Post-quantum security and cryptographic inventory

Post-quantum security: from strategy to cryptographic agility

Post-quantum security as an organisation-wide responsibility

Post-quantum security means more than introducing post-quantum algorithms. Companies need to know where cryptography is used, which data is protected and which systems are interdependent. Without this transparency, they cannot assess risk or reliably plan or manage migration projects.

Strategically assessing cryptographic modernisation

Bestseller

PQS Readiness Workshop

In the PQS Readiness Workshop, you’ll analyse your existing system landscape for post-quantum security together with our experts. We’ll shed light on the cryptographic mechanisms, dependencies and regulatory requirements involved and discuss the migration challenges ahead. The workshop will establish a shared understanding of risks, fields of action and priorities as a basis for targeted cryptographic modernisation.

Bestseller

Inventory pilot project

In the cryptographic inventory pilot project, you’ll gain visibility into the algorithms, keys, certificates and dependencies present in your system landscape. You’ll develop a clear understanding of the migration effort, risks and technical limitations in the context of post-quantum security. This pilot will provide a sound basis for deciding on the next steps in your cryptographic modernisation.

When is it the right solution?

As a company, you’re faced with the challenge of future-proofing your cryptographic environment. Perhaps you’re thinking about implementing post-quantum security, but don’t know where to start, or maybe you’re struggling with fragmented systems and complex dependencies.

We’re here to support you at every stage of your strategic process – from analysing your existing cryptographic landscape and prioritising critical data and systems to planning and implementing migration and modernisation measures. This allows you to systematically reduce risk, meet compliance requirements and gradually future-proof your cryptographic environment without disrupting ongoing business processes.

Your benefits:

  • Structured planning and implementation of cryptographic migration
  • Centralised view of all cryptographic dependencies
  • Reduced risk and reliably demonstrated compliance

Your next step towards post-quantum security

Cryptographic inventory as the basis for modernisation

As part of the inventory pilot project, Swisscom Security Advisory will work with you to analyse the current use of cryptography across your systems. Cryptographic mechanisms, keys, certificates and protocols will be automatically recorded and evaluated with the help of a cryptographic inventory solution. The aim is to create transparency about existing dependencies, identify quantum risks and derive concrete recommendations for cryptographic modernisation. This pilot will provide a sound basis for deciding on the next strategic or technical steps towards post-quantum security.

This pilot is aimed at specific applications or services and examines the use of cryptography in the source code or at runtime. Among other things, algorithms, libraries, protocols and cryptographic configurations used in virtual machines are analysed. This pilot is particularly suited to security-critical or business-relevant applications and will help you identify specific migration requirements and risks at an early stage.

This pilot focuses on the analysis of cryptographic mechanisms in the corporate network and the PKI. The cryptographic inventory is installed and used to evaluate TLS and SSH protocols as well as X.509 certificates and keys within 30 to 60 days. The underlying data may come directly from network scans or existing tools such as Tenable or Qualys. Optionally, a targeted PKI analysis can be carried out using EJBCA, Keyfactor, Venafi or other systems. This pilot provides the ideal introduction to enterprise-wide cryptographic modernisation.

Based on the scan results, our experts will create a structured cryptographic report with quantum risk analysis and prioritised recommendations. This will include, among other things, an evaluation of the algorithms, protocols and keys being used as well as a comparison with regulatory and internal guidelines. In addition, you’ll receive an evaluation of the results in terms of cryptographic modernisation, including actionable recommendations and integration priorities for particularly critical systems and services.

Swisscom’s production-ready PQS solutions support you in the transition from pilot projects to a stable, scalable operation. Based on an integrated security architecture, we incorporate post-quantum-ready cryptography, cryptographic inventorying, central key management and compliance-aligned monitoring into your existing infrastructure. The focus is on cryptographic agility, long-term operational reliability and regulatory compliance. Together, we develop a future-proof solution that can be flexibly adapted to new standards, threats and business requirements and ensures the long-term security of your critical systems.

Why Swisscom?

Holistic PQS expertise

Strategic consulting, applied cryptography and operations from a single source – from analysis to implementation.

Practical and feasible

Focus on real system landscapes, migrations and dependencies instead of theoretical concepts.

Trust and regulation

Many years of experience with highly regulated environments and critical infrastructure in Switzerland.

Find out more 

More articles

Frequently Asked Questions (FAQ)

Post-quantum security refers to the process of preparing and transitioning cryptographic systems to quantum-resistant methods. The goal is to protect data, applications and digital business processes even when quantum computers become capable of breaking established encryption standards such as RSA or ECC. To achieve this, organisations must conduct a thorough cryptographic inventory, assess their risks and plan clear migration paths. 

In a so-called 'Harvest Now, Decrypt Later' attack, adversaries record encrypted data today with the intention of decrypting it in the future using powerful quantum computers. Particularly at risk is any information that must remain confidential for many years — such as customer data, intellectual property or sensitive business documents. Organisations should therefore begin planning post-quantum security measures early on in order to mitigate long-term risks. 

A cryptographic inventory captures the cryptographic methods, keys, certificates and dependencies within an IT landscape. It provides visibility into where cryptography is in use and which systems will be affected by a migration. Without a complete inventory, it is difficult to plan risk mitigation and modernisation measures. 

Cryptographic agility is the ability of an organisation to replace or update cryptographic methods flexibly. This allows organisations to respond more quickly to new security requirements, regulatory obligations, or post-quantum algorithms. It is considered an essential prerequisite for a successful post-quantum security strategy. 

Our experts will be happy to answer your questions. Contact us.