Urgent.News

What's breaking now, across thousands of outlets.

Editions

Tech

Why Cryptographic Inventory Is the First Step Toward Quantum Readiness

Post-quantum readiness starts with visibility. DevOps teams need a continuous cryptographic inventory to map algorithms, keys, certificates, libraries, infrastructure and third-party dependencies before PQC migration begins.

Why Cryptographic Inventory Is the First Step Toward Quantum Readiness

Cryptographic inventory is a critical component of preparing for quantum-ready systems. While post-quantum cryptography often focuses on replacing algorithms like RSA and elliptic curve cryptography, DevOps teams face a more complex challenge. Understanding where vulnerable cryptography exists, which applications rely on it, who owns those dependencies, and the difficulty of changing each one are key aspects of quantum readiness.

Building a comprehensive cryptographic inventory goes beyond simply selecting a replacement algorithm. It involves identifying algorithms, protocols, keys, certificates, applications, services, devices, and data flows. Cryptography is embedded throughout the software delivery lifecycle, from developers using package managers to Kubernetes terminating TLS connections. Each of these dependencies may not be visible in a conventional certificate inventory.

Modern software delivery introduces cryptography at various stages, including source control systems, dependency managers, CI systems, artifact repositories, signing systems, and runtime environments. A single application can depend on cryptography from multiple infrastructure layers, often connected to the broader software supply chain. Traditional source code searches for cryptographic elements may not reveal the complete picture, as applications often inherit cryptographic behavior from various sources.

A useful cryptographic inventory should capture more than just algorithm names. It should provide context for engineers and security teams to determine where cryptography exists, its purpose, ownership, and future replacement. This includes information about algorithms, libraries, protocols, certificates, keys, applications, services, data sensitivity, infrastructure, and vendor dependencies. By mapping these elements, organizations can create an operational map rather than a mere list of assets.

Written by urgent.news from DevOps.com's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at devops.com →

More in Tech

TM Keen To Participate In SALAM Submarine Cable Project

Telekom Malaysia Bhd (TM) has expressed interest in participating in the SALAM submarine cable project, which aims to strengthen connectivity between Peninsular Malaysia and East Malaysia. Group chief executive officer Datuk Amar Huzaimi Md Deris said the company is evaluating its options and is keen to participate in the initiative.

More from Friday 21 August →