A practical starting point

Five questions for your first cryptographic assessment

A focused assessment should help you make a decision, even before you have a complete inventory.

1. Which decision should the assessment inform?

Choose a concrete question. You might need to investigate an aging algorithm, understand a service’s certificates, or establish a starting point for post-quantum planning. A clear question keeps the first scope manageable.

2. What is inside the scope?

Agree which systems, files, services, and environments will be assessed. Record relevant access restrictions and exclusions. An assessment result needs those boundaries to be interpreted correctly.

3. What evidence will you need?

Think beyond a total asset count. Decide which cryptographic properties, observed locations, and relationships will help your team investigate a finding. Preserve enough context to return to the source.

4. Who can explain the findings?

Application owners and infrastructure teams understand operational context that a discovery tool may not observe. Involve them when interpreting results, identifying dependencies, and choosing follow-up actions.

5. What happens after the first assessment?

Agree how findings will be reviewed and which questions need further investigation. Plan a follow-up assessment where it can show whether relevant changes are reflected in the observed environment.

Back to perspectives

Define a first scope that answers a real question.

Discuss an assessment

Product screenshot

Illustrative assessment data