The inventory should record when and where quantum-vulnerable cryptography protects the most sensitive and critical datasets, with estimates of how long those datasets need protection, because data taken now can be decrypted later. Organizations should correlate the cryptographic inventory with existing programmes (asset inventory, identity, credential and access management, endpoint detection and response, continuous diagnostics and mitigation), understand which systems and protocols move or access their most sensitive data, and identify quantum-vulnerable cryptography protecting critical processes, especially in critical infrastructure.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.