Know where vulnerable cryptography lives before a deadline asks
Every post-quantum roadmap starts with an inventory. QuantumLock takes the cryptographic bill of materials your tools already produce, evaluates it against a versioned policy, and returns a decision you can reproduce for an auditor.
- Format
- CycloneDX 1.6 CBOM
- Policy
- softquantus-pqc-baseline 1.0.0
- Decision
- Pass, review or fail
The problem
You cannot migrate what you cannot see
Cryptography sits in libraries, certificates, protocols and keys spread across teams. Discovery tools can list it; what most organisations lack is a consistent, repeatable judgement of what is acceptable and what must move.
One policy for every team
Every inventory is judged by the same versioned policy pack, identified by its own content hash.
Honest about gaps
When an asset does not state its quantum security level, the finding says unknown, not vulnerable.
Reproducible for auditors
The same CBOM evaluated against the same pack version gives the same decision id.
How it works
From CBOM to decision
- 01
Export
Produce a CycloneDX 1.6 CBOM with the discovery and build tools you already use.
- 02
Import
QuantumLock validates it against closed allow-lists, canonicalises and hashes it. Importing the same CBOM twice gives one record, not two.
- 03
Evaluate
The CBOM is evaluated against the softquantus-pqc-baseline pack. Each finding has a severity from critical to info.
- 04
Decide
The result is pass, review or fail, with a decision id derived by SHA-256. Decisions are listed so you can track progress over time.
What the policy checks
Six rule kinds, stated in the open
Quantum-vulnerable primitives
Flags algorithms that a quantum computer could break, such as RSA and elliptic-curve schemes.
Missing quantum level
Reports an asset without a stated quantum security level as unknown, so a gap is never mistaken for a pass.
Minimum NIST quantum level
Requires a minimum NIST post-quantum security category where one is stated.
Minimum classical level
Requires a minimum classical security strength, so a post-quantum move does not weaken today's protection.
Banned algorithms
Fails algorithms your policy no longer allows at all.
Unevaluated asset types
Names the asset types the pack does not evaluate, so a pass never silently covers certificates, protocols or key material.
Questions
Inventory questions buyers ask first
Does QuantumLock scan our systems?
No. QuantumLock does not scan networks or code. It evaluates the CBOM your own tools produce, so discovery stays with the tools and teams you already trust.
Why CycloneDX?
CycloneDX 1.6 defines a cryptographic bill of materials as an open standard, so your inventory is not locked to one vendor.
What does unknown mean?
The asset did not state a quantum security level. QuantumLock reports that it cannot judge it rather than guessing it is vulnerable or safe.
Does a pass cover our certificates and keys?
Only for the asset types the pack evaluates. Anything else is listed as unevaluated in the same decision, so the scope of a pass is always written down.
Can an auditor reproduce a decision?
Yes. The decision id is a SHA-256 hash, and evaluating the same CBOM against the same pack version gives the same id.
Further reading
Standards and related pages
Bring one CBOM
Send us an inventory from one system and we will walk through the decision it produces, finding by finding.