Post-Quantum Cryptographic Analyzer
- Algorithms
- 1,284
- Quantum-vulnerable
- 312 ▴
- Readiness
- 61%
Discovery coverage · illustrative
What you get
The outcomes that matter
See every algorithm you run
A clock you can plan against
Board-ready, in money terms
Inside PQCA
Every module, end to end
PQCA runs the full quantum-readiness lifecycle in one sovereign platform → discover, inventory, assess, plan and prove. Each module below is part of one integrated platform.
Discover
Inventory
Assess
Plan & migrate
Prove & operate
How it works
From cryptographic blind spot to migration plan
- 01
Discover
Fingerprint the cryptography each service actually uses — network, code, configurations, certificates and encrypted files. Network and certificate discovery are recorded as a machine-readable CBOM (CycloneDX 1.7), folding in supply-chain SBOMs; code and file analysis catch what never crosses the wire. - 02
Assess
Score every algorithm against classical and quantum attack and model HNDL exposure over your data’s shelf life. - 03
QRC-Budget
Quantify the risk per asset and org-wide in your own currency — technical severity becomes a budget line. - 04
Comply
Score your reported progress against 21 frameworks and 78 controls with per-control Met / Partial / Gap evidence and policy-as-code. - 05
Plan the migration
Drive the phased, owner-assigned, budget-tracked roadmap and report conformance to auditors and the board — on a complete audit trail: every mutation and sensitive download recorded, automation attributed by name, exportable as CEF for your SIEM.
Coverage
Built around the frameworks that govern the transition
Harvest-now-decrypt-later risk is modeled on Mosca’s inequality against a quantum horizon you configure — so the migration deadline is your data’s, not a vendor’s.
21 regulatory frameworks · 78 individually scored controls · 41 dated milestones on the live clock. ISO/IEC and IETF coverage is ISO/IEC 18033-2 Amendment 2 (FrodoKEM, Classic McEliece, ML-KEM) and the IETF TLS hybrid key-exchange drafts, including the X25519MLKEM768 codepoint PQCA probes for on the wire. For FIPS 140-3 specifically, PQCA tracks your plan to move onto CMVP-certified modules. It does not validate modules, and it is not a substitute for CMVP.
Plugged into the estate you already run
Inventory flows in from the systems that already know your assets; findings flow out to the queues your teams already work; and the same scanner gates code before it ships. No new silo, no swivel-chair.
Enterprise inventory sync — CMDB
PQCA stays in step with your asset inventory. Pull connectors for ServiceNow CMDB, NetBox/Nautobot, Qualys, Nessus and Active Directory; a watched-folder CSV channel for air-gapped estates — your CMDB exports, PQCA imports and archives; and scoped API keys for push automation, where the importer role can call exactly one endpoint and nothing else. Existing asset records are never overwritten unless you opt in.
Two-way ITSM ticketing
Findings become ServiceNow or Jira tickets carrying full remediation playbooks. Ticket status syncs back onto the finding every 15 minutes, and — opt-in — a genuinely resolved ticket closes its finding. Dismissed tickets (Won’t Do, Cancelled) never count as remediation, and a person’s closure is never overwritten. Status sync-back is ServiceNow and Jira only — Slack and generic webhooks are push-only notifications.
Developer CLI
The same scanner, in your pipeline: a zero-dependency pip package, a single-file pqca.pyz for locked-down endpoints, or a standalone executable. SARIF output annotates pull requests; a --fail-on gate blocks quantum-broken cryptography at build time. Fully offline — no server, no network.
One group, every entity
Banking groups and regional holdings answer for several licensed entities at once. A Master PQCA links each subsidiary, reads its posture on a schedule and reports the group side by side — while every subsidiary’s data stays in its own install. This is federation — many separate installs reporting upward to a parent — not multi-tenant isolation inside one install.
Link every subsidiary
A Master PQCA links each subsidiary and reads its posture on a schedule, so the group view is current without a quarterly collection exercise.
The group, side by side
Group exposure, mean readiness, the weakest entity and the soonest mandate — every entity reported side by side, so the board sees where the group stands and which subsidiary sets the pace.
Live, or from a CBOM
A subsidiary is read live from its own PQCA, or from a CBOM it uploads — either way it takes its place in the same group view.
Data stays in its own install
Every subsidiary’s data stays in its own install, sovereign to its jurisdiction and data-residency rules — the Master reads posture and reports the group.
Licensed per number of linked subsidiaries.
Four eyes on everything that matters
PQCA is a system of record, so the changes that move a risk position do not take effect because one person clicked save. On eight governed surfaces a Maker proposes and a Checker decides, and the proposal, the decision, the decider and the before-and-after state are all recorded.
Propose, decide, record
Risk acceptances · the QRC migration roadmap · the quantum horizon · the financial risk-exposure model · applied frameworks and jurisdictions · cryptographic policy · algorithm risk overrides · platform restore. Segregation of duties over cryptographic policy and risk acceptance is what an internal audit function tests for, and what turns a scanner into evidence.
The exception file an examiner asks for
Every bank carries findings it cannot remediate this year. What supervision tests is whether the exception was authorised, by whom, with what compensating control, and when it expires. PQCA records that as a first-class object with attachments and an expiry date — proposed by a Maker, approved by a Checker, and surfaced again when it lapses.
The crypto your scanner cannot reach
A network scan sees what it can route to. It misses outbound connections from behind NAT, sessions too short to catch, and every host on a segment it has no path into. PQCA ships a lightweight endpoint sensor for Windows and Linux that closes that gap — and it is built to pass a change advisory board, not to fight one.
No packet capture. No driver. No kernel module.
It samples the operating system’s own connection table on an interval, attributes each flow to the owning process, and posts flow metadata to the platform. Nothing else — no payload data ever leaves the endpoint.
A Scheduled Task, or a systemd service
On Windows it installs as a Scheduled Task from a single .exe (or PowerShell); on Linux as a systemd service from one shell command. Estates enforcing application control (WDAC, Smart App Control) allow-list the unsigned executable or sign it with their own certificate — see Deployment below.
A key that can only submit
It authenticates with a scoped service key that can call exactly one endpoint and nothing else — so a compromised sensor cannot read your inventory.
Capped at 60 days
Traffic records are capped at 60 days and purged automatically — a rolling window of what talks to what, not a permanent flow archive.
Added value
The value it creates
Discovery and a CBOM are the mechanism. This is what proving control of your cryptography is worth to the business.
Provable crypto-agility
Turn “we think we’re fine” into a signed Cryptographic Bill of Materials and a readiness score you can put in front of a regulator or board.
Fix what matters first
HNDL and financial-exposure scoring rank every weak algorithm by real business risk, so migration budget lands on the data that will actually be harvested.
Answer the mandate on demand
Export CBOM, quantum-risk findings and a phased roadmap as board-ready evidence — not a slide deck assembled the week before the audit.
Air-gapped, owned by you
Runs fully on-premise and offline, so the most sensitive map of your estate — where its cryptography is weak — never leaves your control.
Regulatory fit
Where PQCA fits your obligations
21 regulatory frameworks · 78 individually scored controls · 41 dated milestones on the live clock. The standards driving the post-quantum transition — and exactly how PQCA tracks and evidences your progress against each.
Benchmarks every discovered algorithm against the finalised ML-KEM, ML-DSA and SLH-DSA standards and flags what must be replaced.
Tracks progress toward the 2035 post-quantum mandate for national-security systems, algorithm by algorithm.
Federal civilian agencies move sooner than NSS: key establishment quantum-safe by end-2030 and digital signatures by end-2031, with agency migration plans due to OMB in October 2026. M-26-15 expressly excludes national-security systems.
Applies the deprecation timeline — RSA and ECC deprecated after 2030, disallowed after 2035 — so legacy crypto is retired on schedule.
Cryptographic-resilience evidence for financial entities under DORA, and product obligations under the Cyber Resilience Act.
ISO/IEC 18033-2 Amendment 2 (FrodoKEM, Classic McEliece, ML-KEM) and the IETF TLS hybrid key-exchange drafts, including the X25519MLKEM768 codepoint PQCA probes for on the wire. PQCA produces cryptographic-inventory evidence that supports an ISO 27001 control set; it does not assess or certify an ISMS.
SAMA’s binding milestones — cryptographic inventory and classification complete by 31 Dec 2026, institution-level quantum risk assessment by 31 Mar 2027 — alongside the UAE National Encryption Policy, Saudi NCA, Kuwait’s CBK resilience framework and the Central Bank of Jordan roadmap to 2035, scored natively with local-currency reporting. Saudi NCA is scored as general cryptographic-hygiene controls — NCA has published no post-quantum mandate; the Kingdom’s dated PQC milestones are SAMA’s.
National transition guidance mapped as first-class frameworks — UK NCSC, Germany’s BSI TR-02102-1, France’s ANSSI, Canada’s CCCS ITSM.40.001, the mandatory Treasury Board SPIN, OSFI’s quantum-readiness expectations for financial institutions, and Australia’s ASD ISM.
Documents cryptographic protection of cardholder data and surfaces weak cipher suites (Requirement 4).
HSM approvals tracked against the PTS timeline — v4 new-device approvals end mid-2027, and v5 is the first PTS revision to carry post-quantum requirements.
We tell you which numbers we measured
Most of PQCA’s compliance scoring tracks the progress you report against your own migration roadmap. Two things are different: they are computed from what your services actually negotiated on the wire, not from anything anyone attested. CNSA 2.0 suite conformance is measured estate-wide from real findings. Hybrid-versus-pure key-exchange verdicts are measured per endpoint and judged against the jurisdiction you selected — because ANSSI, BSI, ASD and CNSA 2.0 genuinely disagree about whether a hybrid construction is acceptable, and a single global verdict would be wrong for someone. Everything else on the compliance screen is a tracking view of self-attested roadmap progress, and the platform says so on the screen itself.
“We could not look” is never scored as “it was fixed”
A scanner that quietly retires a service it failed to reach manufactures compliance progress. PQCA distinguishes not vulnerable from not observed, and an unreachable target is recorded as unreachable — never as resolved. In a regulated institution the difference is a reportable control failure.
Risk mitigation
The risk it takes off the table
“Harvest now, decrypt later” is happening today. Here is what the quantum threat looks like without PQCA — and with it.
No inventory of where cryptography actually runs — TLS, SSH, certificates, code and files are a blind spot.
A complete, deduplicated Cryptographic Bill of Materials across the estate, refreshed on every scan.
Long-life secrets are being captured now for decryption once a quantum computer exists.
HNDL exposure modelled per dataset, so the data with the longest shelf life is re-encrypted first.
Migration is an open-ended, unbudgeted scramble as deadlines approach.
A phased, budgeted roadmap prioritized by quantum risk and financial impact.
Regulators ask for crypto-agility evidence you cannot produce.
Signed CBOM, risk scores and roadmap exportable on demand.
The estate drifts — new weak algorithms creep back in unnoticed.
Snapshots and drift-diff flag every regression against the approved baseline.
Deployment & security
Yours to run, built to defend
Every Terashield platform deploys inside your environment and stays under your control → hardened, directory-integrated, and audit-ready from day one.
On-premise & air-gapped
Sovereign by design
Hardened by default
Evidenced & exportable
Single process, single scheduler
PQCA runs as one process with one scheduler. There is no clustering, high availability or failover; recovery is a restore from your last backup, so set RTO and RPO expectations around your backup cadence. A bank asks this early — a straight answer builds more trust than a gap.
From the admin console, not a database shell
Backup and restore run from the admin console — which matters in air-gapped sites where the application team is not granted a database shell. A restore is itself a governed, four-eyes change.
Offline and signed
No activation server, no phone-home, no evaluation timer. A licence is an Ed25519-signed file bound to the machine and renewed by email attachment.
Complete, application-level, not hash-chained
Every scan, score, export and decision is written to an audit trail the application only ever appends to, with the acting user, the timestamp and the before-and-after state. It is not hash-chained, and a full platform restore replaces it along with the rest of the data — so treat it as a complete application-level record, and forward it to your SIEM if you need tamper-evidence held outside the platform.
Endpoint sensors: the Windows sensor .exe ships unsigned. An endpoint estate enforcing application control — WDAC or Smart App Control — must allow-list it, or sign it with the customer’s own code-signing certificate before rollout. Plan for this before a pilot, not during one.
See PQCA in your environment
Start with evidence. Migrate on your terms. See your entire cryptographic estate, its quantum risk, and your migration path → in a platform that never leaves your network.
See PQCA in your environment.
Request a private briefing — bring a subnet or a packet capture and see real findings, real risk and a roadmap draft in 30 minutes. Nothing leaves your network.