Enterprise post-quantum readiness // regulated institutions

You can't migrate the cryptography you can't see.

PQCA discovers, inventories and quantum-risk-assesses every piece of cryptography running across your entire estate — from TLS and SSH to OT/ICS, mainframe and data at rest — scoring each algorithm for quantum and classical risk, pricing that exposure in your own currency, and carrying the same evidence straight into a phased, budgeted migration to quantum-safe cryptography. Where discovery scanners and PKI suites stop at a findings list, PQCA closes the loop with a full GRC roadmap: live readiness scoring across 15+ global mandates (NIST, CNSA 2.0, EU DORA & CRA, PCI DSS, ANSSI, BSI, CBJ and more), policy-as-code with automatic violation detection, per-control audit evidence, and an owner-assigned, budget-tracked migration plan that ties every task to the asset and the regulator behind it — the governance layer competitors leave to spreadsheets. Independently compared against the market's leading PQC discovery platforms — ask for the competitive brief. Entirely on-premise. Zero outbound calls.

Live · nearest binding deadlineFIPS 140 validated modules → Historical · 21 Sep 2026
Algorithms found
1,284
Quantum-vulnerable
312
Readiness
61%
Illustrative sample data — not live telemetry
Why now

The quantum threat isn't a someday problem. It's a today inventory problem.

A cryptographically-relevant quantum computer will unravel the RSA and elliptic-curve cryptography behind every banking transaction, government record and piece of critical infrastructure — and the attack has already started. Adversaries are harvesting encrypted data today to decrypt the day that machine arrives; for records a bank must keep secret for 10, 15, even 20 years, "later" is already inside the danger window. The fix is no longer optional — NIST has finalized the post-quantum standards (FIPS 203/204/205), and regulators from the NSA's CNSA 2.0 to the EU and central banks have set migration deadlines between 2030 and 2035. Yet most institutions can't take the first step, because they can't answer the question every migration begins with: where is our cryptography, and what is it? It's scattered across TLS, SSH, databases, mainframes, OT and data at rest — undocumented, unowned, unmeasured. Without a living cryptographic inventory, there is nothing to migrate from. You cannot migrate what you cannot see.

Your cryptography is invisible

Most institutions have no cryptographic inventory. You can't answer "where are we quantum-vulnerable?" because no one has ever mapped it — the estate runs on a stale spreadsheet of assumptions.

Harvest-now, decrypt-later is running

Long-lived secrets — core-banking ledgers, cardholder data, health and government records — captured today are decrypted the day a cryptographically-relevant quantum computer arrives. The exposure is already on the clock.

The deadlines are fixed, not hypothetical

FIPS-140 modules go Historical in Sep 2026. CNSA 2.0 lands for new national-security systems in Jan 2027. NIST disallows 112-bit security by 2035. The planning window is now — not at "quantum day."

The clock is already running

Fixed deadlines, inside your planning horizon

PQCA tracks the mandates that create the demand as a live countdown — each tagged by legal weight, each bound to real migration progress. Draft and advisory dates are labeled as guidance, never dressed up as binding law.

FIPS 140 modules
Legacy validated modules move to Historical21 Sep 2026Binding · US
CNSA 2.0
Required for new national-security systems1 Jan 2027Binding · US NSS
EU CRA
Cyber Resilience Act core obligations apply11 Dec 2027Binding · EU
NIST IR 8547
112-bit security disallowed (deprecated 2030)1 Jan 2035Guidance · Global

Dates reflect published standards and mandates as of 2026. PQCA's compliance engine retargets to the frameworks you answer to — NIST/NSA/EU alongside UAE, Saudi NCA and, per PQCA's own roadmap modeling, the Central Bank of Jordan.

How it works

From a blind spot to a funded program — in one platform

Every quantum-readiness effort stalls in the same place: a scan hands you a list, and the list goes nowhere. Point scanners stop there. PKI and HSM suites see mostly certificates and keys — a slice of the estate, not the cryptography buried in TLS and SSH, OT and mainframes, databases and data at rest. PQCA takes the evidence it discovers and carries it the whole way: an evidence-based cryptographic inventory becomes a quantum- and classical-risk score, becomes an exposure priced in your own currency, becomes readiness mapped to 15+ mandates with per-control evidence, becomes an owner-assigned, budget-tracked migration roadmap the board can fund. No exporting between five tools, no reconciling four risk models, no spreadsheet in the middle — one tool, one risk model, one source of truth, from the first blind spot to the funded program that closes it.

Discover

Live evidence, not a spreadsheet. PQCA builds your inventory from the cryptography each service actually negotiates on the wire.

9 protocol families · 100+ ports

Assess

Every algorithm scored against classical and quantum attack; Mosca's inequality flags the data already exposed to HNDL.

70+ algorithm reference

QRC-Budget

Quantum risk quantified per asset and org-wide, in your own currency — technical severity becomes a budget line.

10 currencies

Comply

Live readiness scored against 15+ frameworks with per-control Met / Partial / Gap evidence and policy-as-code.

15+ frameworks

Migrate

The same evidence flows into a phased, budgeted, owner-assigned roadmap — the estate you inventory is the estate you migrate.

Five-phase QRC plan
Discovery

Five ways to find crypto — because one is never enough

No single method sees all of it, so PQCA runs five. It probes live TLS, SSH and OT services for what they can negotiate; reads packet captures for what actually crossed the wire — passively, air-gapped, without touching a host; inspects files and data at rest for the ciphers protecting them; scans source code and configuration for the algorithms, library calls and keys baked in; and folds in the applications and certificates your teams already track. Every finding lands in one evidence-based Cryptographic Bill of Materials, scored by the same risk engine — so nothing in the estate stays dark. And the discovery is honest: an unreachable host is reported as unreachable, never silently counted as "clean."

Active network

Real handshakes across nine protocol families — TLS, STARTTLS, SSH, database wire protocols, OT/ICS, SMB, RDP, Kerberos, and UDP probes for QUIC, IKEv2, WireGuard and ONVIF — 100+ ports, full accepted-cipher-suite enumeration.

Passive PCAP

Parse the crypto actually negotiated on the wire from a capture — monitor-only, in-memory, air-gap friendly. Nothing is stored.

Config & source

Heuristic static scan of source and infra config for hard-coded crypto, with purpose inference — TLS, backups, tokens, code-signing.

Encrypted files

Detect ~30 container formats — PEM/PKCS, LUKS, BitLocker, VeraCrypt, JKS, PGP, Vault — by magic bytes. Multi-GB files never move.

HSM / KMS import

Ingest exported key lists from AWS KMS, Azure Key Vault or PKCS#11 / HSM — the most accurate crypto surface there is — fully offline.

Reaches where IT-only tools stop: OT/ICS (Modbus, DNP3, S7, OPC UA), IoT (MQTT, RTSP/ONVIF), mainframe (TN3270E, IBM MQ) and data-at-rest via database fingerprinting — each with a migration advisory. See the discovery deep-dive →

Financial exposure

Price the risk your board can fund

Not every red badge is urgent. PQCA quantifies quantum risk per asset and org-wide — value(sensitivity) × risk factor × HNDL multiplier — in your own currency, so leadership can rank it and fund it. A technical scan becomes a board decision.

Figures are illustrative and computed on-premise; PQCA prices in USD, EUR and JOD/SAR/AED/KWD/OMR/BHD with air-gapped manual FX. No live rates leave your network.

Compliance & frameworks

Prove control against the regulators you answer to

Per-control Met / Partial / Gap evidence across 15+ global frameworks, each control bound to real roadmap progress — not just proof that a scan ran. Portable policy-as-code retargets the mapping to your own regulator.

US · FederalCNSA 2.0

Suite-conformance measured estate-wide, with the 1 Jan 2027 gate for new national-security systems tracked live and hybrid-vs-pure verdicts per endpoint.

US · FederalNIST IR 8547

RSA/ECC deprecation and 112-bit timelines bound to your migration phases, so transition guidance maps to what you have actually moved.

Global · PaymentsPCI DSS 4.0

Req. 12.3.x cryptographic-inventory obligations satisfied with a machine-readable CBOM auditors accept, plus keyed-material and cert hygiene findings.

EU · FinancialEU DORA

ICT and cryptographic-resilience evidence for financial entities, exportable as OSCAL and STIX for your regulator's examination.

MENA · GulfUAE · Saudi NCA

Regional mandates most US/EU-centric tools ignore — scoped per jurisdiction, with local-currency reporting.

MENA · ModeledCentral Bank of Jordan

The CBJ sectoral roadmap is modeled as a first-class framework from a PQCA-sourced reference — attributed, not asserted as an audited alignment.

Migration roadmap

Discovery is only the first half

The same evidence flows into a five-phase, budgeted, owner-assigned QRC program with dates, cost and an auditable trail. The estate you inventory is the estate you migrate.

Phase 01

Preparation

Set crypto-agility policy, roles and scope; stand up the sovereign deployment inside your perimeter.

Owner · Governance
Phase 02

Discovery

Run the five channels; build the CBOM; score risk and price exposure across the estate.

Owner · Crypto/PKI
Phase 03

Pilot

Validate quantum-safe crypto in the mode your regulator requires — hybrid or pure — on a bounded slice.

Owner · Engineering
Phase 04

Adoption & migration

Execute per-finding remediation with owners, dates and budget KPIs; advisory-only, never touching prod itself.

Budget · cost/paid/remaining
Phase 05

Validation

Re-scan, diff the CBOM, and evidence readiness against the frameworks and deadlines you answer to.

Owner · GRC
Why PQCA

Why security teams choose PQCA

PQCA runs the whole post-quantum program on one risk model and one source of truth — discover → assess → QRC-Budget → comply → roadmap — deployed at enterprise scale on your own hardware, sovereign and air-gap-ready, and built for regulated banks, government, and critical infrastructure.

Five discovery channels, one inventory

Active network scanning, passive PCAP capture, encrypted-file-at-rest analysis, source-and-config code scanning, and X.509/CBOM import all converge on a single inventory — so nothing negotiated, stored, coded, or captured slips the net.

OT, IoT, and mainframe in reach

Dedicated probes cover Modbus, DNP3, S7comm, EtherNet/IP, BACnet, OPC UA, MQTT and CoAP — plus IP-camera RTSP/ONVIF and mainframe TN3270E and IBM MQ — the 10-to-20-year-lifecycle assets generic scanners miss. A 70+ algorithm knowledge base across 100+ default ports maps every finding to a named migration recommendation, not a bare "unknown."

Quantum and classical, one score

Every observation is scored on two independent axes — Shor-era quantum status and classical hygiene — then collapsed to a single 0–100 risk score and a five-level severity band. Key-size escalation means a 1024-bit RSA key is reported broken, not laundered into "ok" by a family default.

HNDL grounded in Mosca's inequality

Harvest-now-decrypt-later exposure is computed per asset from data retention versus a calendar-anchored quantum horizon, so migration deadlines actually come due instead of forever receding. Un-curated assets surface as a data-quality gap, never a false clean bill of health.

Exposure priced in your currency

A transparent, admin-tunable model turns technical risk into money — default anchors $1,000,000 / $250,000 / $50,000 by sensitivity — so leadership prioritizes in dollars, or dinar. Figures display in any of 10 currencies, 8 of them MENA, fully offline.

Fifteen mandates, one readiness number

Your live posture maps against 15 PQC frameworks — CNSA 2.0, NIST IR 8547, PCI DSS 4.0, DORA, the EU CRA, BSI, ANSSI, CCCS, ASD, and more, plus the three MENA regulators (CBJ, UAE, Saudi NCA) scored natively rather than force-fit into a US framework — into one number, with per-control met / partial / gap evidence.

Deployment-aware verdicts

Because ANSSI, BSI, ASD, and CNSA 2.0 disagree on hybrid versus pure PQC, PQCA judges every negotiated key exchange against all four — so "we deployed ML-KEM" gets the right answer for each jurisdiction, not a hopeful one.

Policy-as-code, no policy engine

Start with a sentence — banned and approved families with minimum key sizes like RSA<3072 — and graduate to a portable, schema-validated JSON policy with a tiered ladder and first-match-wins rules. Violations are detected against the live estate with no false positives on unknown key sizes, and sunset dates tighten the policy automatically as deadlines pass.

Five phases, standards-aligned

A fixed, ordered roadmap aligned to the CBJ sectoral roadmap and NIST migration guidance, with admin-editable timeline windows. A fresh install seeds an 18-item kickoff checklist, so you begin with a plan, not a blank page.

Discovery to backlog in one click

Generate-from-inventory turns every quantum-vulnerable asset, certificate, and application into an owned, dated, priority-ranked task — deduplicated and linked to the exact item it migrates. The same estate the platform scanned becomes the plan the team works.

QRC-Budget, rolled up by phase

Every action item tracks cost, paid, and computed remaining, aggregated per phase and across the whole program in your display currency. A CISO sees committed-versus-paid-versus-still-needed at a glance, with server-side guards that keep the figures internally consistent.

Readiness that tracks real work

Compliance readiness is computed from the roadmap itself — each control is bound to a phase and scored by that phase's real completion, not by whether a scan happened. Applying a framework seeds its unmet obligations into the backlog at 0%, so nothing you haven't done can score as done.

Built for enterprise scale

PQCA is production software for large, regulated estates — not a pilot tool or a consultant's script. It scans tens of thousands of endpoints across segmented networks, data centres and OT plants; role-based access with Active Directory groups keeps crypto, GRC, engineering and audit teams in their own lanes on the same inventory; and every scan, score and export is captured on an append-only audit trail. Multi-site organisations run it per region or per subsidiary and roll findings, exposure and roadmap budget up to one group-level picture — deployed on hardware you already own, integrated with the directory and SIEM you already run.

On-prem, air-gapped

Every scan, score, framework map, and export runs on your own hardware — no telemetry, and exactly zero outbound calls beyond one optional, admin-invoked FX refresh you can replace with manual rates. One codebase installs four ways — offline, native single-process Server install on a network with no internet. Encrypted AES-256-GCM backup and restore moves a whole instance between sites without exposing a byte.

Streams to your SIEM and directory

Findings, drift events, and the full audit trail forward to any SIEM as CEF over UDP, TCP, or TLS — SSRF-hardened, with at-least-once delivery on the audit and drift streams — while Active Directory handles sign-on and least-privilege provisioning by group. It fits the SOC and the joiner-leaver process you already run.

The numbers behind the coverage

Verifiable, concrete figures — the surface PQCA actually probes, scores and reports.

9
Live protocol families
100+
Ports probed (TCP + UDP)
70+
Algorithms in the reference
15+
Regulatory frameworks
10
Reporting currencies
0
Outbound calls

See your own crypto estate scored — on-prem, on a call.

Bring a subnet or a packet capture. In 30 minutes you'll see real findings, real risk, and a real roadmap draft. No cloud sign-up, no data leaves your environment.