Guide 01 / Direct answer

What is post-quantum cryptographic discovery?

It is the evidence-led process of finding the cryptography an organization depends on, identifying what quantum-capable attacks could affect, and producing a migration-ready record that another party can verify.

What does it discover?

A complete program looks beyond certificates. It maps keys, algorithms, protocols, libraries, function calls, configuration, hardware security modules, cloud key services, network endpoints, containers and the dependencies connecting them.

The authorized surface may span source code, running systems, network observations, cloud control planes and endpoint telemetry. Every vantage point has blind spots, so coverage claims should name both the observed surface and residual unknowns.

What should it produce?

The core output is a cryptographic inventory, often represented as a cryptographic bill of materials (CBOM). A high-trust output is portable, schema-valid, bound to collection time and scope, and protected by hashes or signatures.

The decisive question is whether an unaffiliated reviewer can verify that the evidence is intact without relying on a screenshot or a vendor-controlled dashboard. See the evidence artifact criterion.

Why is discovery only the first step?

Organizations still need change detection, risk quantification, ownership, remediation and verified closure. The 2026.5 index finds that product capabilities cluster around discovery breadth and separate more sharply downstream.

Compare the 14 assessed products or read the buyer evaluation framework.