43% of companies don't know which crypto assets they are protecting

Inventory of Certificates and Other Cryptographic Assets

Post-quantum cryptography (PQC) has become a key topic in security strategies over the past two years. The discussion has focused on algorithms and terminology, while less attention has been paid to the first step—one without which nothing else can be done: determining where a company actually uses cryptography.

According to a 2024 global survey by Entrust and the Ponemon Institute, 43% of organizations cite the inability to inventory their own cryptographic assets as the main obstacle to preparing for PQC. This holds true across all nine countries surveyed (Entrust, 2024). Companies know they need to prepare, but they don’t know exactly what to prepare for. They have no idea of the scope of the problem they face because they lack a map of their own environment.

This problem is not hypothetical, nor is it limited to the years 2030 or 2035, when RSA and ECC are estimated to lose their security value. It is a problem that already exists today and manifests itself in every security incident, audit, or outage caused by an expired certificate. PQC has merely brought it to light and given it a timeline.

I can't protect what I don't know about

Cryptography has been accumulating in enterprise infrastructure for decades and is almost never centrally tracked. It is scattered throughout application code, TLS configurations, certificates issued by various CAs, HSM modules, IoT devices, backup systems, and across dozens of vendors and SaaS services that the organization, as a customer, cannot see.

The security team can thus describe which servers the company operates (something CMDB and asset management have been handling for years), but it cannot answer questions such as which algorithm and key length are used to protect specific data or communications, or where an algorithm that should have been decommissioned long ago is still in use.

This is precisely the gap described by CIS Control 1 (Inventory and Control of Enterprise Assets), one of the fundamental security frameworks—unrelated to quantum computers. Its premise is simple: an organization cannot defend assets it does not know exist (CIS, cisecurity.org). In cryptography, this principle is all the more urgent because a weakness does not manifest as a missing server in the inventory, but as a silent vulnerability that remains active for years until someone exploits it or the certificate expires.

Inventory is important even without PQC

As we mentioned in the introduction—it makes sense to be aware of your assets even without considering PQC. PQC has merely highlighted this issue and given it a name. There are three good practical reasons that have nothing to do with quantum computers:

Speed of response to an incident. When a vulnerability is discovered in a specific algorithm, library, or certificate authority, the extent of the damage depends on how quickly the company can identify all the places where that asset is used. A company without an inventory spends weeks manually searching through its code and infrastructure. A company with a structured overview can respond within hours.

Operational stability. Expired certificates have long been among the most common causes of unplanned service outages. This is not an unusual risk, but rather a consequence of the fact that no one centrally tracks when each certificate expires and who is responsible for renewing it.

Regulatory compliance. Frameworks such as ISO 27001 or the NIS2 Directive require demonstrable management of cryptographic controls, not just their existence. Without an inventory, this management cannot be substantiated during an audit.

In other words, even if the PQC standards never took effect, a cryptography audit would still be a worthwhile investment in basic security hygiene.

Why PQC Increases the Need for Solutions

In addition to the reasons mentioned above, PQC adds a timeframe and a measurable risk that can already be quantified today.

Harvest now, decrypt later. Attackers can capture encrypted data now and decrypt it later, once a cryptographically relevant quantum computer becomes available. Gartner warns that this type of attack is likely already underway and is particularly relevant for data with a long retention period, such as medical records, biometrics, intellectual property, and financial and personal data. Without an inventory, it is impossible to determine which data and systems are exposed to this risk, because the risk is a function of the sensitivity of the data and its required retention period, not the technical characteristics of a single system.

Regulatory pressure comes with specific deadlines. Several authorities have independently established timelines that share a common first step—an inventory:

The range of dates between 2027 and 2035 is not a contradiction, as it reflects the varying sensitivity of the data and the differing levels of risk that individual authorities are willing to accept. Another figure is more important for planning: there is less time remaining between “today” and the nearest relevant deadline (2027–2029) than it typically takes just to conduct an inventory at a medium-sized organization with a heterogeneous infrastructure.

Without an inventory, prioritization is impossible. The migration to PQC algorithms (ML-KEM, ML-DSA) cannot be rolled out across the board. It involves a phased approach by domain (PKI/HSM, network, applications, OT/IoT, archives) with varying degrees of urgency. Prioritization based on risk (HNDL for data confidentiality, risk of signature forgery for integrity) is only possible when there is a clear overview of what, where, and for how long the company is protecting. An inventory is therefore not just a technical preliminary step; it provides the input data needed to make decisions about the allocation of budget and personnel.

More on post-quantum challenges.

Inventory in Practice

What is tracked: algorithms and their parameters (type, key length, mode), certificates and their validity, protocol versions (TLS 1.0 vs. 1.3), cryptographic libraries in the code, HSM and KMS configurations, hard-coded keys in applications, and the cryptography used by third parties and SaaS providers. Companies typically overlook this last category the most because they cannot directly control it.

Data sources: Static source code analysis, network and TLS scanning, records of certificate authorities and internal CAs, HSM/KMS configurations, and questionnaire surveys of vendors where the company does not have direct technical access.

Priority, not completeness. Attempting to conduct an exhaustive inventory of the entire organization all at once usually brings the project to a standstill for months (a typical organization has tens of thousands of certificates in its infrastructure). A practical approach starts with systems that are directly exposed to the Internet and with data that must have a long retention period. That is where the combination of risk and urgency is highest.

Ownership. An inventory without a clearly assigned owner becomes obsolete within a few weeks, because the infrastructure is constantly changing. Assigning responsibility (RACI) is not just an extra administrative detail; it is essential for the inventory to remain usable even six months from now.

Start or wait?

A cryptographic inventory is the first step in any serious PQC transition, but its value does not end there. It addresses a problem that companies face regardless of quantum computers: the inability to respond quickly to cryptographic incidents and to document the management of security controls. The recommendation, therefore, is to start as soon as possible. PQC has merely added specific deadlines and a quantifiable risk in the form of “harvest-now-decrypt-later” attacks to the inventory process.

As a qualified provider of trust-building services, SEFIRA has long focused on the field of PKI and the integration of digital trust into organizational operations. We’ll help you embark on a practical journey toward a post-quantum future.