Migration Planning / Management Tools Audit

What this is for: Audit your discovery, assessment, configuration, and enforcement tooling stack — feeds the Information Repository per CSWP.39 §5.

What a good answer looks like: You know which of your own tools would have to change before a single production key does.

Worked example: Rate your coverage — None, Manual, Partial or Automated — for each of the seven categories from Asset Management (CMDB / SBOM pipeline) to Zero-Trust Enforcement: the gap list, ordered by importance, says which tool has to change before a production key does.

Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.

Browse all Business tools · Browse PQC learning modules

For your role

Executive / Business Leader
Rate coverage None, Manual, Partial or Automated for the seven tool categories from crypto scanners to zero-trust enforcement: the gap list, ordered by importance, says which tool has to change before a production key does.
GRC / Risk & Compliance
Enter the systems covered by each category and the coverage level: the export records the management-tools gap the CSWP.39 §5 step 3 audit requires, with the ordering already applied.

CSWP.39 §5 step 3 (Identify Gaps) requires auditing the Management Tools layer — the discovery, assessment, configuration, and enforcement tooling that keeps your crypto inventory and risk data current. Without these tools, your Risk Analysis Engine operates on incomplete, manually maintained data. Rate your current coverage for each tool category, then review the gap recommendations.

Crypto ScannersNone

Detect algorithms, key lengths, cert details across source code and network traffic.

CPM: Inventory + Observability · CSWP.39 §5 (Identify Gaps step)
Coverage level
Systems covered: 0%

Deploy a crypto scanner (e.g., Keyfactor Discovery, Venafi TLC, or open-source cryptoscan) in passive mode against at least one production network segment.

Vulnerability ManagementNone

CVE feeds, crypto library EoL tracking, CMVP historical-cert alerts.

CPM: Assurance · CSWP.39 §5 (Identify Gaps step)
Coverage level
Systems covered: 0%

Subscribe to the NIST CMVP change-notice feed and NVD API for crypto CVEs. Create a weekly triage task.

Asset Management (CMDB / SBOM pipeline)None

SBOM generation, CBOM enrichment, and CMDB feeds that keep the crypto asset inventory current.

CPM: Inventory · CSWP.39 §5 (Inventory step)
Coverage level
Systems covered: 0%

Generate a CycloneDX SBOM for your top 5 critical applications using Syft or cdxgen.

Configuration Management (Policy-as-Code / CLM)None

Crypto policy-as-code enforcement and certificate-lifecycle management — pushing approved algorithms and cert renewals to systems automatically.

CPM: Configuration · CSWP.39 §5 (Identify Gaps step)
Coverage level
Systems covered: 0%

Adopt a certificate-lifecycle management (CLM) tool (e.g., Venafi, Keyfactor Command, HashiCorp Vault PKI) for at least one critical CA chain.

Log Management / SIEMNone

Crypto-drift events, cipher-suite anomalies, protocol-version alerts in real time.

CPM: Observability · CSWP.39 §5 (Identify Gaps step)
Coverage level
Systems covered: 0%

Configure TLS handshake logging on at least your public-facing load balancers; route to your SIEM.

Zero-Trust EnforcementNone

Policy engines that block disallowed cipher suites at the network layer; mTLS enforcement.

CPM: Governance · CSWP.39 §4.3 (service mesh / zero-trust)
Coverage level
Systems covered: 0%

Define a crypto policy baseline (minimum TLS 1.2, approved cipher suites); document it in Governance.

Data Classification ScannersNone

Classify data assets by sensitivity to drive inventory prioritisation.

CPM: Inventory · CSWP.39 §5 (Govern step)
Coverage level
Systems covered: 0%

Manually classify your top-10 data repositories by sensitivity (public / internal / confidential / restricted).

Tool-chain Completeness
0%

How this is scored: each tool's coverage level (None 0 → Automated 3) is multiplied by its importance to a PQC migration, summed, and divided by the maximum possible weighted total. It is a weighted average, not a plain one — the four foundational tools (crypto scanners, vulnerability management, asset management, configuration management) each count three times as much as data classification. Systems-coverage percentages are yours to enter; nothing seeds them, because a count of detected products says nothing about how much of your estate they reach.

Coverage heatmap
Crypto Scanners
None · 0% systems
Vulnerability Management
None · 0% systems
Asset Management
None · 0% systems
Configuration Management
None · 0% systems
Log Management / SIEM
None · 0% systems
Zero-Trust Enforcement
None · 0% systems
Data Classification Scanners
None · 0% systems
Priority gaps (7)
Crypto Scanners — currently None
Vulnerability Management — currently None
Asset Management (CMDB / SBOM pipeline) — currently None
Configuration Management (Policy-as-Code / CLM) — currently None
Log Management / SIEM — currently None
Zero-Trust Enforcement — currently None
Data Classification Scanners — currently None
CSWP.39 §5: Discovery, assessment, configuration, and enforcement tooling must be automated — not manual surveys. Tool-chain completeness score below 75% means the Risk Analysis Engine (Step 7) is operating on incomplete data.

Management Tools Audit — Export

Save this audit to your Command Center under the Management Tools zone, or export as markdown / PDF / DOCX for sharing.

Try it

Rate a category "None". Where does it land in the output?

Next step

Next in Migration Planning: Crypto BOM (CBOM) Builder

Crypto BOM (CBOM) Builder is the next Migration Planning tool in the Command Center.