Cryptographic inventory
Algorithms, keys and certificates across applications, infrastructure, vendors and devices.
Service 07
Australian Signals Directorate guidance sets the end of 2030 to stop using traditional asymmetric cryptography. We find where it lives across your organisation and plan a safe, staged move to post-quantum cryptography.
Why now
Encrypted data stolen today can be decrypted once quantum computers mature. Migration takes years across vendors, devices and code, so leaders who start planning now control the cost and the risk.
What we deliver
Algorithms, keys and certificates across applications, infrastructure, vendors and devices.
Prioritised by data sensitivity and how long it must stay secret.
How easily each system can change algorithms, and what blocks it.
Questions and evidence to request from suppliers about their post-quantum plans.
A staged plan aligned to ASD guidance and the NIST standards, with costs and owners.
A clear, non-technical brief on exposure, plan and budget.
Engagement
Three to four weeks, led by a team with hands-on quantum computing expertise, not just security checklists.
from A$14,000
A quantum computer able to break today's public-key cryptography does not exist yet, but adversaries can record encrypted data now and decrypt it later. Data that must stay secret for years is already at risk.
In August 2024, NIST published the first post-quantum standards: ML-KEM for key establishment (FIPS 203), and ML-DSA and SLH-DSA for digital signatures (FIPS 204 and 205). Australian guidance points organisations to these algorithms at their strongest settings.
With an inventory. You cannot migrate cryptography you cannot find. Most organisations discover algorithms in vendor products, certificates, VPNs, code and devices they did not know about.
The ASD guidance is written for Australian organisations broadly and is most pressing for government suppliers, critical infrastructure, financial services, health and anyone holding long-lived sensitive data.
Related