Business Tools

Interactive planning and governance tools for PQC migration — ROI calculators, RACI builders, vendor scorecards, and more.

37 tools
Zone:
Phase:
Audience:
Group by

New here? Start with the essentials

Risk & Strategy

Governance & Policy

Migration Planning

Roadmap Builder

Build a two-track migration roadmap (key-exchange/HNDL ∥ signatures-PKI/TNFL) on the 8-phase spine, with gates G0–G6 (+ G8 at closure) and milestone dependencies

Stakeholder Comms Planner

Plan stakeholder communication strategies for PQC migration programs

KPI Tracker Template

Track migration KPIs with configurable metrics and reporting templates

Deployment Playbook

Generate deployment playbooks with rollback procedures and validation steps

Hybrid Transition Planner

For architects

Architect-facing decision tree from CSWP.39 §3.2.4 - pick traditional+PQC, PQC+PQC, pure PQC, or crypto-gateway pathway with concrete algorithm pairings

MTI Negotiator

For architects

Protocol-designer + architect decision tool from CSWP.39 §3.1.1 - picks Mandatory-to-Implement signature / KEM / hash plus alternates from audience, deadline, and constraint inputs

Crypto API Refactor Audit

For developers

Architect + senior-developer audit from CSWP.39 §4.1 - grades current crypto-agility state and emits a phased refactor checklist with language-specific call-site guidance (Go / Java / .NET / Node / Python / Rust / C / C++ / JS)

Cloud Responsibility Matrix

For architects

Architect + compliance-lead matrix from CSWP.39 §6.4 - per-asset-class shared-responsibility model across IaaS / PaaS / SaaS / FaaS, with PQC availability per cloud and watch-outs for multi-cloud, BYOK, FedRAMP, and sovereign-cloud overlays

Crypto Architecture Diagram

Document apps, libraries, HSMs, protocols, key stores, and CAs with their dependencies; renders as a Mermaid diagram

Management Tools Audit

Audit your discovery, assessment, configuration, and enforcement tooling stack — feeds the Information Repository per CSWP.39 §5

Crypto BOM (CBOM) Builder

Build a CBOM slice from an SBOM, library posture, or HSM inventory; feeds the Assets pipeline

Crypto Vulnerability Watch

NIST NVD CVE digest for the products on your /migrate selection, joined via CPE — the top CVEs per product by severity from the current snapshot

Infrastructure Modernization Planner

Phase 6 deliverable — consolidates the PKI modernization plan, HSM/KMS upgrade schedule, network/middlebox compatibility report, and PQC capacity plan into one infrastructure-readiness artifact

Refresh-Cycle Alignment

Phase 4 Activity 4.3 — maps PQC migration tasks onto already-funded infrastructure refresh programs (data center, SD-WAN, cloud, PKI, HSM, vendor renewals) so PQC work rides existing budgets

Data-at-Rest Strategy

Phase 5 Activity 5.6 — per-store data-at-rest decision (re-encrypt under PQC keys, PQC key-wrap, crypto-shred, delete, or accept & monitor), recorded back into the CBOM

Migration Verification & Closure

Prove migration with the framework's 5-point evidence standard, log classical-key decommissioning (SP 800-88), and record program closure & BAU handover