Business Tools
Interactive planning and governance tools for PQC migration — ROI calculators, RACI builders, vendor scorecards, and more.
Interactive planning and governance tools for PQC migration — ROI calculators, RACI builders, vendor scorecards, and more.
New here? Start with the essentials
Risk & Strategy
ROI Calculator
Calculate migration ROI with breach avoidance, compliance savings, and payback period
Board Pitch Builder
Build board-ready investment proposals with executive summary and budget request
Breach Scenario Simulator
Compare classical vs quantum-enabled breach cost (per-event and annual expected loss) with HNDL exposure
Cost of Inaction Analyzer
Model the discounted cost of delaying PQC migration — breach exposure, HNDL residual, and regulatory penalties
Cost Model Explorer
Compare the six PQC costing-model families on one scenario, with a live Monte Carlo run
CRQC Scenario Planner
Plan for cryptographically relevant quantum computer threat scenarios
Risk Register Builder
Build a PQC risk register with impact, likelihood, owners, and mitigations
Risk Heatmap & Treatment Plan
Visualise residual risk and draft treatment strategies per risk category
Initial Scoping Assessment
Phase 0 first-cut scope — top-20 in-scope systems, an estate-size estimate, and the top-10 vendor dependencies; seedable from your /migrate selection
Compliance & Audit
Compliance Checklist
Per-framework PQC compliance checklist seeded from your starred frameworks and assessment
Audit Readiness Checklist
Multi-section audit checklist covering inventory, policy, controls, and documentation
Compliance Timeline Builder
Plot framework milestones, deadlines, and dependencies on a single timeline
Governance & Policy
RACI Builder
Build RACI matrices for 10 PQC activities across 6 organizational roles
Policy Template Generator
Generate cryptographic algorithm, key management, vendor, and migration policies
KPI Dashboard Builder
Build KPI dashboards for tracking PQC migration metrics and progress
Program Charter
Phase 0 mandate artifact — sponsor sign-off, Steering Committee, QRPM appointment, governance cadence, and the multi-year budget commitment
Skills & Team Plan
Foundations staffing plan — core roles + FTE from the framework role model, the 1-FTE-per-500-instances sizing heuristic, and build / borrow / buy per role
Accelerated Execution Profile
Phase 4 Activity 4.7 — a pre-drafted contingency package (trigger conditions, compressed sequence, pre-approved risk acceptances, emergency resource request, activation authority) activated if the quantum timeline accelerates
Vendor & Supply Chain
Migration Planning
Roadmap Builder
Build a two-track migration roadmap (key-exchange/HNDL ∥ signatures-PKI/TNFL) on the 8-phase spine, with gates G0–G6 (+ G8 at closure) and milestone dependencies
Stakeholder Comms Planner
Plan stakeholder communication strategies for PQC migration programs
KPI Tracker Template
Track migration KPIs with configurable metrics and reporting templates
Deployment Playbook
Generate deployment playbooks with rollback procedures and validation steps
Hybrid Transition Planner
For architectsArchitect-facing decision tree from CSWP.39 §3.2.4 - pick traditional+PQC, PQC+PQC, pure PQC, or crypto-gateway pathway with concrete algorithm pairings
MTI Negotiator
For architectsProtocol-designer + architect decision tool from CSWP.39 §3.1.1 - picks Mandatory-to-Implement signature / KEM / hash plus alternates from audience, deadline, and constraint inputs
Crypto API Refactor Audit
For developersArchitect + senior-developer audit from CSWP.39 §4.1 - grades current crypto-agility state and emits a phased refactor checklist with language-specific call-site guidance (Go / Java / .NET / Node / Python / Rust / C / C++ / JS)
Cloud Responsibility Matrix
For architectsArchitect + compliance-lead matrix from CSWP.39 §6.4 - per-asset-class shared-responsibility model across IaaS / PaaS / SaaS / FaaS, with PQC availability per cloud and watch-outs for multi-cloud, BYOK, FedRAMP, and sovereign-cloud overlays
Crypto Architecture Diagram
Document apps, libraries, HSMs, protocols, key stores, and CAs with their dependencies; renders as a Mermaid diagram
Management Tools Audit
Audit your discovery, assessment, configuration, and enforcement tooling stack — feeds the Information Repository per CSWP.39 §5
Crypto BOM (CBOM) Builder
Build a CBOM slice from an SBOM, library posture, or HSM inventory; feeds the Assets pipeline
Crypto Vulnerability Watch
NIST NVD CVE digest for the products on your /migrate selection, joined via CPE — the top CVEs per product by severity from the current snapshot
Infrastructure Modernization Planner
Phase 6 deliverable — consolidates the PKI modernization plan, HSM/KMS upgrade schedule, network/middlebox compatibility report, and PQC capacity plan into one infrastructure-readiness artifact
Refresh-Cycle Alignment
Phase 4 Activity 4.3 — maps PQC migration tasks onto already-funded infrastructure refresh programs (data center, SD-WAN, cloud, PKI, HSM, vendor renewals) so PQC work rides existing budgets
Data-at-Rest Strategy
Phase 5 Activity 5.6 — per-store data-at-rest decision (re-encrypt under PQC keys, PQC key-wrap, crypto-shred, delete, or accept & monitor), recorded back into the CBOM
Migration Verification & Closure
Prove migration with the framework's 5-point evidence standard, log classical-key decommissioning (SP 800-88), and record program closure & BAU handover