Crypto agility is not the ability to swap an algorithm. It is the ability to know where cryptography is used, what depends on it, and how to change it safely.
Why most migrations stall
Post-quantum cryptography creates the urgency, but the blocker is older: most organisations cannot say where their cryptography lives.
- Unknown cryptographic estateRSA, ECDSA, SHA-1 and certificates spread across code, configuration and endpoints.
- Unknown dependenciesNo way to tell which systems and data each algorithm protects.
- Unknown migration costWithout a scope, there is no budget and no sequencing.
- Migration riskChanges made blind break integrations, or quietly miss the assets that matter.
The CRYPTAGION approach
- DiscoverSource code (Python, JavaScript/TypeScript, Java, Go, C/C++), X.509 certificates and live TLS endpoints — inside your perimeter.
- InventoryEvery finding with its provenance — file, line, function or endpoint — exported as a CycloneDX 1.6 CBOM.
- ClassifyAlgorithm, key size or curve, use case, quantum status, and whether it sits in production, test, example or vendor code.
- PrioritiseA 0–100 risk score weighted by data sensitivity and harvest-now-decrypt-later exposure.
- DecideRemediate now, migrate to PQC, or retain and monitor — with a recommended replacement and migration year.
- Track driftSnapshots and diffs between releases, and a CI gate that stops new cryptographic debt.
The result is the capability itself: the next time an algorithm has to change — for post-quantum or for any other reason — you already know where it is and what to do first.
Core capabilities
- Cryptographic inventory — code, certificates and TLS in one evidence-backed inventory.
- Policy as code — a
.cryptagion.yamlsensitivity policy per path, and gate thresholds in your pipeline. - Lifecycle visibility — certificate validity and expiry, key sizes, deprecated hashes.
- Migration decisions — replacement mapping to ML-KEM, ML-DSA and SLH-DSA, with a migration year per asset.
- Migration roadmap — assets sequenced into four waves, with the regulatory context you choose (for example DORA, NIS2, CRA).
- Continuous CBOM refresh — re-scan on a schedule and diff the inventory between releases (Platform tier).
- CI/CD gate — fail builds on new high-risk cryptography, with SARIF for code-scanning tools.
Measure it before you migrate
Crypto agility can be assessed: how complete the inventory is, how cryptography is configured, how quickly a change can be rolled out. Our guide Crypto-agility explained sets out a five-level maturity model, and the 2-minute readiness assessment gives you a first score.
CRYPTAGION runs on-prem or air-gapped — see deployment & data flow. It supports compliance activities; use of the product does not by itself establish regulatory compliance.
Start with one critical domain. We run discovery in the call and show you your real inventory — no payment until you’ve seen it work.
Book a free discovery call →