← Knowledge areas
Knowledge area 01 · Discover

Cryptographic
Discovery

You cannot govern, prioritise or migrate cryptography you do not know exists.

Cryptographic discovery creates visibility into where and how cryptography is used across systems, applications, services, devices and data flows. The objective is not merely to produce a list, but to build a living evidence base for risk management and change.

Last reviewed: August 2026

Cryptography rarely lives in one place.

It may be implemented in application code, libraries, TLS endpoints, APIs, identity platforms, databases, operating systems, cloud services, network appliances, HSMs, certificates, signing services and third-party products. Different teams may own each layer.

This fragmentation makes cryptographic change difficult. Before an organisation can assess exposure or plan migration, it needs to understand the extent, location and use of its current cryptography — an approach explicitly reflected in NIST NCCoE's post-quantum migration work.

What should discovery capture?

A useful cryptographic inventory connects technical facts to operational and business context. Depending on scope and maturity, it may include:

01

Algorithms

Encryption, key establishment, signatures, hashing and other cryptographic algorithms, including parameters and relevant strengths.

02

Protocols & services

TLS, SSH, VPN, code signing, email encryption, certificate-based authentication and other services that rely on cryptography.

03

Keys

Key type, purpose, associated algorithm, owner, location, lifecycle state and expiry metadata — never the secret key material itself.

04

Certificates & trust

Certificates, chains, issuing authorities, trust relationships, expiry, usages and the systems that consume them.

05

Libraries & components

Cryptographic libraries, SDKs, firmware, HSMs, embedded components and products that provide or constrain cryptographic capabilities.

06

Systems & applications

The applications, services, devices and infrastructure components implementing or depending on each cryptographic mechanism.

07

Protected data

What information is protected, its sensitivity, required confidentiality lifetime and whether long-lived data creates future exposure.

08

Ownership & context

Technical owner, business owner, environment, criticality, exposure, vendor dependency and other information needed to make risk decisions.

A list of algorithms is not enough.

“Where do we use RSA?” is useful.

“Which critical services depend on RSA, what data do they protect, who owns them, which vendors constrain the migration, and what breaks if we change it?” is actionable.

This is the transition from cryptographic inventory to cryptographic dependency intelligence. Discovery should therefore feed dependency mapping, risk assessment, governance and migration planning rather than becoming an isolated spreadsheet exercise.

Use multiple lenses.

No single discovery technique is likely to reveal every cryptographic dependency. A mature approach can combine complementary evidence sources.

Network & endpoint observationIdentify exposed protocols, certificates, cipher suites and cryptographic services.
Code & dependency analysisFind cryptographic APIs, libraries, hard-coded choices and software dependencies.
Certificate & key-management sourcesUse PKI, certificate lifecycle, HSM, KMS and secrets-management metadata.
Configuration & platform dataInspect cloud, infrastructure, middleware, operating-system and appliance configurations.
Architecture & asset contextConnect findings to applications, services, data flows, CMDB records and architecture repositories.
People & suppliersValidate ownership, hidden dependencies, managed services and product constraints with engineering teams and vendors.

Inventory is a capability, not a one-off scan.

Cryptographic estates change continuously as software is released, certificates rotate, cloud services evolve and vendors update products. Discovery therefore needs a refresh model, defined ownership and a way to reconcile new findings with known inventory.

The long-term goal is not perfect visibility on day one. It is an increasingly reliable system of record that can answer risk and migration questions quickly enough to support real decisions.

Discovery is where post-quantum migration begins.

NIST's current Migration to Post-Quantum Cryptography work includes a dedicated Cryptographic Visibility and Risk Management workstream focused on building and maintaining comprehensive cryptographic inventories to guide migration.

That makes discovery more than housekeeping: it is foundational migration infrastructure.

Further reading

This page synthesises public technical guidance for educational purposes. Source material should be consulted directly for normative requirements and implementation-specific guidance.

Knowledge base← All knowledge areasNext knowledge areaDependency Mapping →