Long-lived data can be captured now
Legal, financial, health and intellectual-property data can be collected today and targeted for decryption in the future.
For product-security teams that need to find where one critical product depends on classical cryptography — before planning a PQC migration. Start with a controlled, local assessment; no source-code upload required.
Scope
one approved product
2
representative repos
3
approved TLS endpoints
1
certificate export
Illustrative inventory view — not a live customer scan
EU roadmap: planning and pilots begin
High-risk use cases targeted
Medium-risk use cases targeted
Coordinated roadmap for EU Member States; company obligations depend on sector and applicable regulation.
The business problem
PQC migration touches identity, certificates, vendors, archives, products and procurement. Without a current inventory, leadership cannot see cost, ownership or sequencing.
Legal, financial, health and intellectual-property data can be collected today and targeted for decryption in the future.
Critical systems, embedded devices, trust chains and vendor dependencies cannot be replaced in one maintenance window.
Cryptography is spread across certificates, code, cloud services, hardware and third parties — often without a clear owner.
It is not knowing which business processes depend on vulnerable cryptography, how long their data must remain protected, and who can change them.
Evidence, not hype
The deadlines are becoming concrete, the standards are published and platform providers have multi-year programs underway.
DORA · EU 2024/1774
DORA itself does not name post-quantum cryptography. Its supporting Delegated Regulation (EU) 2024/1774 requires a policy on encryption and cryptographic controls, provisions to update cryptographic technology as cryptanalysis evolves, and a current register of certificates and certificate-storing devices for critical or important functions.
Articles 6 and 7. This is not PQC certification; it does make an unknown or stale cryptographic inventory a governance problem today.
From uncertainty to a decision
PQC Radar turns scattered cryptographic signals into a prioritized business view your security, risk, architecture and procurement teams can act on.
A defensible starting map of algorithms, certificates, protocols, libraries and critical dependencies.
Know what exists, where it sits and who owns it.
Exposure ranked by data lifetime, business criticality, external reach and migration difficulty.
Fund the work that reduces the most risk first.
Clear decisions, owners, vendor questions, quick wins and validation steps for the next quarter.
Move from awareness to governed execution.
Data boundary
A typical scope can include two representative repositories, approved TLS endpoints, a certificate export and one signing or update workflow. Analysis runs locally; source code is not uploaded. Evidence is redacted and validated with product owners.
PQC Readiness Sprint
In two weeks, we establish the initial evidence base, align stakeholders and produce an executive-ready migration plan — without pretending it is a complete cryptographic audit.
Typical fixed-scope pilot: €6,000–€12,000 excl. VAT, confirmed after scoping.
Start with your highest-risk question
Tell us what is driving the conversation — regulation, customer pressure, long-lived data or an unknown inventory. We will reply with a practical next step.
info@pqc-radar.com