Migration Planning / Crypto API Refactor Audit
§4.1What this is for: Architect + senior-developer audit from CSWP.39 §4.1 - grades current crypto-agility state and emits a phased refactor checklist with language-specific call-site guidance (Go / Java / .NET / Node / Python / Rust / C / C++ / JS).
What a good answer looks like: A list of call sites, not a list of libraries. The refactor happens where the API is called, and that is where the estimate has to come from.
Worked example: Choose Go, OpenSSL (libcrypto / EVP), '10 - 50 call sites' and 'Partially hardcoded': the audit grades it 'Phase 2 - Complete the facade', and the checklist names the Go imports to grep for outside the facade and a lint rule to ban them.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Developer / Engineer
- Enter the application type, language and the crypto APIs in use (OpenSSL EVP, BoringSSL, libsodium, BouncyCastle, .NET, Web Crypto, JCE, PKCS#11), the call-site count and how hardcoded they are: the plan is a phased refactor checklist by call site with language-specific guidance.
Crypto API Refactor Audit
Architect + senior-developer decision tool from NIST CSWP 39 Section 4.1 - Using an API in a Crypto Library Application. Grades the application's current crypto-agility state and emits a phased refactor checklist with language-specific call-site guidance.
Agility lives at the API boundary
An app that calls `RSA_sign()` directly is NOT agile; one that calls `EVP_DigestSign()` with the algorithm selected at run-time IS.
Wrap then refactor
Large fully-hardcoded surfaces refactor faster behind a thin facade than as a single big-bang change.
Providers vary in PQC timing
Build the fallback path explicitly - CSWP-39 Section 4.1 warns providers ship PQC at different times.
Step 1 - Stack inventory
Tell the audit engine what the application looks like today - language, providers, and the API surface in use.
Step 2 - Refactor scope
Pick the PQC target algorithms, estimate how many call sites are affected, and grade your current crypto-agility state.
Step 3 - Refactor plan (editable)
Edit the narrative carried into the exported audit. The audit checklist, facade pattern, and watch-outs are generated automatically.
- NIST CMVP — Cryptographic Module Validation
- NIST ACVP — Automated Crypto Validation Protocol
- NIST FIPS 203 — ML-KEM
- NIST FIPS 204 — ML-DSA
- NIST FIPS 205 — SLH-DSA
- Carnegie Mellon CyLab (Americas)
- UC Berkeley BQIC (Americas)
- Ruhr University Bochum Cryptography (EMEA)
- Max Planck Institute Security and Privacy (EMEA)
- Brno University of Technology (EMEA)
- Duke University Quantum Center (Americas)
Try it
What does the tool say a good refactor plan lists?
Next step
Next in Migration Planning: Cloud Responsibility MatrixCloud Responsibility Matrix is the next Migration Planning tool in the Command Center.