Vendor & Supply Chain / Supply Chain Risk Matrix
§5.3What this is for: Assess supply chain risks with dependency mapping and impact analysis.
What a good answer looks like: The suppliers you cannot replace inside your own deadline are visible at a glance. Those are the programme, the rest are logistics.
Worked example: Pick your products on Migrate and set your industry: a domain such as 'HSM-protected keys' gets PQC Ready, FIPS Validated, Hybrid Support and Known CVEs counts and a Migration Gap × Impact score, and one click downloads a CycloneDX CBOM.
Runtime and privacy: This planning tool runs in your browser. Use synthetic or approved organizational data and review the site privacy terms before entering sensitive material.
For your role
- Executive / Business Leader
- The matrix maps the products you selected on Migrate across TLS, VPN, SSH, email and messaging by migration gap and impact: the suppliers you cannot replace inside your own deadline are the programme.
- GRC / Risk & Compliance
- Read the Product Dependencies per domain with the catalogue evidence behind each cell; a product in the high-gap, high-impact corner is a third-party risk entry with its proof attached.
- /assess — compliance frameworks step— Step 5 captures policy + framework registry
- /compliance — framework explorer
- /leaders — stakeholder ecosystem
- /library — policy & governance docs
- NIST CSWP.39-upd1 — Considerations for Achieving Crypto Agility (Dec 2025, upd. Jun 2026)
- NIST IR 8547 — Transition to PQC Standards
- ENISA — Post-Quantum Cryptography Integration Study
- NIST Computer Security Resource Center (Americas)
- NIST News & Events (Americas)
- NSA Media Defense Portal (Americas)
- CISA Quantum Page (Americas)
- BSI Post-Quantum Cryptography (EMEA)
- ANSSI Cryptography Guidelines (EMEA)
Try it
Which products does the tool say are the programme rather than logistics?
Next step
Put it in your reportYour readiness report collects what the Vendor & Supply Chain tools produce.