Skip to main content

Understanding Scanner Results

Applies to:
PQC Readiness DashboardQuantum Readiness ScoreCBOMFindings & Severity

The PQC Readiness dashboard​

After a scan, results are summarized on the PQC Readiness dashboard. The headline widgets give you posture at a glance, and the tabs (Scans, Crypto Assets, CBOMs, Compliance, Migration, Policies) let you drill in.

PQC Readiness dashboard

WidgetWhat it tells you
PQC ScoreThe headline gauge — your overall quantum readiness
ComplianceShare of assets meeting the selected framework(s)
RiskAverage per-asset quantum risk (0–10)
VulnerableShare of assets using quantum-vulnerable cryptography
PolicyPolicy-compliance rate across scanned assets

Quantum Readiness Score (QRS)​

The QRS is a composite 0–100 score with four readiness bands. It is the best single number to track over time and to report to stakeholders.

ScoreBandMeaning
90–100Advanced readinessQuantum-safe / hybrid widely deployed
70–89Developing readinessMigration well under way
40–69Early readinessMostly classical — moderate HNDL exposure
0–39Low readinessClassical only — high HNDL exposure

The report's score & signal breakdown shows exactly how the number was earned across the four signals (Algorithm Resilience, Crypto Agility, Harvest Exposure, Migration Posture) and their sub-signals:

QRS score and signal breakdown

Tip
For the full scoring formula, weights, bands and profiles, see QRS Scoring.

Per-asset findings​

Each finding is an individual discovered asset (a certificate, key, keystore or endpoint). It carries a quantum risk score (0–10), a severity, and a priority that orders your remediation queue.

SeverityPrioritySuggested timeline
CriticalP0Immediate
HighP1Within 3 months
MediumP2Within 6 months
LowP3Within 12 months
InfoP4Monitor

A finding includes the asset location, the detected algorithm and key size, the certificate metadata, the risk assessment (severity, priority, reasons), and a recommended action.

Certificate risk quick reference​

AlgorithmRiskAction
RSA-2048 / ECDSA P-256HighPlan migration to hybrid / ML-DSA
RSA-1024, DSA, 3DES, RC4, MD5CriticalReplace immediately
RSA-4096 / ECDSA P-384Medium–HighAcceptable short-term; schedule migration
AES, ChaCha20-Poly1305, SHA-2Low / InfoQuantum-safe — no action
ML-KEM / ML-DSA / HybridLowPost-quantum — target state

CBOM — Cryptographic Bill of Materials​

The CBOM Explorer renders the CycloneDX inventory as an interactive graph. It surfaces the share of components that are quantum-broken or weak, lets you isolate vulnerable primitives, and shows a recommended migration for each one.

CBOM Explorer

Note
Selecting a component shows its identifiers (BOM-Ref, OID, key type/size, format), its quantum-exposure classification, and the recommended post-quantum replacement (e.g. ML-DSA / SLH-DSA per NIST FIPS 204/205). See the CBOM Guide.

Taking action​

Triage by priority

Start with P0/P1 findings on public-facing and high-value systems.

Adopt hybrid first

Deploy hybrid (classical + ML-KEM) to gain protection without breaking compatibility.

Rotate certificates

Reissue quantum-vulnerable certificates with PQC or hybrid as they come up for renewal.

Track the QRS

Re-scan regularly and watch the QRS trend upward as you migrate.

Export & reporting​

FormatUse
PDFExecutive Quantum Risk Assessment report
CycloneDX CBOM (JSON)Machine-readable cryptographic inventory
JSON / YAMLAutomation and integrations
SARIFCI/CD security tabs (GitHub / GitLab / Azure DevOps)

Next steps​