Risk & Strategy / Initial Scoping Assessment
§5What this is for: Phase 0 first-cut scope — top-20 in-scope systems, an estate-size estimate, and the top-10 vendor dependencies; seedable from your /migrate selection.
What a good answer looks like: An honest inventory gap. "We do not know what is in this estate" is a finding, and often the most valuable one.
Worked example: List 'Customer-facing TLS gateway' as system 1 with priority A and owner Vendor, enter 2400 as the estate estimate and name OpenSSL, Microsoft and F5 as vendor dependencies: the export is a numbered systems table, the estimate and vendors.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- List the top in-scope systems, give an estate-size estimate and the top vendor dependencies, seeded from your Migrate selection: an honest inventory gap is a finding, and often the most valuable one.
- GRC / Risk & Compliance
- Triage each system as internal or external with its protocols and sensitivity, and enter the estate-size estimate: the export is the Phase 0 scope statement the later inventory is measured against.
Initial Scoping Assessment
Phase 0 rapid first-cut: your top 20 systems triaged by priority and owner, a rough estate-size estimate, and your top 10 vendor dependencies.
Triage the top 20 by priority tier (A = internet-exposed + long-lived secrecy/trust; B = internal Tier-1; C = everything else) and owner. The detailed crypto per system belongs in the CBOM Builder — this stays a rapid triage.
Rough count of cryptographic instances (keys, certificates, library call-sites, protocol endpoints). Calibrates Year 1 FTE sizing.
Capped at 10 — Framework Activity 0.5 asks for the 5–10 vendors whose PQC readiness will most constrain your migration timeline.
Initial Scoping Assessment — Export
Save this scope to your Command Center under the Governance zone, or export as markdown / PDF / Word. This seeds the Discovery & Inventory phase that follows.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
What does the tool call the most valuable finding of a first scoping?
Next step
Put it in your reportYour readiness report collects what the Risk & Strategy tools produce.