Every serious discussion of post-quantum migration, crypto-agility and cryptographic resilience ends at the same starting point: you cannot migrate, replace or protect what you have not found. A cryptographic inventory — a complete picture of where and how your organisation uses cryptography — is the unglamorous first step that everything else depends on, and it is the one most firms skip because it is harder than it sounds and produces no immediate headline. It is also increasingly expected: regulators and frameworks pushing crypto-agility assume you can answer where your cryptography lives, and most organisations cannot.
Why this is harder than it looks
Cryptography is not in one place. It is in your applications, your TLS certificates, your VPNs, your databases, your code-signing, your HSMs, your third-party services, your embedded devices, and the libraries buried inside all of them. Much of it was configured years ago by people who have left, using defaults nobody recorded. The result is that most organisations genuinely do not know which algorithms protect which data, where their certificates are, or which vulnerable public-key cryptography sits on the critical path. A cryptographic inventory is the work of making that visible — and it is exactly the capability that a crypto-agility requirement, a post-quantum migration, or an audit of cryptographic controls all assume you already have.
What a useful inventory captures
- Algorithms and key sizes in use, and specifically where quantum-vulnerable public-key cryptography (RSA, ECDSA, ECDH) is relied on.
- Certificates and their lifecycles — where they are, when they expire, who owns them, because certificate sprawl is where migrations stall.
- The data each protects, so you can prioritise by confidentiality lifespan rather than treating every use equally.
- Third-party and embedded cryptography, since the components you did not write are often the hardest to change and the easiest to forget.
- The dependency map — which systems would be affected by changing a given algorithm, so you know the blast radius before you touch anything.
Why it pays off beyond quantum
The inventory is often justified by post-quantum migration, but its value is broader and more immediate. It surfaces expired and weak certificates, deprecated algorithms still in use, and single points of cryptographic failure that are risks today, quantum aside. It is the foundation of crypto-agility — you cannot swap algorithms by policy if you do not know where they are. And it is the artefact that turns a vague “we should think about quantum” board conversation into a prioritised, fundable roadmap.
Free · 4 minutes
If your most senior engineer left tomorrow, would anyone still understand the system?
Fourteen questions on documentation, dependencies, and the gap between how the architecture works and how many people know it. Banded finding on screen, full sheet by email.
The temptation is to skip the inventory and jump to deploying post-quantum algorithms, because that feels like progress. It is not; it is guessing. The firms that migrate successfully start by finding where their cryptography actually lives — which is slower to start and far faster to finish, because every later decision rests on it.
Who this is for
This reading is for:
- CISOs and architects starting a post-quantum migration
- Compliance leads facing crypto-agility expectations under DORA and the CRA
- CTOs asked “where do we use vulnerable cryptography?”
- Boards funding a crypto programme and wanting a sensible first deliverable
Sixteen Pillars builds the cryptographic inventory that turns a vague quantum concern into a prioritised, fundable roadmap and the foundation for crypto-agility. Pricing is published at /pricing/. If this is live for your organisation and you would like an independent reading, the place to start is a conversation.
Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming