Cryptographic Discovery: Why No Single Tool Can Build Your PQC Inventory

Before an organisation can plan its post-quantum migration, it needs to understand what it is actually migrating.
That sounds straightforward.
In practice, it isn't.
FINMA Guidance 05/2026 calls for an inventory covering encryption, signature and authentication technologies across ICT systems, applications and infrastructure, including outsourced and service-based environments.
That scope extends far beyond certificates.
A certificate inventory isn't a cryptographic inventory
Certificates are an important part of the picture, but they're only one layer.
A broader cryptographic inventory can include:
- algorithms
- cryptographic libraries
- protocols
- keys
- certificates
- cryptographic use within applications and code
- authentication mechanisms
- dependencies between cryptographic assets and systems
This distinction is especially important when planning for PQC.
Why one discovery tool isn't enough
Cryptography exists at multiple layers of enterprise infrastructure.
Network scanning can expose one part of the environment.
Static source-code analysis can identify another.
Container scanning may uncover cryptographic dependencies packaged with applications.
CMDB data provides organisational context.
Certificate lifecycle management platforms provide visibility into certificates and their lifecycle.
The campaign's recommended discovery model therefore combines passive and active network scanning, container-image scanning, source-code analysis, CMDB and CLM integrations.
The blind spots matter
Some of the most difficult assets may exist outside the obvious inventory.
Cloud services.
OT.
Embedded systems and firmware.
Legacy environments.
Third-party services.
Cryptographic dependencies buried inside applications.
The objective isn't simply to produce a longer asset list.
It is to understand where cryptography exists, what depends on it and how difficult it will be to change.
Turn discovery into a living inventory
A one-off spreadsheet won't support a multi-year migration programme.
The next step is therefore to structure the discovered information so it can remain current.
A machine-readable CBOM provides one approach.
By integrating inventory generation with development and operational processes, organisations can move from:
“What cryptography do we think we have?”
to:
“What cryptography is actually deployed, where is it used, and what needs to change?”
Where certificate lifecycle management fits
Certificate lifecycle management is one part of this broader architecture.
Once certificates have been identified, their issuance, renewal, replacement and policy enforcement can increasingly be automated.
That operational capability matters for crypto-agility.
But the distinction is important:
Cryptographic discovery and inventory → AgileSec
Certificate lifecycle management and operational crypto-agility → CEMA
The source briefing explicitly requires this product boundary and states that CEMA must not be positioned as a complete cryptographic asset inventory or CBOM solution.
Discovery makes the roadmap measurable
Ultimately, the purpose of discovery isn't inventory for inventory's sake.
It allows organisations to answer the questions that make migration planning possible:
What needs to migrate?
What needs to migrate first?
What will take longest?
Which systems depend on third parties?
Which changes can be automated?
And what target dates can we credibly put in front of the board?
That is where discovery turns into a migration programme.
Want to understand your cryptographic landscape?
Building a reliable inventory starts with knowing where cryptography is actually used across your systems, applications and infrastructure.
Talk to ID Security about cryptographic discovery, certificate visibility and the first steps towards a practical PQC migration programme.
CONTACT ID SECURITY →
And
Continue the conversation
Join the ID Security Community for practical exchange around Certificate Management & Automation and Post-Quantum Cryptography & Crypto-Agility.
JOIN THE ID SECURITY COMMUNITY →