Algorithms
Encryption, key establishment, signatures, hashing and other cryptographic algorithms, including parameters and relevant strengths.
You cannot govern, prioritise or migrate cryptography you do not know exists.
Cryptographic discovery creates visibility into where and how cryptography is used across systems, applications, services, devices and data flows. The objective is not merely to produce a list, but to build a living evidence base for risk management and change.
Last reviewed: August 2026
It may be implemented in application code, libraries, TLS endpoints, APIs, identity platforms, databases, operating systems, cloud services, network appliances, HSMs, certificates, signing services and third-party products. Different teams may own each layer.
This fragmentation makes cryptographic change difficult. Before an organisation can assess exposure or plan migration, it needs to understand the extent, location and use of its current cryptography — an approach explicitly reflected in NIST NCCoE's post-quantum migration work.
A useful cryptographic inventory connects technical facts to operational and business context. Depending on scope and maturity, it may include:
Encryption, key establishment, signatures, hashing and other cryptographic algorithms, including parameters and relevant strengths.
TLS, SSH, VPN, code signing, email encryption, certificate-based authentication and other services that rely on cryptography.
Key type, purpose, associated algorithm, owner, location, lifecycle state and expiry metadata — never the secret key material itself.
Certificates, chains, issuing authorities, trust relationships, expiry, usages and the systems that consume them.
Cryptographic libraries, SDKs, firmware, HSMs, embedded components and products that provide or constrain cryptographic capabilities.
The applications, services, devices and infrastructure components implementing or depending on each cryptographic mechanism.
What information is protected, its sensitivity, required confidentiality lifetime and whether long-lived data creates future exposure.
Technical owner, business owner, environment, criticality, exposure, vendor dependency and other information needed to make risk decisions.
“Where do we use RSA?” is useful.
“Which critical services depend on RSA, what data do they protect, who owns them, which vendors constrain the migration, and what breaks if we change it?” is actionable.
This is the transition from cryptographic inventory to cryptographic dependency intelligence. Discovery should therefore feed dependency mapping, risk assessment, governance and migration planning rather than becoming an isolated spreadsheet exercise.
No single discovery technique is likely to reveal every cryptographic dependency. A mature approach can combine complementary evidence sources.
Cryptographic estates change continuously as software is released, certificates rotate, cloud services evolve and vendors update products. Discovery therefore needs a refresh model, defined ownership and a way to reconcile new findings with known inventory.
The long-term goal is not perfect visibility on day one. It is an increasingly reliable system of record that can answer risk and migration questions quickly enough to support real decisions.
NIST's current Migration to Post-Quantum Cryptography work includes a dedicated Cryptographic Visibility and Risk Management workstream focused on building and maintaining comprehensive cryptographic inventories to guide migration.
That makes discovery more than housekeeping: it is foundational migration infrastructure.
This page synthesises public technical guidance for educational purposes. Source material should be consulted directly for normative requirements and implementation-specific guidance.