Skip to content
The migration clock is already running

Your data may outlive the cryptography protecting it.

For product-security teams that need to find where one critical product depends on classical cryptography — before planning a PQC migration. Start with a controlled, local assessment; no source-code upload required.

Cryptographic inventoryIllustrative data

Scope

one approved product

Owner-validated findings

2

representative repos

3

approved TLS endpoints

1

certificate export

AssetCryptoStatus
Release signingRSA-2048Confirmed
Product backendECDSA P-256Owner review
Device identityVendor managedVendor question

Illustrative inventory view — not a live customer scan

2026

EU roadmap: planning and pilots begin

2030

High-risk use cases targeted

2035

Medium-risk use cases targeted

Coordinated roadmap for EU Member States; company obligations depend on sector and applicable regulation.

ML-DSA (FIPS 204)RSA-2048RSA-4096ECDHE P-256X25519ECDSAEd25519ML-KEM (FIPS 203)SLH-DSA (FIPS 205)X.509 / PKI

The business problem

Waiting for a confirmed cryptographic breakthrough leaves no migration window.

PQC migration touches identity, certificates, vendors, archives, products and procurement. Without a current inventory, leadership cannot see cost, ownership or sequencing.

01

Long-lived data can be captured now

Legal, financial, health and intellectual-property data can be collected today and targeted for decryption in the future.

02

Migration takes years

Critical systems, embedded devices, trust chains and vendor dependencies cannot be replaced in one maintenance window.

03

Inventories are often fragmented

Cryptography is spread across certificates, code, cloud services, hardware and third parties — often without a clear owner.

The dangerous gap is not a missing algorithm.

It is not knowing which business processes depend on vulnerable cryptography, how long their data must remain protected, and who can change them.

Evidence, not hype

Governments, standards bodies and technology leaders are already acting.

The deadlines are becoming concrete, the standards are published and platform providers have multi-year programs underway.

DORA · EU 2024/1774

For financial entities in scope of DORA, cryptographic governance is already an explicit control obligation.

DORA itself does not name post-quantum cryptography. Its supporting Delegated Regulation (EU) 2024/1774 requires a policy on encryption and cryptographic controls, provisions to update cryptographic technology as cryptanalysis evolves, and a current register of certificates and certificate-storing devices for critical or important functions.

Articles 6 and 7. This is not PQC certification; it does make an unknown or stale cryptographic inventory a governance problem today.

From uncertainty to a decision

Give leadership a roadmap, not another technical backlog.

PQC Radar turns scattered cryptographic signals into a prioritized business view your security, risk, architecture and procurement teams can act on.

0101

Cryptographic inventory

A defensible starting map of algorithms, certificates, protocols, libraries and critical dependencies.

Know what exists, where it sits and who owns it.

0202

Prioritized business risk

Exposure ranked by data lifetime, business criticality, external reach and migration difficulty.

Fund the work that reduces the most risk first.

0303

30 / 60 / 90-day roadmap

Clear decisions, owners, vendor questions, quick wins and validation steps for the next quarter.

Move from awareness to governed execution.

Data boundary

One approved product. Controlled data boundary.

A typical scope can include two representative repositories, approved TLS endpoints, a certificate export and one signing or update workflow. Analysis runs locally; source code is not uploaded. Evidence is redacted and validated with product owners.

  • No private keys or tokens in outputs
  • Heuristic discovery, clearly marked for validation
  • Not a penetration test, CVE scan or certification

PQC Readiness Sprint

A focused first step for enterprise teams.

In two weeks, we establish the initial evidence base, align stakeholders and produce an executive-ready migration plan — without pretending it is a complete cryptographic audit.

Typical fixed-scope pilot: €6,000–€12,000 excl. VAT, confirmed after scoping.

  • Leadership and technical scoping
  • Initial discovery and inventory
  • Business-risk prioritization
  • Executive report, CBOM-style export and 30/60/90 plan

Start with your highest-risk question

Find out where your migration should begin.

Tell us what is driving the conversation — regulation, customer pressure, long-lived data or an unknown inventory. We will reply with a practical next step.

info@pqc-radar.com

We use these details only to answer your enquiry and retain correspondence only as long as needed for that purpose. Delivery is processed by Resend. No marketing analytics or profiling is used.

Cloudflare Turnstile processes limited technical data to prevent automated abuse.