Q-Ready Discovery
A systematic inventory of every cryptographic asset in your estate: algorithms, key lengths, certificates and certificate authorities, crypto libraries, protocols and TLS versions, and the third-party dependencies that quietly introduce their own. Across source code, cloud services, network and on-premises systems.
This is the phase with the nearest deadline and the longest lead time. It does not depend on the final CBOM format being settled — teams that map their cryptography now will be adjusting an existing inventory in 2027 rather than starting one against a deadline.
- A machine-readable Cryptographic Bill of Materials
- Risk matrix ranked by data sensitivity and harvest-now-decrypt-later exposure
- Prioritised findings, each tied to the mandate and date it breaches
- Two-page executive summary written for a board audience
Typically 4–6 weeks · For CISO, VP of IT, CTO
