Enterprise post-quantum readiness // regulated institutions

You can't migrate the cryptography you can't see.

PQCA discovers, inventories and quantum-risk-assesses the cryptography running across your entire estate, from TLS and SSH to OT/ICS, mainframe and data at rest, scoring each algorithm for quantum and classical risk, pricing that exposure in your own currency, and carrying the same evidence straight into a phased, budgeted migration plan.

Where discovery scanners and PKI suites stop at a findings list, PQCA closes the loop with a full GRC roadmap: live readiness scoring across 21 mandates and 78 controls (NIST, CNSA 2.0, EU DORA & CRA, PCI DSS 4.0, PCI PTS HSM, UK NCSC, ANSSI, BSI, ISO/IEC 18033-2, IETF TLS, CBJ, SAMA — whose circular binds Saudi financial institutions to a complete cryptographic inventory by 31 Dec 2026 and an institution-level quantum risk assessment by 31 Mar 2027 — and more), policy-as-code with automatic violation detection, per-control audit evidence, and an owner-assigned, budget-tracked migration plan that ties migration tasks to the assets and regulators behind them, the governance layer most quantum-readiness work still leaves to spreadsheets.

Entirely on-premise. One internet destination, and only if you want it — an optional, admin-triggered exchange-rate refresh you can skip by typing rates in by hand. For FIPS 140-3 specifically, PQCA tracks your plan to move onto CMVP-certified modules. It does not validate modules, and it is not a substitute for CMVP.

Live · nearest binding deadlineFIPS 140-2 modules → CMVP Historical List · 21 Sep 2026
Algorithms found
1,284
Quantum-vulnerable
312
Readiness
61%
Illustrative sample data — not live telemetry
Why now

The quantum threat isn't a someday problem. It's a today inventory problem.

A cryptographically-relevant quantum computer will unravel the RSA and elliptic-curve cryptography behind every banking transaction, government record and piece of critical infrastructure — and the attack has already started. Adversaries are harvesting encrypted data today to decrypt the day that machine arrives; for records a bank must keep secret for 10, 15, even 20 years, "later" is already inside the danger window. The fix is no longer optional — NIST has finalized the post-quantum standards (FIPS 203/204/205), and regulators from the NSA's CNSA 2.0 to the EU and central banks have set migration deadlines that start this year and run to 2035 — the EU CRA’s reporting obligations (Sep 2026), the FIPS 140-2 move to Historical (Sep 2026) and US agency migration plans due to OMB (Oct 2026) all land inside the next two months. Yet most institutions can't take the first step, because they can't answer the question every migration begins with: where is our cryptography, and what is it? It's scattered across TLS, SSH, databases, mainframes, OT and data at rest — undocumented, unowned, unmeasured. Without a living cryptographic inventory, there is nothing to migrate from. You cannot migrate what you cannot see.

Your cryptography is invisible

Most institutions have no cryptographic inventory. You can't answer "where are we quantum-vulnerable?" because no one has ever mapped it — the estate runs on a stale spreadsheet of assumptions.

Harvest-now, decrypt-later is running

Long-lived secrets — core-banking ledgers, cardholder data, health and government records — captured today are decrypted the day a cryptographically-relevant quantum computer arrives.

The deadlines are fixed, not hypothetical

FIPS 140-2 modules move to Historical in September 2026 — binding, not advisory. The EU Cyber Resilience Act’s main obligations apply from December 2027. NIST’s draft transition guidance disallows 112-bit security by 2035, and CNSA 2.0 requires exclusive post-quantum use for signing and networking by 2030. The planning window is measured in change cycles, not years.

Migration takes years, not quarters

Cryptography isn’t a setting you flip — it’s embedded in vendor products, HSMs, PKI hierarchies and OT devices with ten-to-twenty-year lifecycles, much of it waiting on someone else’s release roadmap. Subtract a realistic migration from a 2030 deadline and the start date is already behind you.

The clock is already running

Fixed deadlines, inside your planning horizon

PQCA tracks the mandates that create the demand as a live countdown — each tagged by legal weight, each bound to real migration progress. Draft and advisory dates are labeled as guidance, never dressed up as binding law. For FIPS 140-3 specifically, PQCA tracks your plan to move onto CMVP-certified modules. It does not validate modules, and it is not a substitute for CMVP.

EU CRA
Reporting obligations apply11 Sep 2026Binding · EU
FIPS 140-2 modules
Modules move to the CMVP Historical List21 Sep 2026Binding · US
OMB M-26-15
US agency PQC migration plans due22 Oct 2026Binding · US
SAMA · KSA
Cryptographic asset inventory and classification complete31 Dec 2026Binding · KSA
SAMA · KSA
Institution-level quantum risk assessment and work plans31 Mar 2027Binding · KSA
PCI PTS HSM
v4 new-device approvals end — v5 adds PQC30 Jun 2027Binding · Global
EU CRA
Cyber Resilience Act core obligations apply11 Dec 2027Binding · EU
CBJ · Jordan
First dated milestone on the sectoral PQC roadmap31 Dec 2027Guidance · JO
NIST IR 8547
112-bit security disallowed (deprecated 2030)31 Dec 2035Draft · Global

Dates reflect published standards and mandates as of 2026. PQCA's compliance engine retargets to the frameworks you answer to — NIST/NSA/EU alongside SAMA, the UAE, Kuwait’s CBK and the Central Bank of Jordan.

How it works

From a blind spot to a funded program — in one platform

Every quantum-readiness effort stalls in the same place: a scan hands you a list, and the list goes nowhere. Point scanners stop there. PKI and HSM suites see mostly certificates and keys — a slice of the estate, not the cryptography buried in TLS and SSH, OT and mainframes, databases and data at rest. PQCA takes the evidence it discovers and carries it the whole way: an evidence-based cryptographic inventory becomes a quantum- and classical-risk score, becomes an exposure priced in your own currency, becomes readiness mapped to every mandate you answer to — SAMA included — with per-control evidence, becomes an owner-assigned, budget-tracked migration roadmap the board can fund. No exporting between five tools, no reconciling four risk models, no spreadsheet in the middle — one tool, one risk model, one source of truth, from the first blind spot to the funded program that closes it.

Discover

Live evidence, not a spreadsheet. PQCA builds your inventory from the cryptography each service actually negotiates on the wire.

8 discovery channels · 114 probes per host

Assess

Every algorithm scored against classical and quantum attack; data shelf life weighed against your quantum horizon flags what's already exposed to HNDL.

70 algorithm families · operator-tunable

QRC-Budget

Quantum risk quantified per asset and org-wide, in your own currency — technical severity becomes a budget line.

10 currencies

Comply

Reported roadmap progress scored against 21 frameworks and 78 controls with per-control Met / Partial / Gap evidence and policy-as-code.

21 frameworks · 78 controls

Plan the migration

The same evidence flows into a phased, budgeted, owner-assigned roadmap — the estate you inventory is the estate you migrate.

Five-phase QRC plan
Discovery

Eight ways to find crypto — because one is never enough

No single method sees all of it, so PQCA runs eight. It probes live TLS, SSH and OT services for what they can negotiate; reads packet captures for what actually crossed the wire — passively, air-gapped, without touching a host; inspects files and data at rest for the ciphers protecting them; scans source code and configuration for the algorithms, library calls and keys baked in; and folds in imported records — HSM/KMS key lists, SBOMs and CBOMs, and the certificate registry your teams already keep; and stays in step with your asset inventory — pull sync from ServiceNow CMDB, NetBox, Qualys, Nessus and Active Directory, or a watched-folder CSV channel for air-gapped estates. It also asks every TLS endpoint what it would negotiate if offered post-quantum groups, and hears from lightweight endpoint sensors about the connections no scan can route to. Network and certificate discovery build one evidence-based Cryptographic Bill of Materials, scored by the same risk engine; code and file analysis catch the cryptography that never crosses the wire — so nothing in the estate stays dark. And the discovery is honest: an unreachable host is reported as unreachable, never silently counted as "clean."

Active network

114 probes per host on every default scan — 101 TCP ports plus 13 UDP probes (QUIC, IKEv2, WireGuard, ONVIF, DTLS and OpenVPN) — real handshakes across TLS, STARTTLS, SSH, database wire protocols, OT/ICS, mainframe, SMB, RDP and Kerberos, with full accepted-cipher-suite enumeration. Beyond the catalogue, a full TCP 1–65535 sweep and a bounded UDP sweep are available per host, and admins can add custom ports to the standing catalogue.

Passive PCAP

Parse a capture you already have for the crypto actually negotiated on the wire — read-only, in-memory, air-gap friendly. Nothing is stored.

Config & source

Heuristic static scan of source and infra config for hard-coded crypto, with purpose inference — TLS, backups, tokens, code-signing.

Encrypted files

Detect 28 encryption container formats — PEM and PKCS, LUKS, BitLocker, VeraCrypt/TrueCrypt, JKS and JCEKS, OpenPGP, Ansible Vault, Cryptomator, KeePass, SQLCipher, encrypted ZIP, 7-Zip, Office and PDF — by magic bytes, plus an entropy check that flags opaque ciphertext in any format we do not recognise. Only the first 1 MB and last 256 KB of a file is ever read, so multi-gigabyte volumes are classified without moving the payload.

Imported records

Ingest what you already hold — key lists from AWS KMS, Azure Key Vault, or any generic key list your HSM can export, supply-chain SBOMs and CBOMs, and your certificate registry — the authoritative record for the keys you hold, fully offline. PQCA grades an exported key list: there is no live connector holding credentials into your Luna, CloudHSM or Key Vault, and nothing from the list is persisted.

Inventory sync (CMDB)

Stays in step with the asset inventory you already keep — pull connectors for ServiceNow CMDB, NetBox/Nautobot, Qualys, Nessus and Active Directory, a watched-folder CSV channel for air-gapped estates, and scoped API keys for push automation. Existing asset records are never overwritten unless you opt in.

PQC readiness probe

Most tools tell you what a server uses today. PQCA asks what it would do: it sends a TLS 1.3 ClientHello advertising the IANA hybrid and pure ML-KEM groups and records what the server actually picks — hybrid, pure ML-KEM, or classical. That answer, not the current cipher, is what sequences a migration and puts pressure on a vendor.

Endpoint traffic sensor

A lightweight collector for Windows and Linux that finds the cryptography no network scan reaches: outbound connections from behind NAT, short-lived sessions, and hosts your scanner has no route to.

Reaches where IT-only tools stop: OT/ICS (Modbus, DNP3, S7, OPC UA), IoT (MQTT, RTSP/ONVIF), mainframe (TN3270E, IBM MQ) and data-at-rest via database fingerprinting — each with a migration advisory. See the discovery deep-dive →

Financial exposure

Price the risk your board can fund

Not every red badge is urgent. PQCA quantifies quantum risk per asset and org-wide — value(sensitivity) × risk factor × HNDL multiplier — in your own currency, so leadership can rank it and fund it. You set the impact anchors for each sensitivity tier, so the model reflects your business, not our assumptions. A technical scan becomes a board decision.

Estimates for prioritization, not actuarial values — computed on-premise. Prices in 10 currencies: USD and EUR alongside JOD, SAR, AED, KWD, OMR, BHD, IQD and SYP. Rates can be entered manually for air-gapped deployments, so pricing never requires an outbound call.

Compliance & frameworks

Evidence your position against the regulators you answer to

21 regulatory frameworks · 78 individually scored controls · 41 dated milestones on the live clock. Per-control Met / Partial / Gap evidence, with readiness scored from the migration-roadmap progress you report rather than from the mere existence of a scan — two exceptions, CNSA 2.0 suite conformance and hybrid-versus-pure key-exchange verdicts, are measured from what your services actually negotiated on the wire. Evidence leaves in nine formats: CycloneDX CBOM 1.7 and 1.6, OSCAL, STIX 2.1, SARIF 2.1.0, CEF, CSV, a per-section CSV bundle, portable policy-as-code JSON and board-ready PDF. Portable policy-as-code retargets the mapping to your own regulator.

US · FederalCNSA 2.0

Suite-conformance measured estate-wide, with CNSA 2.0’s 2027 support-and-prefer milestone and 2030 exclusive-use target tracked live, and hybrid-vs-pure verdicts per endpoint.

US · Federal civilianEO 14412 · OMB M-26-15

Key establishment quantum-safe by end-2030 and digital signatures by end-2031 across federal civilian agencies, with migration plans due to OMB by 22 Oct 2026 — a mandate that expressly excludes national-security systems, which stay on CNSA 2.0.

US · FederalNIST IR 8547 (draft)

RSA/ECC deprecation and 112-bit timelines bound to your migration phases, so transition guidance maps to what you have actually moved.

Canada · Federal & financialCCCS · Treasury Board SPIN · OSFI

CCCS ITSM.40.001 guidance, the mandatory Treasury Board SPIN milestones (2026 / 2031 / 2035) and OSFI’s 2035 quantum-readiness expectations for federally regulated financial institutions, scored natively.

Global · PaymentsPCI DSS 4.0

Req. 12.3.x cryptographic-inventory obligations satisfied with a machine-readable CBOM in the CycloneDX standard auditors already work with, plus keyed-material and cert hygiene findings. PTS HSM v5 — the first with post-quantum requirements — is tracked from the June 2027 v4 approval sunset.

EU · FinancialEU DORA

ICT and cryptographic-resilience evidence for financial entities, exportable as OSCAL for your regulator's examination.

KSA · FinancialSAMA (Saudi Central Bank)

SAMA’s post-quantum circular tracked as a first-class framework — cryptographic asset inventory and classification complete by 31 Dec 2026, institution-level quantum risk assessment and work plans by 31 Mar 2027, both binding and both on the live clock. PQCA produces the cryptographic inventory, classification, migration plan and board reporting the circular requires, scored on your own attested progress.

MENA · GulfSaudi NCA · UAE National Encryption Policy · CBK

Regional frameworks scored natively, not force-fit into a US framework — scoped per jurisdiction, with local-currency reporting. Saudi NCA is scored as general cryptographic-hygiene controls: NCA has published no post-quantum mandate, and Saudi Arabia’s dated PQC milestones are SAMA’s.

MENA · JordanCentral Bank of Jordan

The CBJ sectoral roadmap tracked as a first-class framework — dated milestones on the live clock through 2035, cited source, local-currency reporting. Mapped from CBJ’s published roadmap; not an audited alignment.

Migration roadmap

Discovery is only the first half

The same evidence flows into a five-phase, budgeted, owner-assigned QRC program with dates, cost and an auditable trail — suggested owners per phase, budget tracked as cost, paid and remaining. A fresh install opens with an 18-item kickoff checklist, so you start with a plan rather than a blank page. The estate you inventory is the estate you migrate.

Phase 01

Preparation

Set crypto-agility policy, roles and scope; stand up the sovereign deployment inside your perimeter.

Owner · Governance
Phase 02

Discovery

Run the eight channels; build the CBOM; score risk and price exposure across the estate.

Owner · Crypto/PKI
Phase 03

Pilot

Validate quantum-safe crypto in the mode your regulator requires — hybrid or pure — on a bounded slice.

Owner · Engineering
Phase 04

Adoption & migration

Your teams work the per-finding remediation playbooks with owners, dates and budget KPIs — PQCA supplies the plan and the evidence, never applies a change.

Owner · Infrastructure
Phase 05

Validation

Re-scan, diff the CBOM, and evidence readiness against the frameworks and deadlines you answer to.

Owner · GRC
Why PQCA

Why security teams choose PQCA

PQCA runs the whole post-quantum program on one risk model and one source of truth — discover → assess → QRC-Budget → comply → roadmap — deployed at enterprise scale on your own hardware, sovereign and air-gap-ready, and built for regulated banks, government, and critical infrastructure.

Eight discovery channels, one inventory

Real handshakes on the wire, passive analysis of PCAP files you supply, source-and-config code scanning, encrypted-file-at-rest analysis, certificate and key-list import, inventory sync from your CMDB, a PQC readiness probe that asks each TLS endpoint what it would negotiate, and endpoint sensors that report the connections no scan can route to — eight channels, one estate: network, certificate and CMDB discovery build the inventory, and code and file analysis catch what never crosses the wire — so nothing in the estate stays dark.

OT, IoT, and mainframe in reach

Dedicated probes cover Modbus, DNP3, S7comm, EtherNet/IP, BACnet, OPC UA, MQTT and CoAP — plus IP-camera RTSP/ONVIF and mainframe TN3270E and IBM MQ — the 10-to-20-year-lifecycle assets generic scanners miss. A 70-family algorithm knowledge base — every rating operator-tunable, though the list itself is fixed: an in-house or national algorithm outside the shipped 70 cannot be added — behind 114 probes per host maps every finding to a named migration recommendation, not a bare "unknown."

Quantum and classical, one score

Every observation is scored on two independent axes — Shor-era quantum status and classical hygiene — then collapsed to a single 0–100 risk score and a five-level severity band. Key-size escalation means a 1024-bit RSA key is reported broken, not laundered into "ok" by a family default.

HNDL grounded in Mosca's inequality

Harvest-now-decrypt-later exposure is computed per asset from data retention versus a calendar-anchored quantum horizon, so migration deadlines actually come due instead of forever receding. Un-curated assets surface as a data-quality gap, never a false clean bill of health.

Exposure priced in your currency

A transparent model whose impact anchors you set turns technical risk into money, so leadership prioritizes in dollars, or dinar. Figures display in any of 10 currencies, 8 of them MENA — no outbound call required.

Every mandate, one readiness number

Your reported roadmap progress is scored against 21 frameworks and 78 individually scored controls — CNSA 2.0, NIST IR 8547, FIPS 140-3 / CMVP module transition (tracking), PCI DSS 4.0, PCI PTS HSM, DORA, the EU CRA, UK NCSC, BSI, ANSSI, CCCS, ASD, ISO/IEC 18033-2 and IETF TLS, plus the MENA regulators (SAMA, CBJ, CBK, the UAE — and Saudi NCA’s general cryptographic-hygiene controls) scored natively rather than force-fit into a US framework — into one number, with per-control met / partial / gap evidence. For FIPS 140-3 specifically, PQCA tracks your plan to move onto CMVP-certified modules. It does not validate modules, and it is not a substitute for CMVP.

Deployment-aware verdicts

Because ANSSI, BSI, ASD, and CNSA 2.0 disagree on hybrid versus pure PQC, PQCA judges every negotiated key exchange against each of the four that applies to you — so "we deployed ML-KEM" gets the right answer for each jurisdiction, not a hopeful one.

Policy-as-code, no policy engine

Start with a sentence — banned and approved families with minimum key sizes like RSA<3072 — and graduate to a portable, schema-validated JSON policy with a tiered ladder and first-match-wins rules. Violations are detected against the live estate with no false positives on unknown key sizes, and sunset dates tighten the policy automatically as deadlines pass.

Five phases, standards-aligned

A fixed, ordered roadmap aligned to the CBJ sectoral roadmap and NIST migration guidance, with admin-editable timeline windows. A fresh install seeds an 18-item kickoff checklist, so you begin with a plan, not a blank page.

Discovery to backlog in one click

Generate-from-inventory turns every quantum-vulnerable asset, certificate, and application into an owned, dated, priority-ranked task — deduplicated and linked to the exact item it migrates. The same estate the platform scanned becomes the plan the team works.

QRC-Budget, rolled up by phase

Every action item tracks cost, paid, and computed remaining, aggregated per phase and across the whole program in your display currency. A CISO sees committed-versus-paid-versus-still-needed at a glance, with server-side guards that keep the figures internally consistent.

Readiness that tracks real work

Compliance readiness is computed from the roadmap itself — each control is bound to a phase and scored by that phase's real completion, not by whether a scan happened. Applying a framework seeds its unmet obligations into the backlog at 0%, so nothing you haven't done can score as done.

Built for enterprise scale

PQCA is production software for large, regulated environments — not a pilot tool or a consultant's script. It runs across segmented networks, data centers and OT plants; Active Directory groups map to administrator and read-only access. PQCA ships four user roles in total — Administrator, Checker, Maker and Read Only: Maker and Checker provide a maker-checker (four-eyes) control over governed changes and are assigned in the platform after directory import, and unattended integrations use separate service-account keys with least-privilege roles — importer, sensor and federation — each confined to a single endpoint. Every scan, score, export and decision is written to an audit trail the application only ever appends to, with the acting user, the timestamp and the before-and-after state; it is not hash-chained, and a full platform restore replaces it, so forward it to your SIEM if you need tamper-evidence held outside the platform. Deploy per region or per subsidiary, each instance sovereign to its own jurisdiction and data-residency rules — on hardware you already own, integrated with the directory and SIEM you already run.

One internet destination, and only if you want it

PQCA’s only vendor-chosen outbound call is an optional exchange-rate refresh — triggered by an admin, never on a timer, and skippable entirely by typing rates by hand. Ten offline fallback rates ship, so currency conversion works with the cable out.

Every other connection PQCA makes goes only to a host you configure on your own network, and none is contacted until you enable it: ticketing and chat (ServiceNow, Jira, Slack or a generic webhook), scheduled inventory pulls from your CMDB, Master-to-subsidiary federation reads, your SMTP relay, your SIEM over syslog/CEF, and your Active Directory. Once enabled, several of those run on a schedule without an operator present.

The web console itself loads nothing from the internet — no CDN, no fonts, no analytics. One codebase installs four ways — Docker, an offline Docker bundle, native Windows, or native Ubuntu — and three of the four run on networks with no internet at all.

One group, every entity

A Master PQCA links each subsidiary, reads its posture on a schedule and reports the group side by side — group exposure, mean readiness, the weakest entity and the soonest mandate — while every subsidiary’s data stays in its own install. Built for banking groups and regional holdings with several licensed entities: a subsidiary is read live from its own PQCA, or from a CBOM it uploads. Licensed per number of linked subsidiaries. This is federation — many separate installs reporting upward to a parent — not multi-tenant isolation inside one install.

The numbers behind the coverage

Verifiable, concrete figures — the surface PQCA actually probes, scores and reports.

8
Discovery channels
114
Probes per host — 101 TCP + 13 UDP
70
Algorithm families — operator-tunable, one save re-scores the estate
21
Regulatory frameworks · 78 scored controls
10
Reporting currencies
1
Optional internet destination — the FX refresh, admin-triggered, skippable

See your own crypto estate scored — on-prem, on a call.

Bring a subnet or a packet capture. In 30 minutes you'll see real findings, real risk, and a real roadmap draft. No cloud sign-up, no data leaves your environment.