Post-Quantum Cryptography Analyzer
- Algorithms
- 1,284
- Quantum-vulnerable
- 312 ▴
- Readiness
- 61%
Discovery coverage · illustrative
What you get
The outcomes that matter
See every algorithm you run
A clock you can plan against
Board-ready, in money terms
Inside PQCA
Every module, end to end
PQCA runs the full quantum-readiness lifecycle in one sovereign platform → discover, inventory, assess, plan and prove. Each module below is part of one integrated platform.
Discover
Inventory
Assess
Plan & migrate
Prove & operate
How it works
From cryptographic blind spot to migration plan
- 01
Discover
Fingerprint the cryptography each service actually uses — network, code, configurations, certificates and encrypted files — and record it as a machine-readable CBOM (CycloneDX 1.7), folding in supply-chain SBOMs. - 02
Assess
Score every algorithm against classical and quantum attack and model HNDL exposure over your data’s shelf life. - 03
QRC-Budget
Quantify the risk per asset and org-wide in your own currency — technical severity becomes a budget line. - 04
Comply
Score readiness against 15+ frameworks with per-control Met / Partial / Gap evidence and policy-as-code. - 05
Migrate
Drive the phased, owner-assigned, budget-tracked roadmap and report conformance to auditors and the board — all on a tamper-evident log.
Coverage
Built around the frameworks that govern the transition
Harvest-now-decrypt-later risk is modeled on Mosca’s inequality against a quantum horizon you configure — so the migration deadline is your data’s, not a vendor’s.
Added value
The value it creates
Discovery and a CBOM are the mechanism. This is what proving control of your cryptography is worth to the business.
Provable crypto-agility
Turn “we think we’re fine” into a signed Cryptographic Bill of Materials and a readiness score you can put in front of a regulator or board.
Fix what matters first
HNDL and financial-exposure scoring rank every weak algorithm by real business risk, so migration budget lands on the data that will actually be harvested.
Answer the mandate on demand
Export CBOM, quantum-risk findings and a phased roadmap as board-ready evidence — not a slide deck assembled the week before the audit.
Air-gapped, owned by you
Runs fully on-premise and offline, so the most sensitive map of your estate — where its cryptography is weak — never leaves your control.
Regulatory fit
Where PQCA fits your obligations
The standards driving the post-quantum transition — and exactly how PQCA helps you satisfy each.
Benchmarks every discovered algorithm against the finalised ML-KEM, ML-DSA and SLH-DSA standards and flags what must be replaced.
Tracks progress toward the 2035 post-quantum mandate for national-security systems, algorithm by algorithm.
Applies the deprecation timeline — RSA and ECC deprecated after 2030, disallowed after 2035 — so legacy crypto is retired on schedule.
Cryptographic-resilience evidence for financial entities under DORA, and product obligations under the Cyber Resilience Act.
Feeds Annex A 8.24 (use of cryptography) with a live, evidenced view of control state across the estate.
The UAE National Encryption Policy, Saudi NCA and the Central Bank of Jordan roadmap scored natively — with local-currency reporting.
National transition guidance mapped as first-class frameworks — UK NCSC, Germany’s BSI TR-02102-1, France’s ANSSI, Canada’s CCCS ITSM.40.001 and Australia’s ASD ISM.
Documents cryptographic protection of cardholder data and surfaces weak cipher suites (Requirement 4).
Risk mitigation
The risk it takes off the table
“Harvest now, decrypt later” is happening today. Here is what the quantum threat looks like without PQCA — and with it.
No inventory of where cryptography actually runs — TLS, SSH, certificates, code and files are a blind spot.
A complete, deduplicated Cryptographic Bill of Materials across the estate, refreshed on every scan.
Long-life secrets are being captured now for decryption once a quantum computer exists.
HNDL exposure modelled per dataset, so the data with the longest shelf life is re-encrypted first.
Migration is an open-ended, unbudgeted scramble as deadlines approach.
A phased, costed roadmap prioritised by quantum risk and financial impact.
Regulators ask for crypto-agility evidence you cannot produce.
Signed CBOM, risk scores and roadmap exportable on demand.
The estate drifts — new weak algorithms creep back in unnoticed.
Snapshots and drift-diff flag every regression against the approved baseline.
Deployment & security
Yours to run, built to defend
Every Televestigo platform deploys inside your environment and stays under your control → hardened, directory-integrated, and audit-ready from day one.
On-premise & air-gapped
Sovereign by design
Hardened by default
Evidenced & exportable
See PQCA in your environment
Start with evidence. Migrate on your terms. See your entire cryptographic estate, its quantum risk, and your migration path → in a platform that never leaves your network.
See PQCA in your environment.
Request a private briefing — bring a subnet or a packet capture and see real findings, real risk and a roadmap draft in 30 minutes. Nothing leaves your network.