Phase 2 · Migrate public-key cryptography
1Algorithms a cryptographically relevant quantum computer would break — plan the move to ML-KEM and ML-DSA.
- RSA-2048Plan migrationalgorithm
Plan digital-signature migration → ML-DSA (FIPS 204)
Post-quantum planner
Load a CBOM and get a phased migration plan mapped to NIST post-quantum standards. Everything runs in your browser — nothing is uploaded.
Migration posture
Priorities follow the harvest-now-decrypt-later threat: key establishment and signatures first, then symmetric key sizes and protocol configuration. Readiness labels are explanatory heuristics from asset names — verify against current NIST guidance before acting.
Phased plan
Algorithms a cryptographically relevant quantum computer would break — plan the move to ML-KEM and ML-DSA.
Plan digital-signature migration → ML-DSA (FIPS 204)
Larger key sizes, protocol configuration inventories, and missing detail to gather.
Inventory the algorithms negotiated inside it → Hybrid post-quantum key exchange where available
Assets that already meet post-quantum expectations — re-check as standards evolve.
No change required → AES-256 is considered sufficient
No account · no upload · no retention