Discover what you actually depend on
Certificates and keys are only the beginning. Examine cryptography in services, hosts, containers, software and nested archives. Each finding retains its discovery path, so your team can trace it back to the source.
Private and symmetric keys are supported through metadata collection. Normal inventory and offline results describe the keys without retaining their secret values by default.
Choose remote scanning, a portable agent that runs once, or offline collection. Coverage depends on the sources, formats and access you select; review collection gaps alongside the findings.
See the relationships behind the inventory

A list tells you what you found. Relationships help you understand what a change could affect. Connect properties, sources and related assets, then use that evidence in technical reviews and CBOM workflows.
Put requirements beside the evidence

Assess observed algorithms, key characteristics and certificate validity against configured policies. Separate issues that need attention from planned transitions, with the applicable framework in view.
Policy findings support your assessment; they do not establish organizational compliance on their own.
Make supplier conversations specific

Some changes depend on someone else’s roadmap. Bring PKI Consortium PQCMM evidence alongside identified products and versions. See where evidence is available and where you need to ask the supplier.
Give each team a useful next step
The Dashboard, Executive Brief, Program Plan and Technical Queue turn the same assessment into views for sponsors, program leads and engineers. Repeat assessments to revisit findings as systems and policies change.
