown to the team that manages the certificate authority. Network scanning shows most public services negotiate modern TLS with elliptic curve key exchange, but a legacy partner connection still uses an older RSA key exchange.

Code analysis of the agency's three main applications reveals that one hardcodes an RSA signature routine for signing documents that must remain verifiable for 30 years. A vendor questionnaire shows the case management platform's provider plans post-quantum support in its next major release, while the building access system's vendor has no plan at all.

The resulting priorities practically write themselves:

  1. The long-lived document signatures, which need a migration plan and crypto-agile redesign
  2. The partner connection, which carries sensitive data over the internet
  3. Unknown certificates, which need owners
  4. The access control vendor, which becomes a procurement issue at contract renewal

None of this was visible before the inventory.

Frequently asked questions

How long does an inventory take? A first pass on high-priority systems can take weeks; a comprehensive enterprise inventory takes longer. Start with what matters most and expand.

Can a tool do this automatically? Tools help enormously with network, certificate and code discovery, but none sees everything. Vendor questionnaires and asset records fill the gaps.

Do we need to replace symmetric encryption like AES? Symmetric algorithms and hash functions are much less affected by known quantum attacks than public-key algorithms. Guidance generally favors larger key sizes, such as AES-256, rather than replacement. The urgent work is public-key cryptography.

How CDT can help

CDT's quantum readiness and post-quantum security team performs cryptographic discovery across networks, code, certificates and devices, builds the inventory and turns it into a prioritized migration roadmap.

Sources

Let's talk

Ready to strengthen your security posture?

Talk with a CDT engineer about your mission, your systems and your deadlines. We'll tell you honestly what it takes.