TOOL METHODOLOGY

PQC/CBOM Tool Methodology.

Additional page sections

Quantum-safe migration instruments for crypto inventories, CBOM drafts, protocol pressure, suppliers and roadmap evidence.

PURPOSE

What this family supports.

Quantum-safe migration instruments for crypto inventories, CBOM drafts, protocol pressure, suppliers and roadmap evidence.

INPUT ASSUMPTIONS

How inputs are treated.

Inputs are user-entered assumptions or evidence states. The tools do not verify live systems, datasets, vendors, clinical claims, vulnerabilities or scientific measurements.

OUTPUT POLICY

Artifact boundaries.

Outputs are preliminary orientation artifacts for human review. They are not certification, legal advice, medical advice, engineering sign-off or compliance approval.

OUTPUT ARTIFACTS

Artifacts produced.

  • Post-quantum readiness dashboard
  • Crypto exposure inventory
  • CBOM draft
  • HNDL urgency estimate
  • PQC migration roadmap
  • Supplier PQC questionnaire
  • PQC readiness maturity band
  • Protocol pressure heatmap
  • PQC/QKD decision note
  • PQC vendor evidence matrix
SOURCE FAMILIES

Reference families.

CBOM practiceHNDL risk analysisNIST PQC source familyPKI modernizationPQC migrationPQC migration planningPQC migration practicePQC protocol migrationPQC roadmap reviewPQC transition maturityPQC transition planningQKD infrastructure reviewcontract risk themescrypto-agilitycrypto-agility governancecryptographic inventory
INSTRUMENTS

Tools using this methodology.

PQC / Crypto-Agility / CBOM

Additional section

Post-Quantum Readiness Dashboard

Classifies quantum-safe readiness stage and identifies the first evidence actions for post-quantum transition.

Best for
Post-quantum readiness dashboard
Input
7 categorical evidence fields
Output
Post-quantum readiness dashboard
Method
radar
Maturity
Beta · v2.1
Limits
Does not scan systems.
Exports
copy, Markdown, JSON
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

Crypto Exposure Mapper

Maps user-entered assets, algorithms, protocols and data lifetimes into a quantum-vulnerable dependency inventory.

Best for
Crypto exposure inventory
Input
6 categorical evidence fields
Output
Crypto exposure inventory
Method
inventory table
Maturity
Beta · v2.3
Limits
Not a scanner.
Exports
copy, Markdown, JSON, CSV
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

CBOM Builder

Builds a manual cryptographic bill of materials draft with algorithms, operations, owners, evidence and migration candidates.

Best for
CBOM draft
Input
9 categorical evidence fields
Output
CBOM draft
Method
inventory table
Maturity
Beta · v2.4
Limits
Not an automatic cryptographic scanner.
Exports
copy, Markdown, JSON, CSV
CBOMPQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

Harvest-Now / Decrypt-Later Horizon Estimator

Estimates harvest-now-decrypt-later urgency from confidentiality lifetime, capture feasibility and migration lead time.

Best for
HNDL urgency estimate
Input
6 numeric and categorical fields
Output
HNDL urgency estimate
Method
timeline
Maturity
Beta · v2.5
Limits
Does not forecast when cryptographically relevant quantum computers arrive.
Exports
copy, Markdown, JSON
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

PQC Roadmap Generator

Creates a phased post-quantum migration roadmap from inventory, supplier, protocol and governance inputs.

Best for
PQC migration roadmap
Input
6 categorical evidence fields
Output
PQC migration roadmap
Method
timeline
Maturity
Beta · v2.7
Limits
Does not perform migration.
Exports
copy, Markdown, JSON
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

Supplier PQC Questionnaire

Generates supplier questions and evidence requests for post-quantum readiness and crypto-agility.

Best for
Supplier PQC questionnaire
Input
4 categorical evidence fields
Output
Supplier PQC questionnaire
Method
evidence matrix
Maturity
Beta · v2.9
Limits
Does not verify supplier readiness.
Exports
copy, Markdown, JSON, CSV
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

PQC Readiness Score

Produces a maturity-band view of quantum-safe readiness with an unknown-evidence penalty and confidence level.

Best for
PQC readiness maturity band
Input
9 categorical evidence fields
Output
PQC readiness maturity band
Method
radar
Maturity
Beta · v3.1
Limits
Not a certification.
Exports
copy, Markdown, JSON
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

Protocol Pressure Map

Scores protocol migration pressure from exposure, difficulty, business criticality and data lifetime.

Best for
Protocol pressure heatmap
Input
8 categorical evidence fields
Output
Protocol pressure heatmap
Method
heatmap
Maturity
Beta · v1.1
Limits
Does not inspect traffic.
Exports
copy, Markdown, JSON
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

QKD / PQC Comparator

Distinguishes PQC migration, QKD infrastructure assessment and specialized hybrid scenarios.

Best for
PQC/QKD decision note
Input
4 categorical evidence fields
Output
PQC/QKD decision note
Method
decision tree
Maturity
Research interface · v1.2
Limits
Does not design a QKD network.
Exports
copy, Markdown, JSON
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

PQC Vendor Evidence Comparator

Compares vendor evidence for crypto inventory, algorithm agility, hybrid support, testing and contractual commitments.

Best for
PQC vendor evidence matrix
Input
8 categorical evidence fields
Output
PQC vendor evidence matrix
Method
crosswalk matrix
Maturity
Beta · v1.3
Limits
Does not verify vendor implementations.
Exports
copy, Markdown, JSON
PQC / Crypto-Agility
open instrument →
PQC / Crypto-Agility / CBOM

PQC Contract Clause Checklist

Creates PQC-related contract language themes and evidence topics for legal and procurement review.

Best for
PQC contract clause checklist
Input
4 categorical evidence fields
Output
PQC contract clause checklist
Method
evidence matrix
Maturity
Prototype · v1.5
Limits
Not legal advice.
Exports
copy, Markdown, JSON
PQC / Crypto-Agility
open instrument →

Version policy: each instrument has a version, maturity state, assumptions, limitations, example input, example output and export formats. Method notes should be updated when scoring logic, input taxonomy or source families change.