By Cyber Defense Technologies January 20, 2026 5 min read
Every organization planning for post-quantum cryptography faces the same first question: where is our cryptography? The honest answer, for most, is "we don't fully know."
Cryptography is embedded in almost everything: TLS on web servers and load balancers, VPNs, SSH, email, databases, disk encryption, code signing, identity systems, hardware security modules, smart cards, IoT devices, and countless libraries inside applications. Much of it was configured by vendors or developers years ago and never documented.
A cryptographic inventory changes that. Federal agencies have been directed to maintain one, and it is the foundation of any credible quantum readiness plan.
Building a cryptographic inventory
-
1
Discover
Scan networks, code, certificates, libraries and devices for cryptography in use.
-
2
Record
Capture algorithm, key size, purpose, owner, data protected and how long it must stay secret.
-
3
Prioritize
Rank by data lifespan, exposure to interception and difficulty of change.
-
4
Plan
Decide how each item will migrate: vendor update, configuration change or redesign.
-
5
Maintain
Keep the inventory current as systems, vendors and standards change.
What to record
For each use of cryptography, capture:
- System and component: where it is used
- Purpose: key exchange, encryption, digital signature, hashing, authentication
- Algorithm and parameters: such as RSA-2048, ECDH P-256, AES-256 or SHA-256
- Protocol: TLS version, IPsec, SSH, S/MIME
- Implementation: library, product or hardware module, and version
- Data protected: what information, and its sensitivity
- Data lifespan: how long that information must remain confidential or trustworthy
- Exposure: whether the traffic crosses networks an adversary could intercept
- Owner: the person or team responsible
- Change path: configuration change, vendor update, code change or hardware replacement
The last three fields turn a technical list into a plan.
Where to look
No single tool finds everything. Effective discovery combines several sources.
Network traffic
Passive analysis of network traffic reveals protocols, versions and cipher suites in use between systems. Active scanning of services identifies what servers offer and accept.
Certificates and keys
Certificate discovery across internal and external services, certificate authorities and key management systems shows algorithms, key sizes, expiration dates and owners. Many organizations find far more certificates than they expected.
Code and libraries
Static analysis of source code, and software composition analysis of dependencies, reveals which cryptographic libraries and functions applications use. Look for hardcoded algorithms that would require code changes to replace.
Endpoints and servers
Configuration management and endpoint tools can report operating system cryptographic settings, installed libraries and disk encryption.
Devices and hardware
Network equipment, hardware security modules, smart cards, printers, IoT and operational technology often contain cryptography that software tools cannot see. Asset inventories and vendor documentation fill the gap.
Vendors and services
Cloud services, SaaS applications and managed services use cryptography you do not control. Ask vendors to document what they use and their post-quantum plans.
Prioritizing
With an inventory in hand, rank systems by:
- Data lifespan: information that must stay secret for many years is exposed to harvest-now, decrypt-later collection today.
- Exposure: traffic crossing the internet or other networks an adversary could monitor is at greater risk than traffic confined to protected segments.
- Criticality: systems that support essential missions or protect the trust of others, such as certificate authorities and code signing, deserve early attention.
- Difficulty: long lead-time items, such as hardware replacement and custom code, need to start early even if they are not the highest risk.
Common challenges
- Scale. Large organizations may find tens of thousands of cryptographic uses. Start with high-priority systems and expand.
- Ownership gaps. Many uses have no clear owner. Assigning owners is part of the work.
- Vendor opacity. Some vendors cannot or will not say what they use. Record the gap and address it in procurement.
- Drift. New systems appear constantly. Without maintenance, the inventory decays quickly.
Keeping it current
Build inventory updates into existing processes:
- Procurement: require vendors to disclose cryptography and post-quantum roadmaps.
- Change management: include cryptographic changes in change requests.
- Development: add cryptographic library checks to build pipelines.
- Periodic discovery: rerun network and certificate discovery on a schedule and reconcile differences.
A worked example
A mid-sized agency begins its inventory with its internet-facing services. Certificate discovery finds 400 certificates, 60 of them unknown to the team that manages the certificate authority. Network scanning shows most public services negotiate modern TLS with elliptic curve key exchange, but a legacy partner connection still uses an older RSA key exchange.
Code analysis of the agency's three main applications reveals that one hardcodes an RSA signature routine for signing documents that must remain verifiable for 30 years. A vendor questionnaire shows the case management platform's provider plans post-quantum support in its next major release, while the building access system's vendor has no plan at all.
The resulting priorities practically write themselves:
- The long-lived document signatures, which need a migration plan and crypto-agile redesign
- The partner connection, which carries sensitive data over the internet
- Unknown certificates, which need owners
- The access control vendor, which becomes a procurement issue at contract renewal
None of this was visible before the inventory.
Frequently asked questions
How long does an inventory take? A first pass on high-priority systems can take weeks; a comprehensive enterprise inventory takes longer. Start with what matters most and expand.
Can a tool do this automatically? Tools help enormously with network, certificate and code discovery, but none sees everything. Vendor questionnaires and asset records fill the gaps.
Do we need to replace symmetric encryption like AES? Symmetric algorithms and hash functions are much less affected by known quantum attacks than public-key algorithms. Guidance generally favors larger key sizes, such as AES-256, rather than replacement. The urgent work is public-key cryptography.
How CDT can help
CDT's quantum readiness and post-quantum security team performs cryptographic discovery across networks, code, certificates and devices, builds the inventory and turns it into a prioritized migration roadmap.