Skip to content
Harvest now · decrypt later

Find your quantum-vulnerable cryptography before it becomes an emergency.

PQC Radar scans your TLS, certificates, SSH, APIs, vendors, and long-lived data systems to show where RSA/ECC exposure exists and what to fix first.

3
NIST PQC standards finalized (2024)
5-20+
year confidentiality windows at risk
2029
Cloudflare's full PQC target
Now
when migration planning should start
crypto-inventory.consoleLive scan
target: acme-corp.example
demo data
RSA certificates
37
2048-bit, internet-facing
ECC key exchange
112
P-256 / X25519 endpoints
TLS endpoints scanned
1,284
across 9 environments
SSH hosts
208
RSA / ECDSA host keys
Long-lived data stores
14
10y+ retention flagged
Vendor dependencies
63
crypto-relevant integrations
AssetAlgorithmRisk
edge-gw-01.tlsRSA-2048high
api.paymentsECDHE P-256high
vault.kms.rootRSA-4096medium
ssh.bastion-3ECDSA P-256high
archive.kyc.s3RSA-OAEPhigh
ci.signing.keyEd25519medium
72
Priority
Migration priority score

Console preview: sample data, not a live customer scan

RSA-2048RSA-4096ECDHE P-256X25519ECDSAEdDSA / Ed25519DH / IKETLS 1.2 / 1.3SSH host keysX.509 / PKIJWT / JWSML-KEM (FIPS 203)ML-DSA (FIPS 204)
The real risk

The quantum risk is not theoretical for data stolen today.

Quantum risk is not only about future computers. It is about data lifetime, and the clock starts the moment data is captured.

1Capture today

An attacker records encrypted traffic or steals an archive.

2Store for years

It sits untouched, still protected by RSA/ECC.

3Break later

A future quantum computer breaks the public-key layer.

4Read old data

Yesterday's confidential data becomes readable.

If your data must stay confidential for the next decade, your quantum risk window may already be open.
Who this hits
  • Law firm: Confidential acquisition documents archived for years: captured today, readable later.

  • Fintech: Customer KYC documents and identity records with long regulatory retention windows.

  • Healthtech: Medical records that must stay private for the lifetime of the patient.

  • B2B SaaS: Enterprise customer contracts and tenant data under multi-year confidentiality terms.

  • IoT vendor: Devices shipped to the field expected to stay deployed for 10-20 years.

  • Any org: VPN, TLS, SSH and certificates in use without a record of which algorithms back them.

Útočná plocha

What systems are most exposed?

Cryptography hides in more places than any inventory expects. Here is where we look, and what we check.

TLS / HTTPS

Checks: Negotiated key-exchange groups, cipher suites, certificate algorithms, and hybrid support.

VPNs & remote access

Checks: VPN endpoints, IKE proposals, certificate chains, and PSK vs public-key usage.

SSH infrastructure

Checks: Host key types, key-exchange algorithms, and key inventory across fleets.

Code signing

Checks: Signing key algorithms, certificate lifetimes, and CI/CD signing flows.

Certificates & PKI

Checks: Full certificate inventory, key algorithms, expiry, and issuing CA dependencies.

APIs & service auth

Checks: JWT/JWS algorithms, mTLS configs, and OAuth/OIDC signing keys.

Encrypted backups

Checks: Key-wrapping algorithms, KMS configuration, and backup retention windows.

Customer data archives

Checks: Retention periods vs. crypto lifetime, envelope encryption, and access exposure.

IoT firmware & devices

Checks: Secure-boot/update signature schemes and crypto-agility of the update channel.

Vendor & third-party

Checks: Vendor PQC roadmaps, supported algorithms, and contractual/procurement exposure.

Evidence

The world is already moving.

Standards are final and major platforms have shipped. Every claim links to a primary source.

Standards

NIST finalized PQC standards in 2024

ML-KEM, ML-DSA, and SLH-DSA are now published federal standards.

Guidance

CISA, NSA & NIST say start now

Official guidance: inventory your cryptography and begin migration planning.

Migration is an engineering process, not a one-click certificate update.

See the full timeline
The product

What PQC Radar does

Four steps: from scattered cryptography to a prioritized migration plan.

01

Discover

Scan endpoints, certificates, repositories, and cloud assets plus any infrastructure data you provide.

  • TLS endpoint sweep
  • Certificate transparency
  • Repo & dependency scan
  • Cloud asset import
02

Inventory

Map every place RSA, ECC, DH/ECDH, TLS, SSH, and signing dependencies actually live.

  • CBOM-style export
  • Algorithm classification
  • Asset-to-crypto mapping
  • Key lifetime tagging
03

Prioritize

Rank by data lifetime, exposure, algorithm, and migration difficulty so you fix the right things first.

  • Data-lifetime model
  • Exposure scoring
  • Business-impact weighting
  • Migration-difficulty score
04

Roadmap

Deliver a 30/60/90-day plan: quick wins, hybrid PQC candidates, and the right questions for your vendors.

  • 30/60/90-day plan
  • Hybrid PQC candidates
  • Vendor question pack
  • Crypto-agility guidance
pqc-radar discover --target acme-corp.examplesecure shell
# authorized external readiness scan
$pqc-radar discover --scope scope.yaml
resolving endpoints 1,284
pulling CT logs 312 certs
fingerprinting TLS & SSH done
!RSA-2048 · edge-gw-01internet
!ECDHE P-256 · api.paymentsinternet
!DH · vpn.gatewayinternet
!ECDSA · ssh.bastion-3internal
!RSA-4096 · vault.kms.rootinternal
~14 stores · 10y+ retentionflagged
inventory complete · 418 public-key assets
risk: ELEVATED · priority 72/100
$
CRYPTOGRAPHIC DEPENDENCY MAPdemo
INTERNET-FACINGINTERNAL SERVICESEdge GWTLSRSA-2048CDNhybridAPIECDHEVPNDHSSHECDSAAuthECDSAKMSRSA-4096ArchiveRSA-OAEP
Quantum-vulnerable (RSA · ECC · DH)Hybrid-PQC readyEdge gateway (scan origin)
FAQ

Straight answers, no hype.

The questions security leads, founders, and engineers actually ask.

No, not for normal systems at meaningful scale. The near-term risk is harvest-now-decrypt-later, and being ready to migrate before it is urgent.

RSA, elliptic-curve cryptography, Diffie-Hellman, ECDH, and ECDSA are the primary concern. Symmetric encryption like AES is affected differently and is usually handled with larger keys.

Crypto hides across TLS, certificates, APIs, SSH, VPNs, cloud, code dependencies, vendors, backups, and firmware. You cannot migrate what you cannot find.

It identifies your exposure and builds a migration roadmap. Actual migration depends on your systems, vendors, and protocols. We do not claim instant quantum-proofing.

A readable report with a crypto inventory, evidence-backed findings, prioritized risks, vendor questions where relevant, and a practical 30/60/90-day migration plan.

PQC standards are newer, vendor support is uneven, and PKI, signing, legacy systems, and larger keys need careful sequencing. Inventory first, then migrate the highest-risk paths.

Anyone with long-lived or regulated data, enterprise or government customers, or products with long deployment lifetimes.

Attackers can capture encrypted data now and decrypt it later. Large crypto migrations also take years to plan and execute.

Start with a readiness sprint.

Get a clear view of your RSA/ECC exposure and a practical 30/60/90-day roadmap.

Free 20-minute callLightweight external scanFull Readiness Sprint
Contact

Tell us what you want assessed.

A few details on your systems. We reply to scope a short call and confirm written authorization before anything is scanned.

Systems you want assessed

We confirm written authorization before any scanning.