Enterprise post-quantum readiness // regulated institutions

You can't migrate the cryptography you can't see.

PQCA discovers, inventories and quantum-risk-assesses the cryptography running across your entire estate, from TLS and SSH to OT/ICS, mainframe and data at rest, scoring each algorithm for quantum and classical risk, pricing that exposure in your own currency, and carrying the same evidence straight into a phased, budgeted migration plan.

Where discovery scanners and PKI suites stop at a findings list, PQCA closes the loop with a full GRC roadmap: live readiness scoring across 19 global mandates (NIST, CNSA 2.0, EU DORA & CRA, PCI DSS, ANSSI, BSI, CBJ, Saudi NCA, UAE and more), policy-as-code with automatic violation detection, per-control audit evidence, and an owner-assigned, budget-tracked migration plan that ties migration tasks to the assets and regulators behind them, the governance layer most quantum-readiness work still leaves to spreadsheets.

Benchmarked against the market’s leading PQC discovery platforms, ask for the competitive brief. Entirely on-premise. Zero outbound calls, beyond one optional currency refresh you can turn off.

Live · nearest binding deadlineFIPS 140-2 validated modules → Historical · 21 Sep 2026
Algorithms found
1,284
Quantum-vulnerable
312
Readiness
61%
Illustrative sample data — not live telemetry
Why now

The quantum threat isn't a someday problem. It's a today inventory problem.

A cryptographically-relevant quantum computer will unravel the RSA and elliptic-curve cryptography behind every banking transaction, government record and piece of critical infrastructure — and the attack has already started. Adversaries are harvesting encrypted data today to decrypt the day that machine arrives; for records a bank must keep secret for 10, 15, even 20 years, "later" is already inside the danger window. The fix is no longer optional — NIST has finalized the post-quantum standards (FIPS 203/204/205), and regulators from the NSA's CNSA 2.0 to the EU and central banks have set migration deadlines between 2030 and 2035. Yet most institutions can't take the first step, because they can't answer the question every migration begins with: where is our cryptography, and what is it? It's scattered across TLS, SSH, databases, mainframes, OT and data at rest — undocumented, unowned, unmeasured. Without a living cryptographic inventory, there is nothing to migrate from. You cannot migrate what you cannot see.

Your cryptography is invisible

Most institutions have no cryptographic inventory. You can't answer "where are we quantum-vulnerable?" because no one has ever mapped it — the estate runs on a stale spreadsheet of assumptions.

Harvest-now, decrypt-later is running

Long-lived secrets — core-banking ledgers, cardholder data, health and government records — captured today are decrypted the day a cryptographically-relevant quantum computer arrives.

The deadlines are fixed, not hypothetical

FIPS 140-2 modules move to Historical in September 2026 — binding, not advisory. The EU Cyber Resilience Act’s main obligations apply from December 2027. NIST’s draft transition guidance disallows 112-bit security by 2035, and CNSA 2.0 requires exclusive post-quantum use for signing and networking by 2030. The planning window is measured in change cycles, not years.

Migration takes years, not quarters

Cryptography isn’t a setting you flip — it’s embedded in vendor products, HSMs, PKI hierarchies and OT devices with ten-to-twenty-year lifecycles, much of it waiting on someone else’s release roadmap. Subtract a realistic migration from a 2030 deadline and the start date is already behind you.

The clock is already running

Fixed deadlines, inside your planning horizon

PQCA tracks the mandates that create the demand as a live countdown — each tagged by legal weight, each bound to real migration progress. Draft and advisory dates are labeled as guidance, never dressed up as binding law.

EU CRA
Reporting obligations apply11 Sep 2026Binding · EU
FIPS 140-2 modules
Legacy validated modules move to Historical21 Sep 2026Binding · US
OMB M-26-15
US agency PQC migration plans due22 Oct 2026Binding · US
PCI PTS HSM
v4 new-device approvals end — v5 adds PQC30 Jun 2027Industry · Global
EU CRA
Cyber Resilience Act core obligations apply11 Dec 2027Binding · EU
CBJ · Jordan
Central Bank of Jordan — first dated milestone on the sectoral PQC roadmap31 Dec 2027Guidance · JO
NIST IR 8547
112-bit security disallowed (deprecated 2030)31 Dec 2035Draft · Global

Dates reflect published standards and mandates as of 2026. PQCA's compliance engine retargets to the frameworks you answer to — NIST/NSA/EU alongside the UAE, Saudi NCA, Kuwait’s CBK and the Central Bank of Jordan.

How it works

From a blind spot to a funded program — in one platform

Every quantum-readiness effort stalls in the same place: a scan hands you a list, and the list goes nowhere. Point scanners stop there. PKI and HSM suites see mostly certificates and keys — a slice of the estate, not the cryptography buried in TLS and SSH, OT and mainframes, databases and data at rest. PQCA takes the evidence it discovers and carries it the whole way: an evidence-based cryptographic inventory becomes a quantum- and classical-risk score, becomes an exposure priced in your own currency, becomes readiness mapped to 19 mandates with per-control evidence, becomes an owner-assigned, budget-tracked migration roadmap the board can fund. No exporting between five tools, no reconciling four risk models, no spreadsheet in the middle — one tool, one risk model, one source of truth, from the first blind spot to the funded program that closes it.

Discover

Live evidence, not a spreadsheet. PQCA builds your inventory from the cryptography each service actually negotiates on the wire.

5 discovery channels · 77 ports

Assess

Every algorithm scored against classical and quantum attack; data shelf life weighed against your quantum horizon flags what's already exposed to HNDL.

70 algorithm families

QRC-Budget

Quantum risk quantified per asset and org-wide, in your own currency — technical severity becomes a budget line.

10 currencies

Comply

Live readiness scored against 19 frameworks with per-control Met / Partial / Gap evidence and policy-as-code.

19 frameworks

Plan the migration

The same evidence flows into a phased, budgeted, owner-assigned roadmap — the estate you inventory is the estate you migrate.

Five-phase QRC plan
Discovery

Five ways to find crypto — because one is never enough

No single method sees all of it, so PQCA runs five. It probes live TLS, SSH and OT services for what they can negotiate; reads packet captures for what actually crossed the wire — passively, air-gapped, without touching a host; inspects files and data at rest for the ciphers protecting them; scans source code and configuration for the algorithms, library calls and keys baked in; and folds in imported records — HSM/KMS key lists, SBOMs and CBOMs, and the certificate registry your teams already keep. Network and certificate discovery build one evidence-based Cryptographic Bill of Materials, scored by the same risk engine; code and file analysis catch the cryptography that never crosses the wire — so nothing in the estate stays dark. And the discovery is honest: an unreachable host is reported as unreachable, never silently counted as "clean."

Active network

Real handshakes — TLS, STARTTLS, SSH, database wire protocols, OT/ICS, mainframe, SMB, RDP, Kerberos, plus UDP probes for QUIC, IKEv2, WireGuard and ONVIF — 77 default ports (72 TCP + 5 UDP), with full accepted-cipher-suite enumeration.

Passive PCAP

Parse a capture you already have for the crypto actually negotiated on the wire — read-only, in-memory, air-gap friendly. Nothing is stored.

Config & source

Heuristic static scan of source and infra config for hard-coded crypto, with purpose inference — TLS, backups, tokens, code-signing.

Encrypted files

Detect ~30 container formats — PEM/PKCS, LUKS, BitLocker, VeraCrypt, JKS, PGP, Vault — by magic bytes. Multi-GB files never move.

Imported records

Ingest what you already hold — key lists from AWS KMS, Azure Key Vault or PKCS#11 / HSM, supply-chain SBOMs and CBOMs, and your certificate registry — the authoritative record for the keys you hold, fully offline.

Reaches where IT-only tools stop: OT/ICS (Modbus, DNP3, S7, OPC UA), IoT (MQTT, RTSP/ONVIF), mainframe (TN3270E, IBM MQ) and data-at-rest via database fingerprinting — each with a migration advisory. See the discovery deep-dive →

Financial exposure

Price the risk your board can fund

Not every red badge is urgent. PQCA quantifies quantum risk per asset and org-wide — value(sensitivity) × risk factor × HNDL multiplier — in your own currency, so leadership can rank it and fund it. You set the impact anchors for each sensitivity tier, so the model reflects your business, not our assumptions. A technical scan becomes a board decision.

Estimates for prioritization, not actuarial values — computed on-premise. Prices in 10 currencies: USD and EUR alongside JOD, SAR, AED, KWD, OMR, BHD, IQD and SYP. Rates can be entered manually for air-gapped deployments, so pricing never requires an outbound call.

Compliance & frameworks

Prove control against the regulators you answer to

Per-control Met / Partial / Gap evidence across 19 global frameworks, each control bound to real roadmap progress — not just proof that a scan ran. Portable policy-as-code retargets the mapping to your own regulator.

US · FederalCNSA 2.0

Suite-conformance measured estate-wide, with CNSA 2.0’s 2027 support-and-prefer milestone and 2030 exclusive-use target tracked live, and hybrid-vs-pure verdicts per endpoint.

US · Federal civilianEO 14412 · OMB M-26-15

Key establishment quantum-safe by end-2030 and digital signatures by end-2031 across federal civilian agencies, with migration plans due to OMB by 22 Oct 2026 — a mandate that expressly excludes national-security systems, which stay on CNSA 2.0.

US · FederalNIST IR 8547 (draft)

RSA/ECC deprecation and 112-bit timelines bound to your migration phases, so transition guidance maps to what you have actually moved.

Canada · Federal & financialTreasury Board SPIN · OSFI

The mandatory Treasury Board SPIN milestones (2026 / 2031 / 2035) and OSFI’s 2035 quantum-readiness expectations for federally regulated financial institutions, scored natively.

Global · PaymentsPCI DSS 4.0

Req. 12.3.x cryptographic-inventory obligations satisfied with a machine-readable CBOM in the CycloneDX standard auditors already work with, plus keyed-material and cert hygiene findings. PTS HSM v5 — the first with post-quantum requirements — is tracked from the June 2027 v4 approval sunset.

EU · FinancialEU DORA

ICT and cryptographic-resilience evidence for financial entities, exportable as OSCAL for your regulator's examination.

MENA · GulfUAE · Saudi NCA · CBK

Regional mandates scored natively, not force-fit into a US framework — scoped per jurisdiction, with local-currency reporting.

MENA · JordanCentral Bank of Jordan

The CBJ sectoral roadmap tracked as a first-class framework — dated milestones on the live clock through 2035, cited source, local-currency reporting. Mapped from CBJ’s published roadmap; not an audited alignment.

Migration roadmap

Discovery is only the first half

The same evidence flows into a five-phase, budgeted, owner-assigned QRC program with dates, cost and an auditable trail — suggested owners per phase, budget tracked as cost, paid and remaining. A fresh install opens with an 18-item kickoff checklist, so you start with a plan rather than a blank page. The estate you inventory is the estate you migrate.

Phase 01

Preparation

Set crypto-agility policy, roles and scope; stand up the sovereign deployment inside your perimeter.

Owner · Governance
Phase 02

Discovery

Run the five channels; build the CBOM; score risk and price exposure across the estate.

Owner · Crypto/PKI
Phase 03

Pilot

Validate quantum-safe crypto in the mode your regulator requires — hybrid or pure — on a bounded slice.

Owner · Engineering
Phase 04

Adoption & migration

Your teams work the per-finding remediation playbooks with owners, dates and budget KPIs — PQCA supplies the plan and the evidence, never applies a change.

Owner · Infrastructure
Phase 05

Validation

Re-scan, diff the CBOM, and evidence readiness against the frameworks and deadlines you answer to.

Owner · GRC
Why PQCA

Why security teams choose PQCA

PQCA runs the whole post-quantum program on one risk model and one source of truth — discover → assess → QRC-Budget → comply → roadmap — deployed at enterprise scale on your own hardware, sovereign and air-gap-ready, and built for regulated banks, government, and critical infrastructure.

Five discovery channels, one inventory

Active network scanning, passive PCAP capture, encrypted-file-at-rest analysis, source-and-config code scanning, and X.509/CBOM import work one estate: network and certificate discovery build the inventory, and code and file analysis catch what never crosses the wire — so nothing in the estate stays dark.

OT, IoT, and mainframe in reach

Dedicated probes cover Modbus, DNP3, S7comm, EtherNet/IP, BACnet, OPC UA, MQTT and CoAP — plus IP-camera RTSP/ONVIF and mainframe TN3270E and IBM MQ — the 10-to-20-year-lifecycle assets generic scanners miss. A 70-family algorithm knowledge base across 77 default ports maps every finding to a named migration recommendation, not a bare "unknown."

Quantum and classical, one score

Every observation is scored on two independent axes — Shor-era quantum status and classical hygiene — then collapsed to a single 0–100 risk score and a five-level severity band. Key-size escalation means a 1024-bit RSA key is reported broken, not laundered into "ok" by a family default.

HNDL grounded in Mosca's inequality

Harvest-now-decrypt-later exposure is computed per asset from data retention versus a calendar-anchored quantum horizon, so migration deadlines actually come due instead of forever receding. Un-curated assets surface as a data-quality gap, never a false clean bill of health.

Exposure priced in your currency

A transparent model whose impact anchors you set turns technical risk into money, so leadership prioritizes in dollars, or dinar. Figures display in any of 10 currencies, 8 of them MENA — no outbound call required.

Nineteen mandates, one readiness number

Your live posture maps against 19 PQC frameworks — CNSA 2.0, NIST IR 8547, PCI DSS 4.0, DORA, the EU CRA, BSI, ANSSI, CCCS, ASD, and more, plus the four MENA regulators (CBJ, CBK, UAE, Saudi NCA) scored natively rather than force-fit into a US framework — into one number, with per-control met / partial / gap evidence.

Deployment-aware verdicts

Because ANSSI, BSI, ASD, and CNSA 2.0 disagree on hybrid versus pure PQC, PQCA judges every negotiated key exchange against each of the four that applies to you — so "we deployed ML-KEM" gets the right answer for each jurisdiction, not a hopeful one.

Policy-as-code, no policy engine

Start with a sentence — banned and approved families with minimum key sizes like RSA<3072 — and graduate to a portable, schema-validated JSON policy with a tiered ladder and first-match-wins rules. Violations are detected against the live estate with no false positives on unknown key sizes, and sunset dates tighten the policy automatically as deadlines pass.

Five phases, standards-aligned

A fixed, ordered roadmap aligned to the CBJ sectoral roadmap and NIST migration guidance, with admin-editable timeline windows. A fresh install seeds an 18-item kickoff checklist, so you begin with a plan, not a blank page.

Discovery to backlog in one click

Generate-from-inventory turns every quantum-vulnerable asset, certificate, and application into an owned, dated, priority-ranked task — deduplicated and linked to the exact item it migrates. The same estate the platform scanned becomes the plan the team works.

QRC-Budget, rolled up by phase

Every action item tracks cost, paid, and computed remaining, aggregated per phase and across the whole program in your display currency. A CISO sees committed-versus-paid-versus-still-needed at a glance, with server-side guards that keep the figures internally consistent.

Readiness that tracks real work

Compliance readiness is computed from the roadmap itself — each control is bound to a phase and scored by that phase's real completion, not by whether a scan happened. Applying a framework seeds its unmet obligations into the backlog at 0%, so nothing you haven't done can score as done.

Built for enterprise scale

PQCA is production software for large, regulated environments — not a pilot tool or a consultant's script. It runs across segmented networks, data centers and OT plants; Active Directory groups map to admin and read-only access, so reviewers and auditors work the same inventory without write access; and every scan, score and export is captured on an append-only audit trail. Deploy per region or per subsidiary, each instance sovereign to its own jurisdiction and data-residency rules — on hardware you already own, integrated with the directory and SIEM you already run.

On-prem, air-gapped

Every scan, score, framework map, and export runs on your own hardware — no telemetry, and exactly zero outbound calls beyond one optional, admin-invoked FX refresh you can replace with manual rates. One codebase installs four ways — Docker, an offline Docker bundle, native Windows, or native Ubuntu — including networks with no internet at all. Backup and restore move a whole instance between sites, offline.

The numbers behind the coverage

Verifiable, concrete figures — the surface PQCA actually probes, scores and reports.

5
Discovery channels
77
Ports probed (72 TCP + 5 UDP)
70
Algorithm families
19
Regulatory frameworks
10
Reporting currencies
0
Outbound calls

See your own crypto estate scored — on-prem, on a call.

Bring a subnet or a packet capture. In 30 minutes you'll see real findings, real risk, and a real roadmap draft. No cloud sign-up, no data leaves your environment.