DuoKey CPM (formerly PQC Scanner) — Overview
DuoKey CPM (formerly PQC Scanner)
Cryptographic Posture Management — comprehensive post-quantum readiness assessment and continuous crypto posture management.
Introduction
The DuoKey PQC Scanner is a high-performance Post-Quantum Cryptography (PQC) readiness assessment tool. It provides comprehensive cryptographic discovery and analysis across your entire infrastructure - from filesystem certificates and TLS endpoints to source code repositories and cloud KMS services.
The scanner evaluates quantum vulnerability using a 0-10 risk scoring scale with priority levels (P0-P4), generates CycloneDX 1.7 CBOM reports, checks compliance against 8+ frameworks (NIST, ISO 27001, PCI DSS, HIPAA, GDPR, FedRAMP, SOC 2), and integrates directly with ServiceNow for asset tracking and incident management.

Post-Quantum Cryptography (PQC) refers to cryptographic algorithms that are believed to be secure against attacks by both classical and quantum computers. In August 2024, NIST standardized the first set of PQC algorithms:
- ML-KEM (FIPS 203) - Module-Lattice-Based Key-Encapsulation Mechanism, formerly CRYSTALS-Kyber
- ML-DSA (FIPS 204) - Module-Lattice-Based Digital Signature Algorithm, formerly CRYSTALS-Dilithium
- SLH-DSA (FIPS 205) - Stateless Hash-Based Digital Signature Algorithm, formerly SPHINCS+
CLI Commands
The scanner exposes the following commands via the dke-scanner-agent binary:
| Command | Purpose | Output Formats |
|---|---|---|
| filesystem | Scan local directories for certificates, keystores, and keys | JSON, summary |
| domain | Classic SSL/TLS audit of a remote endpoint; add --pqc for the PQ readiness report | report, table, JSON, summary |
| ssh | Discover SSH keys (ssh-agent, user keys, host keys) and classify them | JSON, summary |
| inventory | One-shot full host inventory: filesystem sweep + SSH keys, plus (Windows) cert store, installed apps, and registry crypto policy | JSON, summary |
| source-code | Static analysis of source code for cryptographic usage patterns | JSON |
| ci | CI/CD mode with SARIF output and fail-on-severity thresholds | JSON, SARIF |
| cbom | Export findings as CycloneDX 1.7 Cryptographic Bill of Materials | JSON |
| qrs | Compute and render the Quantum Risk Score from a saved scan result | text, JSON, HTML |
| cloud | Scan a cloud KMS (AWS KMS; Azure/GCP placeholder) for key material | JSON, summary |
| vault | Scan a cockpit-managed vault for quantum-vulnerable keys (thin client) | JSON |
| fortinet | Scan a FortiGate/FortiOS device via its REST API | JSON, summary |
| jfrog | Scan a JFrog Artifactory instance for cryptographic material | JSON, summary |
| terraform | Scan Terraform state and HCL for cryptographic resources | JSON, summary |
| packet-capture | Offline analysis of a .pcap/.pcapng file for TLS handshakes + PQ group usage | JSON, summary (feature-gated) |
| network | Live capture from a network interface for TLS handshakes + PQ group usage | JSON, summary (feature-gated) |
| agent | Run as a persistent process reporting heartbeats to a DKE Cockpit server | - |
| enroll | First-time enrollment with a cockpit server | - |
| upload-scan | Run a one-shot TLS scan and upload the result to the cockpit | - |
Packet capture (.pcap/.pcapng) analysis and live network capture are feature-gated — they require the pcap / pcap-live build features respectively. All other commands are fully implemented.
Scanning Capabilities
From Run a Scan → Step 1 (Source) in the Cockpit you pick what to scan. Sources are grouped into Filesystem, Agent (host inventory), Network (Domain/TLS, TLS Probe, Network Live, Packet Capture), Code & Repos (Source Code, SSH Keys), Cloud / Vault, and SaaS / DevOps (JFrog Artifactory, Terraform IaC, Fortinet).

Filesystem Scanner
- PEM, DER, PKCS#12/PFX, JKS/JCEKS certificates
- Private key algorithm and size detection
- Windows Certificate Store (LocalMachine, CurrentUser)
- Configurable depth, extensions, exclusions
Domain Scanner
- TLS handshake inspection (TLS 1.2/1.3)
- Full certificate chain extraction
- Cipher suite and key exchange detection
- Subdomain discovery via WhoisXML API
- Optional PQ key exchange detection (packet capture)
Source Code Scanner
- 150+ detection rules across 8 languages
- Java, Python, Go, Rust, C#, TypeScript, JavaScript, C/C++
- GitHub, GitLab, Azure DevOps integration
- SARIF output for CI/CD pipelines
Cloud Scanner
- AWS KMS key inventory and algorithm analysis
- Azure Key Vault enumeration
- GCP Cloud KMS metadata retrieval
- REST API-based (no SDK dependencies)
Risk Scoring
The scanner uses a 0-10 quantum risk scale with priority levels:
| Priority | Score | Severity | Action Timeline | Examples |
|---|---|---|---|---|
| P0 | 9.0-10.0 | Critical | Immediate | RSA <2048, DSA, 3DES, RC4 |
| P1 | 7.0-8.9 | High | Within 3 months | RSA-2048, ECDSA P-256, EdDSA |
| P2 | 5.0-6.9 | Medium | Within 6 months | RSA-3072 |
| P3 | 3.0-4.9 | Low | Within 12 months | RSA-4096 |
| P4 | 0-2.9 | Info | Monitor | ML-KEM, ML-DSA, SLH-DSA (PQC algorithms) |
Output Formats
| Format | Flag | Use Case |
|---|---|---|
| JSON | --format json | API integration, automation, programmatic processing |
| YAML | --format yaml | Human-readable configuration and documentation |
| HTML | --format html | Interactive visual reports with embedded CSS |
| Terminal | --format terminal | ANSI colored output with Unicode box drawing |
| SARIF | --format sarif | GitHub/GitLab security tabs (CI mode only) |
| CBOM | dke-scanner-agent cbom | CycloneDX 1.7 Cryptographic Bill of Materials |
Compliance Engine
Built-in compliance checking against 8+ regulatory frameworks:
NIST Standards
- SP 800-52 (TLS Guidelines)
- SP 800-131A (Cryptographic Standards)
- CNSA 2.0 (NSA PQC guidance)
International Standards
- ISO 27001 / 27002
- ETSI Quantum-Safe
- BSI TR-02102 (German PQC Migration)
Industry Compliance
- PCI DSS v4.0
- HIPAA (US Healthcare)
- GDPR (EU Data Protection)
Audit Frameworks
- SOC 2 Type II
- FedRAMP
- Custom PDF-based policies
ServiceNow Integration
Direct integration with ServiceNow for centralized asset tracking and automated incident management.
ServiceNow Features
Asset Publishing
Push findings to custom CMDB tables
Auto-Incidents
Automatically create incidents for P0/Critical findings
Authentication
Basic Auth or OAuth Bearer tokens
Architecture
The PQC Scanner uses a modular architecture: independent scanner modules feed a shared quantum risk-scoring engine and a common output layer, with an optional web dashboard for interactive review.
Cryptographic Discovery Engine
Multi-protocol scanning & deep inspection
Protocol & cipher-suite detection
Cryptographic Bill of Materials
Vulnerable crypto-function detection
X.509 algorithm & key-size analysis
Filesystem & Windows cert store
PQC Readiness Analyzer
Quantum Readiness Score (0–100) & per-asset prioritization
PQC Readiness Dashboard
Actionable insights & migration roadmap
Automated Discovery
Network-wide crypto inventory
Continuous Monitoring
Real-time vulnerability tracking
Compliance Reports
NIST, BSI PQC standards
Migration Tracking
Progress monitoring & validation
Scanner Pipeline
Web Dashboard
The interactive dashboard is the PQC Readiness module inside DuoKey Cockpit — dke-scanner-agent is a CLI/agent for running scans, not a standalone web server. Upload or push a scan result to the Cockpit to view it on the dashboard.
Dashboard Capabilities
Real-Time Visualization
Scan results with risk scoring and distribution charts
Authentication
Cockpit session authentication (SSO / password), same as the rest of the platform
REST API
Cockpit REST API for scans, findings, CBOMs and compliance
Use Cases
Financial Services
PCI DSS 4.0 compliance with quantum risk assessment for payment systems
Healthcare
HIPAA compliance with 'harvest now, decrypt later' protection for PHI
Enterprise IT
Full crypto inventory across legacy systems, cloud KMS, and source code
Cloud Infrastructure
AWS KMS, Azure Key Vault, and GCP Cloud KMS quantum readiness
Government & Defense
CNSA 2.0 and FedRAMP compliance for classified systems
DevSecOps
CI/CD integration with SARIF output and fail-on-severity thresholds
System Requirements
| Component | Minimum | Recommended |
|---|---|---|
| Operating System | Windows 10, Linux (Ubuntu 20.04+), macOS 11+ | Windows 11, Ubuntu 22.04+ |
| Memory | 4GB RAM | 8GB RAM |
| Storage | 5GB available | 10GB SSD |
| Network | Outbound HTTPS to scan targets | Dedicated scanning network |
Current estimates suggest large-scale quantum computers capable of breaking RSA-2048 and ECC P-256 could emerge in the 2030s. However, "harvest now, decrypt later" attacks are already a concern for long-lived sensitive data. Start your PQC assessment today!