← Knowledge areas
Knowledge area 02 · Understand

Dependency
Mapping

Discovery tells you what exists. Dependency mapping tells you what matters when it has to change.

A useful dependency view connects cryptography to systems, data, business services, owners, suppliers and change constraints so risk decisions are based on consequence and controllability — not inventory counts.

Last reviewed: August 2026

Context turns cryptographic inventory into risk intelligence.

Knowing that hundreds of systems use an algorithm does not show which dependency should be addressed first, what business capability could be disrupted or whether the organisation controls the migration path.

Priority becomes defensible when technical findings are connected to security purpose, criticality, exposure, data lifetime, ownership, supplier constraints and realistic remediation effort.

Follow the chain from cryptography to business impact.

01Business serviceWhat organisational capability depends on this?
02System / applicationWhere is the dependency implemented or consumed?
03Cryptographic useWhat security property does it provide?
04ImplementationAlgorithm, protocol, certificate, key, library, platform or service.
05Protected assetWhat data, identity, transaction or trust relationship is protected?
06Owner & supplierWho can approve, implement or constrain change?
Risk lens

A useful dependency answers three questions: what could be affected, why it matters, and who can change it.

Map relationships that change the decision.

01

Criticality & purpose

Connect the dependency to business impact and the confidentiality, integrity, authentication or trust objective it supports.

02

Data & exposure

Understand sensitivity, protection lifetime, external exposure and important trust boundaries.

03

Ownership & control

Identify technical and service owners and whether the organisation can make the change directly.

04

Supplier dependency

Identify vendors, platforms and external counterparties that can delay or constrain remediation.

05

Change constraints

Capture interoperability, legacy technology, release windows, certification needs and operational dependencies.

06

Technology roadmap

Consider whether the system is strategic, being modernised or approaching retirement before choosing treatment.

Relationships remain traceable, owned and decision-ready.

TraceabilityMaterial findings link to known systems and services rather than remaining isolated scan results.
OwnershipA responsible technical or service owner is identifiable, including for third-party dependencies.
Risk contextCriticality, purpose, exposure and protected data are understood well enough to assess consequence.
Treatment statusAccepted, planned, blocked, in-progress and remediated dependencies are distinguishable.
Refresh mechanismRelationships can be updated as applications, suppliers, platforms and architectures change.

Prioritisation principle

Same cryptographic weakness does not mean same organisational risk. Priority emerges from condition + purpose + exposure + impact + data lifetime + migration difficulty + control.

Move from relationships to treatment decisions.

Start with critical servicesMap the dependencies where disruption, compromise or delayed migration would matter most.
Validate ownersTreat unknown ownership as a remediation blocker, not an administrative detail.
Identify external constraintsMake vendor, platform and interoperability dependencies explicit early.
Estimate change windowsUnderstand realistic design, testing, procurement and deployment lead time.
Use the map to prioritiseTranslate technical findings into sequenced risk treatment and governance decisions.

PQC migration is a dependency-management challenge.

Post-quantum transition affects applications, protocols, certificates, hardware, suppliers and communicating parties — not algorithms in isolation.

Mapping those relationships early exposes blockers while the organisation still has time to choose a controlled migration path.

Further reading

Educational synthesis through an information-security risk-management lens.

Previous knowledge area← Cryptographic DiscoveryNext knowledge areaCryptography Governance →