Establish comprehensive cryptographic inventory per NIST SP 1800-38 covering: algorithms in use + key sizes + storage location + system dependencies + protocol bindings (TLS/IPsec/SSH/PKI/HSMs) + applications + microservices + IoT/OT devices. Develop PQC migration roadmap per CNSA 2.0 timeline (2025 transition for new procurements + 2030 software/firmware/services + 2031 NSS networks + 2033 NSS endpoints + 2035 full transition) + White House M-22-09 federal civilian deadlines + ENISA recommendations + NIST SP 800-208 stateful HBS for current use. Prioritise high-risk systems: long-lived encrypted data + harvest-now-decrypt-later (HNDL) threat + root CAs + identity certificates.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.