Find Every Place Cryptography Lives
You cannot migrate what you cannot see. Every PQC migration begins with discovery: finding every place cryptography is used across application code, TLS and SSH configurations, certificate stores, key management systems, databases, file systems, hardware security modules, and third-party services. The output is a Cryptographic Bill of Materials (CBOM) — a complete, prioritized inventory that drives every subsequent migration decision.
This course teaches discovery methodology in depth: the tools that automate parts of the process, the manual techniques for the parts that cannot be automated, and the risk-weighted scoring model that turns a raw inventory into a migration sequence.
Who Should Take This Course
Security engineers, cryptographic engineers, application security specialists, and infrastructure architects responsible for cryptographic discovery and migration planning.
What You Will Learn
This course provides hands-on technical depth in a specific dimension of PQC migration, aligned with the PQC Migration Framework. You will gain practical, applicable skills you can use immediately in migration work.
Course Outline
Module 1 — Discovery Methodology
A structured approach to finding cryptography across the enterprise. Source code scanning for cryptographic API calls. Network scanning for TLS/SSH endpoints and their cipher suites. Certificate discovery across internal and external PKI. Configuration analysis for IPsec, S/MIME, and application-layer encryption. The discovery challenge in legacy systems, embedded devices, and third-party services.
Module 2 — Tooling and Automation
The tools that automate cryptographic discovery and their limitations. CBOM generation tools and standardized formats (CycloneDX cryptography extensions). Integrating discovery into CI/CD pipelines. Where automation works well and where manual analysis remains necessary. Building a repeatable discovery process rather than a one-time scan.
Module 3 — Building the CBOM
Structuring a Cryptographic Bill of Materials. What to capture for each cryptographic asset: algorithm, key length, purpose, location, dependencies, and ownership. Mapping cryptographic assets to business systems and data flows. Handling the third-party dependency problem: cryptography you depend on but do not control.
Module 4 — Prioritization and Scoring
Turning the inventory into a migration sequence. Risk-weighted scoring: quantum vulnerability, data sensitivity, exposure window, business criticality, and migration complexity. The HNDL lens: which assets protect data with long confidentiality requirements. Building a prioritized migration roadmap from the scored CBOM.
Format and Delivery
Online (self-paced) — US$499. Approximately 4 hours. 90-day access.
Live online (instructor-led) — US$499. Scheduled sessions.
Corporate delivery — Custom in-person or online delivery for teams. Contact training@quantumacademy.com.
Prerequisites
A working understanding of PQC fundamentals is recommended. Consider Post-Quantum Foundation or PQCS certification for background. Some courses assume security engineering experience.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. CPE credits earned may apply toward Quantum Academy certification maintenance.
Pricing
| Option | Price |
|---|---|
| Online (self-paced) | US$499 |
| Live online (instructor-led) | US$499 |
All prices are in US dollars.