The language of cryptographic posture.
Clear definitions for discovery, inventory, CBOMs and the post-quantum transition. Follow each term into a more detailed explanation.
Cryptographic posture management
An ongoing practice of discovering cryptography, maintaining inventory, assessing risk and supporting decisions about remediation and modernization.
Explore the topicAutomated cryptographic discovery and inventory (ACDI)
Collection and organization of cryptographic observations across a defined environment. Automation does not remove the need to state coverage and evidence limits.
Explore the topicCryptographic inventory
A structured collection of cryptographic records, their observed attributes, evidence and relevant business context.
Explore the topicCryptographic bill of materials (CBOM)
A structured artifact representing cryptographic assets and relationships within a stated scope. Also called a cryptographic bill of materials.
Explore the topicSoftware bill of materials (SBOM)
A record of software components and relationships. It complements explicit cryptographic information in a CBOM.
Explore the topicCrypto-agility
The ability to change cryptographic implementations and choices with controlled operational impact. It depends on architecture, ownership, processes and testing.
Explore the topicPost-quantum cryptography (PQC)
Cryptographic approaches designed to resist attacks from both classical and quantum computers, under their stated security assumptions.
Explore the topicHarvest now, decrypt later (HNDL)
A threat scenario in which encrypted information is collected today with the aim of decrypting it if relevant cryptography becomes vulnerable later.
Explore the topicCryptographic provenance
Information describing where a cryptographic record came from, how it was collected and the scope it represents.
Explore the topicNegotiated cryptography
Cryptographic choices actually selected during an observed protocol connection. This is distinct from supported or configured capabilities.
Explore the topicCryptographic dependency
A relationship in which a system, software component or process uses or relies on a cryptographic asset.
Explore the topicML-KEM
NIST's standardized module-lattice-based key-encapsulation mechanism, specified in FIPS 203.
Explore the topicML-DSA
NIST's standardized module-lattice-based digital signature algorithm, specified in FIPS 204.
Explore the topicSLH-DSA
NIST's standardized stateless hash-based digital signature algorithm, specified in FIPS 205.
Explore the topicFN-DSA
FN-DSA is the Falcon-derived, lattice-based digital signature algorithm in NIST’s FIPS 206 standardization work.
Follow NIST standardizationReadiness ladder
The four states a post-quantum control in a negotiated protocol such as TLS passes through: available, configured, negotiated, observed. Only the last is evidence of protection; controls that are not negotiated skip the third state.
Explore the topicCryptographic evidence
A source observation or artifact that supports a specific claim about cryptography. Retain the method, source, time and scope so a reviewer can distinguish observed facts from inference.
Explore the topicCanonical data model
A shared structure for representing records from different discovery sources. Normalization makes comparison and correlation possible while preserving source-specific evidence and uncertainty.
Explore the topicDependency graph
A connected representation of how cryptographic assets, software, services and business applications relate. Each relationship should retain its source and distinguish observed connections from inferred ones.
Explore the topicCNSA 2.0
The Commercial National Security Algorithm Suite 2.0 is NSA guidance for quantum-resistant cryptography in National Security Systems. Applicability and transition requirements depend on system type and the current NSA guidance.
Explore the topicNIST IR 8547
NIST's draft transition guidance for post-quantum cryptography standards. It describes a proposed transition approach; it is not a universal legal deadline for every organization.
Explore the topicMake your cryptographic estate visible.
Start with one business service. See Atlas against your own estate.

