Post-Quantum Cryptography Analyzer
- Algorithms
- 1,284
- Quantum-vulnerable
- 312 ▴
- Readiness
- 61%
Discovery coverage · illustrative
What you get
The outcomes that matter
See every algorithm you run
A clock you can plan against
Board-ready, in money terms
Inside PQCA
Every module, end to end
PQCA runs the full quantum-readiness lifecycle in one sovereign platform → discover, inventory, assess, plan and prove. Each module below is part of one integrated platform.
Discover
Inventory
Assess
Plan & migrate
Prove & operate
How it works
From cryptographic blind spot to migration plan
- 01
Discover
Fingerprint the cryptography each service actually uses — network, code, configurations, certificates and encrypted files. Network and certificate discovery are recorded as a machine-readable CBOM (CycloneDX 1.7), folding in supply-chain SBOMs; code and file analysis catch what never crosses the wire. - 02
Assess
Score every algorithm against classical and quantum attack and model HNDL exposure over your data’s shelf life. - 03
QRC-Budget
Quantify the risk per asset and org-wide in your own currency — technical severity becomes a budget line. - 04
Comply
Score readiness against 19 frameworks with per-control Met / Partial / Gap evidence and policy-as-code. - 05
Plan the migration
Drive the phased, owner-assigned, budget-tracked roadmap and report conformance to auditors and the board — on a complete audit trail, with filed evidence hash-verified to SHA-256.
Coverage
Built around the frameworks that govern the transition
Harvest-now-decrypt-later risk is modeled on Mosca’s inequality against a quantum horizon you configure — so the migration deadline is your data’s, not a vendor’s.
Added value
The value it creates
Discovery and a CBOM are the mechanism. This is what proving control of your cryptography is worth to the business.
Provable crypto-agility
Turn “we think we’re fine” into a signed Cryptographic Bill of Materials and a readiness score you can put in front of a regulator or board.
Fix what matters first
HNDL and financial-exposure scoring rank every weak algorithm by real business risk, so migration budget lands on the data that will actually be harvested.
Answer the mandate on demand
Export CBOM, quantum-risk findings and a phased roadmap as board-ready evidence — not a slide deck assembled the week before the audit.
Air-gapped, owned by you
Runs fully on-premise and offline, so the most sensitive map of your estate — where its cryptography is weak — never leaves your control.
Regulatory fit
Where PQCA fits your obligations
The standards driving the post-quantum transition — and exactly how PQCA helps you satisfy each.
Benchmarks every discovered algorithm against the finalised ML-KEM, ML-DSA and SLH-DSA standards and flags what must be replaced.
Tracks progress toward the 2035 post-quantum mandate for national-security systems, algorithm by algorithm.
Federal civilian agencies move sooner than NSS: key establishment quantum-safe by end-2030 and digital signatures by end-2031, with agency migration plans due to OMB in October 2026. M-26-15 expressly excludes national-security systems.
Applies the deprecation timeline — RSA and ECC deprecated after 2030, disallowed after 2035 — so legacy crypto is retired on schedule.
Cryptographic-resilience evidence for financial entities under DORA, and product obligations under the Cyber Resilience Act.
Feeds Annex A 8.24 (use of cryptography) with a live, evidenced view of control state across the estate.
The UAE National Encryption Policy, Saudi NCA, Kuwait’s CBK resilience framework and the Central Bank of Jordan roadmap — now with dated milestones to 2035 — scored natively, with local-currency reporting.
National transition guidance mapped as first-class frameworks — UK NCSC, Germany’s BSI TR-02102-1, France’s ANSSI, Canada’s CCCS ITSM.40.001, the mandatory Treasury Board SPIN, OSFI’s quantum-readiness expectations for financial institutions, and Australia’s ASD ISM.
Documents cryptographic protection of cardholder data and surfaces weak cipher suites (Requirement 4).
HSM approvals tracked against the PTS timeline — v4 new-device approvals end mid-2027, and v5 is the first PTS revision to carry post-quantum requirements.
Risk mitigation
The risk it takes off the table
“Harvest now, decrypt later” is happening today. Here is what the quantum threat looks like without PQCA — and with it.
No inventory of where cryptography actually runs — TLS, SSH, certificates, code and files are a blind spot.
A complete, deduplicated Cryptographic Bill of Materials across the estate, refreshed on every scan.
Long-life secrets are being captured now for decryption once a quantum computer exists.
HNDL exposure modelled per dataset, so the data with the longest shelf life is re-encrypted first.
Migration is an open-ended, unbudgeted scramble as deadlines approach.
A phased, budgeted roadmap prioritized by quantum risk and financial impact.
Regulators ask for crypto-agility evidence you cannot produce.
Signed CBOM, risk scores and roadmap exportable on demand.
The estate drifts — new weak algorithms creep back in unnoticed.
Snapshots and drift-diff flag every regression against the approved baseline.
Deployment & security
Yours to run, built to defend
Every Terashield platform deploys inside your environment and stays under your control → hardened, directory-integrated, and audit-ready from day one.
On-premise & air-gapped
Sovereign by design
Hardened by default
Evidenced & exportable
See PQCA in your environment
Start with evidence. Migrate on your terms. See your entire cryptographic estate, its quantum risk, and your migration path → in a platform that never leaves your network.
See PQCA in your environment.
Request a private briefing — bring a subnet or a packet capture and see real findings, real risk and a roadmap draft in 30 minutes. Nothing leaves your network.