Migration Planning / Crypto API Refactor Audit

What this is for: Architect + senior-developer audit from CSWP.39 §4.1 - grades current crypto-agility state and emits a phased refactor checklist with language-specific call-site guidance (Go / Java / .NET / Node / Python / Rust / C / C++ / JS).

What a good answer looks like: A list of call sites, not a list of libraries. The refactor happens where the API is called, and that is where the estimate has to come from.

Worked example: Choose Go, OpenSSL (libcrypto / EVP), '10 - 50 call sites' and 'Partially hardcoded': the audit grades it 'Phase 2 - Complete the facade', and the checklist names the Go imports to grep for outside the facade and a lint rule to ban them.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Developer / Engineer
Enter the application type, language and the crypto APIs in use (OpenSSL EVP, BoringSSL, libsodium, BouncyCastle, .NET, Web Crypto, JCE, PKCS#11), the call-site count and how hardcoded they are: the plan is a phased refactor checklist by call site with language-specific guidance.

Crypto API Refactor Audit

Architect + senior-developer decision tool from NIST CSWP 39 Section 4.1 - Using an API in a Crypto Library Application. Grades the application's current crypto-agility state and emits a phased refactor checklist with language-specific call-site guidance.

Agility lives at the API boundary

An app that calls `RSA_sign()` directly is NOT agile; one that calls `EVP_DigestSign()` with the algorithm selected at run-time IS.

Wrap then refactor

Large fully-hardcoded surfaces refactor faster behind a thin facade than as a single big-bang change.

Providers vary in PQC timing

Build the fallback path explicitly - CSWP-39 Section 4.1 warns providers ship PQC at different times.

Step 1 - Stack inventory

Tell the audit engine what the application looks like today - language, providers, and the API surface in use.

Step 2 - Refactor scope

Pick the PQC target algorithms, estimate how many call sites are affected, and grade your current crypto-agility state.

Step 3 - Refactor plan (editable)

Edit the narrative carried into the exported audit. The audit checklist, facade pattern, and watch-outs are generated automatically.

Try it

What does the tool say a good refactor plan lists?

Next step

Next in Migration Planning: Cloud Responsibility Matrix

Cloud Responsibility Matrix is the next Migration Planning tool in the Command Center.