Skip to main content
Cryptographic inventory

Know where vulnerable cryptography lives before a deadline asks

Every post-quantum roadmap starts with an inventory. QuantumLock takes the cryptographic bill of materials your tools already produce, evaluates it against a versioned policy, and returns a decision you can reproduce for an auditor.

Format
CycloneDX 1.6 CBOM
Policy
softquantus-pqc-baseline 1.0.0
Decision
Pass, review or fail

The problem

You cannot migrate what you cannot see

Cryptography sits in libraries, certificates, protocols and keys spread across teams. Discovery tools can list it; what most organisations lack is a consistent, repeatable judgement of what is acceptable and what must move.

  • One policy for every team

    Every inventory is judged by the same versioned policy pack, identified by its own content hash.

  • Honest about gaps

    When an asset does not state its quantum security level, the finding says unknown, not vulnerable.

  • Reproducible for auditors

    The same CBOM evaluated against the same pack version gives the same decision id.

Fig. 02 · Policy decision: Audit trail · 90-day window

How it works

From CBOM to decision

  1. 01

    Export

    Produce a CycloneDX 1.6 CBOM with the discovery and build tools you already use.

  2. 02

    Import

    QuantumLock validates it against closed allow-lists, canonicalises and hashes it. Importing the same CBOM twice gives one record, not two.

  3. 03

    Evaluate

    The CBOM is evaluated against the softquantus-pqc-baseline pack. Each finding has a severity from critical to info.

  4. 04

    Decide

    The result is pass, review or fail, with a decision id derived by SHA-256. Decisions are listed so you can track progress over time.

What the policy checks

Six rule kinds, stated in the open

Quantum-vulnerable primitives

Flags algorithms that a quantum computer could break, such as RSA and elliptic-curve schemes.

Missing quantum level

Reports an asset without a stated quantum security level as unknown, so a gap is never mistaken for a pass.

Minimum NIST quantum level

Requires a minimum NIST post-quantum security category where one is stated.

Minimum classical level

Requires a minimum classical security strength, so a post-quantum move does not weaken today's protection.

Banned algorithms

Fails algorithms your policy no longer allows at all.

Unevaluated asset types

Names the asset types the pack does not evaluate, so a pass never silently covers certificates, protocols or key material.

Questions

Inventory questions buyers ask first

Does QuantumLock scan our systems?

No. QuantumLock does not scan networks or code. It evaluates the CBOM your own tools produce, so discovery stays with the tools and teams you already trust.

Why CycloneDX?

CycloneDX 1.6 defines a cryptographic bill of materials as an open standard, so your inventory is not locked to one vendor.

What does unknown mean?

The asset did not state a quantum security level. QuantumLock reports that it cannot judge it rather than guessing it is vulnerable or safe.

Does a pass cover our certificates and keys?

Only for the asset types the pack evaluates. Anything else is listed as unevaluated in the same decision, so the scope of a pass is always written down.

Can an auditor reproduce a decision?

Yes. The decision id is a SHA-256 hash, and evaluating the same CBOM against the same pack version gives the same id.

Bring one CBOM

Send us an inventory from one system and we will walk through the decision it produces, finding by finding.