Guides

Practical guides for cryptographic inventory and migration

Use standards-aware, evidence-led playbooks that preserve uncertainty, ownership, interoperability testing, and verification.

Implementation guide

How to build and maintain a cryptographic inventory

A practical guide to inventory scope, evidence, asset identity, confidence, ownership, CBOM export, continuous discovery, and migration use.

Explore

CBOM guide

Cryptographic bill of materials: what a CBOM contains and how to use it

Understand CBOM scope, CycloneDX cryptographic assets, evidence, relationships, confidence, validation, diffs, and post-quantum migration use.

Explore

PQC migration guide

Post-quantum cryptography migration: an operating roadmap

A practical roadmap for PQC inventory, prioritization, standards tracking, vendor dependencies, interoperability testing, rollout, verification, and drift control.

Explore

CNSA 2.0 guide

CNSA 2.0 planning: inventory, policy, migration evidence, and limits

Use current NSA sources to plan CNSA 2.0-related inventory and migration work while keeping applicability, implementation validation, and compliance decisions with the proper authority.

Explore

NIST PQC standards guide

NIST post-quantum cryptography standards: what migration teams need to track

A current, source-led guide to FIPS 203, FIPS 204, FIPS 205, ongoing NIST work, inventory, implementation testing, and migration governance.

Explore

Quantum security buyer guide

Quantum security companies: how to evaluate the post-quantum market

A current buyer framework for cryptographic inventory, posture management, PQC migration, runtime remediation, PKI and CLM, implementations, and quantum-safe networking vendors.

Explore

X25519MLKEM768 reference

X25519MLKEM768: codepoints, share sizes, and how to verify a hybrid handshake

Reference for the X25519MLKEM768 TLS 1.3 hybrid group: IANA codepoint, key share sizes, concatenation order, client and server support, and the openssl commands that prove which group was negotiated.

Explore

OpenSSL certificate reference

OpenSSL certificate commands: inspect, check expiry, verify a chain, match a key

A command reference for the certificate work an operator actually does with OpenSSL: read a certificate, check expiry with a threshold, fetch a chain from a live server, verify trust, and confirm a key matches its certificate.

Explore

PQC parameter reference

ML-KEM, ML-DSA and SLH-DSA: parameter sets, key and signature sizes

Byte sizes and security categories for every FIPS 203, 204 and 205 parameter set, what each algorithm replaces, and the size changes that break protocols and hardware assumptions during migration.

Explore