A Field Guide to the Cryptographic Inventory in 2026

The cryptographic inventory has become the inventory the security team has been quietly dreading, the inventory the post quantum deadline is forcing the security team to build, the inventory the auditor has been asking for.

Dark cinematic editorial image for A Field Guide to the Cryptographic Inventory in 2026 - abstract cyan digital composition, hacker aesthetic, no text no logos

The cryptographic inventory has become the inventory the security team has been quietly dreading, the inventory the post quantum deadline is forcing the security team to build, the inventory the auditor has been asking for. The honest framing matters here, because the cryptographic inventory the security team has been treating as the spreadsheet the security team has been maintaining sits as the cryptographic inventory the post quantum migration will require the security team to actually automate.

What follows runs as the working version of the field guide. The shorter version is what the security team and the platform team actually have time to read.

What the inventory actually is

Three things, in roughly that order of how much each one matters. The first runs as the certificate list, where the list the inventory should produce, the list that names every certificate the enterprise has deployed, the list that includes the issuer, the expiry, the algorithm, the key length, the list the security team should be maintaining in the certificate management platform the security team should be using. The second runs as the key list, where the list the inventory should produce, the list that names every cryptographic key the enterprise has deployed, the list that includes the algorithm, the length, the rotation schedule, the storage location, the list the security team has been struggling to build because the key sits in the HSM, the cloud KMS, the application config. The third runs as the algorithm usage, where the usage the inventory should track, the usage that says which application uses which algorithm, the usage the migration roadmap needs to know what to migrate, the usage the security team has been quietly postponing because the inventory the security team has been using does not track the usage.

What the typical build misses

Three things, in roughly that order of how often each one shows up. The first runs as the embedded certificate, where the certificate the developer embedded in the application, the certificate the developer shipped in the device, the certificate the security team does not know about, the certificate the inventory the security team has been maintaining does not track. The second runs as the legacy system, where the system the security team cannot scan, the system the scanner does not have access to, the system the inventory the security team has been maintaining does not include, the system the security team has been quietly skipping because the system sits in the operational technology the security team does not have the access to. The third runs as the third party certificate, where the certificate the third party issued, the SaaS, the supplier, the certificate the security team cannot rotate, the certificate the security team has been treating as the third party’s problem, the certificate the inventory needs to track for the expiry the security team will be reminded of too late.

How to land the inventory the post quantum deadline needs

Three moves if you are the security team that wants the cryptographic inventory the post quantum deadline will require. Automate the discovery, where the discovery the scanner (the Qualys SSL Labs, the testssl.sh, the cloud CSPM) the security team can run continuously, the discovery the security team should be running against the production, the discovery the security team can configure to alert on the new certificate, the discovery the security team cannot build without the scanner. Build the SBOM, where the SBOM (the CycloneDX, the SPDX) the development team should be generating, the SBOM that includes the cryptographic dependency, the SBOM the platform team can ingest into the inventory, the SBOM the security team should be requiring the vendor to provide. Map the algorithm to the application, where the application the security team should be cataloguing, the application the security team should be mapping to the algorithm, the application the security team should be using to plan the migration, the application the security team can use to produce the post quantum roadmap the security team can defend. The team that automates, builds the SBOM, and maps the algorithm serves as the team that has landed the inventory the post quantum deadline needs.

Abstract cryptographic inventory as glowing cyan stacked certificates on a dark navy surface, dramatic chiaroscuro lighting from above.
Cryptographic inventory in 2026: 3 things the inventory actually is, 3 things the typical build misses, 3 moves to land the inventory the post quantum deadline needs.

The bottom line

Cryptographic inventory in 2026 sits as the inventory the security team has been quietly dreading. The certificate list, the key list, the algorithm usage, those three are what the inventory is. The embedded certificate, the legacy system, the third party certificate, those three are what the build misses. The automated discovery, the SBOM, the algorithm to application map, those three are the moves. The team that does the three lands the inventory. The team that has the spreadsheet does not.



Sources & Further Reading

All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.

Spotted an error? Email the editor. Corrections are issued with a visible correction note.

Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.

Continue reading