EU post-quantum roadmap: first transition steps — starting with a cryptographic inventory — are due by end of 2026. What it means for you →
For CAC40 · DAX40 · IBEX35 · AEX25 security teams

Cryptographic inventory for crypto‑agility and post‑quantum readiness.

Discover cryptography across source code, certificates and TLS — inside your perimeter.

CRYPTAGION generates a CycloneDX 1.6 CBOM, prioritises classical and quantum risk, and turns the inventory into an actionable migration roadmap, with a board-ready PDF that supports your DORA, NIS2 and EU Cyber Resilience Act evidence.

Built in the EU · On-prem & air-gapped · Demo-able in 4 minutes · Watch the demo ▸
  cryptagion scan · illustrative fixture demoScanning
0Assets found
0Critical
7Algorithm families
  • RSA-2048 · signaturequantum-vulnerable (Shor) · jwt.pyCritical
  • ECDSA-P256 · signaturequantum-vulnerable (Shor)Critical
  • MD5 · hashbroken since 2004 · replace nowCritical
  • SHA-1 · hashcollision-broken since 2017High
  • AES-256-GCM · symmetricquantum-resistant at 256-bitLow
Wave 1: MD5 · SHA-1 quick wins → SHA-2CBOM · CycloneDX 1.6 ✓

Illustrative fixture metrics; no customer exposure or migration estimate inferred — inspect the verified Python case study.

Mapped to NIST FIPS 203 · 204 · 205 CycloneDX 1.6 DORA Art. 9 NIS2 Art. 21 EU Cyber Resilience Act BSI TR-02102-1 CNSA 2.0

CRYPTAGION supports compliance activities; use of the product does not by itself establish regulatory compliance.

Watch

See CRYPTAGION in action.

An illustrative fixture walkthrough of discovery, CBOM, scoring and roadmap. Figures are hypothetical; see the verified Python case study below.

Why now

The post-quantum migration window is open.

Three independent forces have made cryptographic inventory a 2025 board topic.

01

NIST standards are final.

FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) shipped in August 2024. The "we're waiting for standards" excuse expired.

02

EU regulation is live.

DORA, NIS2, and the EU Cyber Resilience Act increase the need for demonstrable ICT resilience, cryptographic governance, and audit-ready evidence — that your existing GRC tooling can ingest.

03

HNDL exposure is now.

Data that must stay confidential beyond roughly seven years is already inside the harvest-now-decrypt-later window under a 2032 CRQC planning scenario. That is a planning assumption, not a prediction. How HNDL is scored →

The platform

Discover. Score. Deliver.

CRYPTAGION discovers, inventories and governs cryptography across software estates, then turns that inventory into a crypto-agility and PQC migration plan.

Discover

Find the keys, hashes and certs you rely on.

Static analysis across five languages, plus X.509 cert stores and live TLS endpoints.

  • Python (AST), JavaScript / TypeScript, Java, Go, C / C++
  • X.509 PEM / DER / CRT / CER, with validity + signature hash
  • Live TLS handshake inventory via sslyze
  • Source code never leaves your perimeter
Score

Risk anyone can defend.

0–100 score per asset, with reasoning. Tunable per data sensitivity and HNDL window.

  • Anchored to NIST IR 8413, BSI TR-02102-1, CNSA 2.0
  • Lifecycle signals: expired certs, aged keys
  • Per-asset sensitivity policy via .cryptagion.yaml
  • YAML-tunable weights — no forking required
Deliver

What your CISO sends the board.

A board-ready PDF, a standards-compliant CBOM, and a 4-wave migration roadmap — generated automatically.

  • CycloneDX 1.6 Crypto-BOM (validated against the strict schema)
  • Executive PDF mapped to DORA, NIS2, EU CRA, FIPS 203/204/205
  • 4-wave migration plan with effort estimates
  • Policy-generated executive narrative — optional EU-sovereign LLM assistance, deterministic offline mode by default
Remediate · Migrate · Retain

Not everything needs replacing.

CRYPTAGION separates today's cryptographic debt from future post-quantum migration candidates, and from the cryptography you should simply keep and monitor. Each finding comes with its recommended replacement.

Remediate now

MD5 · SHA-1 · RSA-1024 · expired certificates

Already broken or out of policy. No quantum computer needed: this is current cryptographic debt, and it goes first.

PQC migrate

RSA · ECDSA · ECDH · DH · Ed25519

Sound today, breakable by Shor's algorithm. Sequenced into migration waves towards ML-KEM and ML-DSA by HNDL exposure and data sensitivity.

Retain & monitor

AES-256 · SHA-256+ · SHA-3 · HMAC

Quantum-resistant at current parameters. Keep it, track it in the inventory and re-check as guidance evolves.

Runs where your code is

CRYPTAGION goes to the code. The code does not go to CRYPTAGION.

$ cryptagion scan code --path ./platform --languages java,go
$ cryptagion risk score --top 15
$ cryptagion export cbom --output cbom.json
$ cryptagion roadmap generate -r dora,nis2,cra
$ cryptagion report pdf -o report.pdf

Source code stays where it is. The cryptographic inventory comes out.

  • On-premises: your servers, your network, your control.
  • Air-gapped runs supported: no outbound connection required; the narrative falls back to a deterministic offline mode.
  • Local execution: static analysis, certificate parsing, scoring, CBOM and PDF are all generated inside your perimeter.
  • Open-standard outputs: CycloneDX 1.6 CBOM, PDF and SARIF. No source code in the exported artefacts.
  • CI/CD compatible: the same engine runs as a pipeline gate.
How it works

From hidden cryptography to a migration-ready CBOM

CRYPTAGION scans code, certificates, and TLS endpoints inside your perimeter, normalizes cryptographic assets, scores quantum exposure, and generates audit-ready outputs for security, architecture, and compliance teams.

Interactive demo

Explore an illustrative fixture demonstration.

An illustrative replay using multi-language fixtures — 75 records, with assumed scoring inputs. These are not pyca/cryptography results. Click Run to play it through; to run it against your code, the first call is free.

cryptagion ~ illustrative fixture replay
Bar chart of 75 cryptographic assets by algorithm family: RSA 28, SHA-2 13, ECDSA 12, AES 7, SHA-1 6, MD5 6, Ed25519 3
Donut chart of risk distribution: 15 critical, 34 high, 11 medium, 15 low
Bar chart of harvest-now-decrypt-later exposure: 68 assets none, 2 at 1–5 years, 5 at 11–20 years

Want to see this against your code? The first call is free. Book 30 minutes →

Verified source demonstration

A Python inventory you can inspect.

243 Python files scanned twice at a pinned pyca/cryptography revision. Both runs produced matching normalized findings; the CBOM passed the official CycloneDX 1.6 schema.

1,804 raw detections: 46 in library source, 1,746 in tests, 12 in documentation scripts. Detections are not vulnerabilities. Rust and Python stub files are outside this scan.

Read the evidence and limitations →Download raw CBOM
What it detects

Detection coverage, stated explicitly.

No ambiguity about what is supported today versus on the roadmap.

CapabilityStatusHow
Python cryptography detectionAvailableAST-based static analysis
JavaScript / TypeScript detectionAvailableStatic analysis (Semgrep)
Java detectionAvailableSource-code analysis
Go detectionAvailableSource-code analysis
C / C++ detectionAvailableSource-code analysis
Certificate parsingAvailablePEM, DER, CRT, CER
TLS endpoint scanAvailableLive handshake inspection (sslyze)
Quantum risk scoringAvailablePer-asset, HNDL-aware
CycloneDX CBOM exportAvailableVersion 1.6, schema-validated
Executive PDF reportAvailableBoard & audit ready
CI/CD integrationPlatformAPI / pipeline integration
SOAR / GRC integrationPlatformAPI-driven outputs
Multi-cloud KMS scanPlatformAWS KMS, Azure Key Vault, GCP KMS via API
SIEM exportPlatformFindings streamed to your SIEM via API
Container image analysisRoadmapPlanned
Binary analysisRoadmapPlanned
Insights

Post-quantum, explained for regulated EU teams.

Practical, sourced guides on deadlines, regulation and migration — written by the people who run the scans.

How quantum-ready are you?

Answer 10 questions, get a readiness score and your three next steps. Two minutes, no email required.

Take the assessment →

All resources →

Pricing

Built for procurement.

Fixed-fee discovery, transparent platform pricing, optional migration advisory. Public so your CISO does not have to "talk to sales" to budget it.

Q4 REFERENCE PROGRAMME — 3 spots remain

PQC Readiness Pilot — €18,000

A focused, fixed-scope engagement to baseline one critical domain: 3–5 repositories and up to 20 TLS endpoints — producing a sample CycloneDX CBOM, a quantum-risk summary and an executive overview. The natural first step before a full Discovery, at a reference-programme rate in exchange for a public reference and a 30-minute case-study interview. Open to the first 5 reference customers only.

€18,000
first step → full Discovery (€45k)
Apply for a pilot →
Discovery
€45,000
Fixed-fee · 60 days
Scope: up to 50 repositories · 100 TLS endpoints · certificate stores · 1 results workshop · on-prem or air-gapped
  • Full discovery across code + certs + TLS
  • CycloneDX 1.6 Crypto-BOM
  • Board-ready PDF executive report
  • 4-wave migration roadmap
  • Regulatory mapping (DORA, NIS2, CRA)
Migration advisory
Custom
Billed separately
Scope: tailored to your estate · migration waves · crypto-agility design · governance support
  • Hands-on migration support
  • Cryptographic-agility design review
  • Delivered directly or through your security integrator
  • Reference architectures for ML-KEM, ML-DSA, SLH-DSA

The path: PQC Readiness Pilot (€18k) → Discovery (€45k) → Platform (from €80k/year). Integrators and consultancies: a partner licence for use across customer engagements; OEM and redistribution under a separate agreement.

For your procurement file: Download the CRYPTAGION security posture (PDF) →

Why a focused practice

Specialist engineering practice. Enterprise-grade reversibility.

You are inventorying your most sensitive cryptographic assets. You should know exactly who runs the tool, where it runs, and what happens if we disappear. Here are the answers your procurement team will ask for — before they ask.

Your code never leaves your perimeter.

Discovery runs inside your environment. Static analysis, cert parsing and TLS handshakes execute locally; only the findings are aggregated. The executive narrative is policy-generated; optional LLM assistance uses an EU-sovereign backend you can swap, or runs in a deterministic offline mode with no external call at all. Air-gapped runs are supported.

No lock-in. Outputs outlive the vendor.

Every deliverable is an open standard: a CycloneDX 1.6 CBOM your GRC tooling already ingests, and a PDF your board can read without our platform. If you ever stop working with us, your inventory, your roadmap and your audit trail stay fully usable.

Continuity is contractual, not a promise.

Source-code escrow available on Platform engagements, with a documented right-to-audit and a reversibility clause. The offline fallback means a run never depends on our availability. You are buying a deliverable and a method — not a dependency.

Built by practitioners, not a sales org.

CRYPTAGION is built by a focused security-engineering practice — cybersecurity, data & AI specialists with 10 years across banking, luxury and industrial enterprises, where cryptographic risk and regulatory pressure are operational, not theoretical. The people who scope your engagement are the people who run the tool against your code.

FAQ

Questions procurement always asks.

Does my source code leave my environment?

No. Discovery runs inside your perimeter; only aggregated findings are produced. Air-gapped runs are supported.

What standards does the CBOM comply with?

CycloneDX 1.6 Crypto-BOM, validated against the strict schema, with reporting mapped to DORA, NIS2, the EU CRA and FIPS 203/204/205.

Does using CRYPTAGION make us DORA, NIS2 or CRA compliant?

No tool does that on its own. CRYPTAGION supports evidence for cryptographic risk-management, resilience and governance activities relevant to frameworks such as NIS2, DORA and the Cyber Resilience Act. Use of the product does not by itself establish regulatory compliance.

What happens to my deliverables if I stop using CRYPTAGION?

All outputs are open standards (CycloneDX CBOM, PDF) and remain fully usable without the platform. Source-code escrow is available on Platform engagements.

Partners & integrators

Built to work alongside your security partners.

CRYPTAGION is a natural complement to the firms already trusted by regulated EU enterprises. Deliver post-quantum readiness to your clients without building a cryptographic-discovery engine in-house.

MSSPs

Add PQC discovery to your services

Extend your managed offering with cryptographic inventory, CBOM and risk scoring — under your delivery, on the client’s perimeter.

Audit & GRC firms

Produce audit-ready evidence

Generate CycloneDX CBOMs and board-ready reports for your DORA, NIS2 and CRA engagements — open-standard, defensible artefacts.

Integrators

Deliver the migration, not just findings

Pair discovery with wave-based migration roadmaps. Migration Advisory can be delivered directly or co-delivered with you.

Partner licence for multi-customer use, plus referral and co-delivery arrangements. See the partner programme →

Free 30-minute discovery call

I will run CRYPTAGION against your code in the call.

Bring a representative repository (public, anonymised, or under NDA). You walk out with a real preview of your cryptographic posture. No payment until you've seen the tool work against your own codebase. No slides. No salesforce.

Book a free 30-minute call on Calendly

Or write directly: contact@cryptagion.io