Migration Planning / Crypto Architecture Diagram
§5.4What this is for: Document apps, libraries, HSMs, protocols, key stores, and CAs with their dependencies; renders as a Mermaid diagram.
What a good answer looks like: Every trust boundary shows which algorithm crosses it. A diagram without algorithms on the arrows cannot tell you what breaks.
Worked example: Add a customer-facing web app, OpenSSL, a network HSM and an internal root CA with their dependencies: the Mermaid preview draws the chain, and the HSM's detail line says whether it has ML-DSA firmware yet.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- Add the applications, libraries, HSMs, protocols, key stores and certificate authorities with their dependencies: the diagram preview draws the chain and the detail lines say which components have post-quantum support yet.
- GRC / Risk & Compliance
- Capture each cryptographic component with its version and dependencies (for example an HSM's firmware and whether it has ML-DSA): the structured table and the Mermaid diagram are the inventory artefact, exportable as markdown or PDF.
Crypto Architecture Diagram
Capture every cryptographic component (apps, libraries, HSMs, protocols, key stores, CAs) and the dependencies between them. The artifact stores both the structured table and a Mermaid graph that renders inside the Command Center viewer — the diagram below updates live as you edit.
Aligned with NIST CSWP.39 §5.4 — Cryptographic Architecture.
Components
| Kind | Name | Detail (version, vendor, FIPS, PQC support) | Depends on (ids, comma-separated) | |
|---|---|---|---|---|
id: app-1 | ||||
id: lib-1 | ||||
id: hsm-1 | ||||
id: ca-1 |
Diagram preview
Diagram couldn’t render — see the list view.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Add an app, a library, an HSM and a CA with dependencies. What does the artefact store?
Next step
Next in Migration Planning: Management Tools AuditManagement Tools Audit is the next Migration Planning tool in the Command Center.