Crypto-agile security against quantum attacks
Compliance deadlines for CNSA 2.0, NIST, and federal PQC mandates are already here. Quill discovers every key, certificate, and cryptographic operation across your infrastructure, so you can remediate risk and answer to auditors and boards with evidence.

What we do
Quantum risk research and guidance
Cryptographic asset discovery and inventory
Direct migration planning
Orchestrate remediation and compliance
The cryptographic assets to inventory and migrate
Below is a list of the different assets and attack points for quantum computers, organized by discovery and remediation effort. Quill works to streamline both processes in a hands-free manner.
JWT & token signing
TLS / SSL key exchange
Service-mesh / internal mTLS
SSH keys
Email: S/MIME & PGP
Database & storage encryption
DNS / DNSSEC
VPN / IPsec
Code-signing & digital signatures
Auth tokens: FIDO2 / PIV
X.509 PKI & certificate authorities
Third-party / SaaS / supply-chain
HSMs & embedded / IoT firmware
Manual migration costs years you don't have.
Certificates, keys, and code call sites are automatable. Quill discovers them and generates the diff. Size your company and see both.
Scroll the table sideways for the full breakdown.
| Class | Count | By hand | Automated | Tool role |
|---|---|---|---|---|
| Discovery § | n/a | $4,200,000 | $120,000 | automated ‡ |
| Certs & keys | 250,000 | $18,750,000 | $2,812,500 | automated ‡ |
| Code sites | 6,000 | $7,200,000 | $1,080,000 | automated ‡ |
| Redesign * | 20 | $600,000 | $600,000 | flag only |
| Hardware † | 40 | $944,000 | $944,000 | flag only |
| Total | $31,694,000 | $5,556,500 |
MeasuredOne Quill scan: 22:22 wall clock, unattended. 47 hosts, 149 cryptographic assets, graded and written to a CycloneDX CBOM.
- †
Hardware capex: $20,000 per unit
A mid-blend of HSM firmware upgrade ($5–15k) against full replacement ($40–60k, Thales Luna-class); appliances typically sit lower. With labor, $23,600 per unit in the model.
- *
Redesign: $30,000 per system
200 hr of structural rework at $150/hr, for a system with no drop-in path. No public per-unit benchmark exists at this granularity; directionally consistent with hardcoded and legacy migrations reported at 4–6+ years.
- †
Hardware labor: $3,600 per unit
24 hr to procure, swap, and revalidate at $150/hr, excluding the capex above.
- ‡
Automation: 85% of the config and code population
Estimated cost saved through crypto-agile automation through testing.
- §
Tooled discovery: scales with estate size
Best market estimate for automated cryptographic discovery: roughly $8–15k small, ~$50k mid-market, $120k+ enterprise. Triangulated from the CLM market.
The dates are fixed. Your procurement cycle is not.
- New NSS acquisitions compliantDue Jan 1, 2027 · CNSSP 15 · enforcement from Dec 31, 2025
- CBOM minimum elements publishedDue Mar 19, 2027 · EO 14412 · 270 days from signing
- Non-capable equipment phased outDue Dec 31, 2030 · CNSSP 15 · 2024 update
- Sensitive federal systems transitionedDue Dec 31, 2030 · EO 14412 · contractors to meet PQC FIPS
- CNSA 2.0 algorithms mandatedDue Dec 31, 2031 · CNSSP 15 · 2024 update
- Post-quantum authenticationDue Dec 31, 2031 · EO 14412 · signed June 22, 2026
- All NSS quantum-resistantDue Jan 1, 2035 · NSM-10 · issued May 4, 2022
- Dec 31, 2025CNSSP 15No CNSA 2.0 transition requirement enforced before this date.
- Jan 1, 2027CNSSP 15All new NSS acquisitions must be CNSA 2.0 compliant unless otherwise noted.
- ~Mar 2027EO 14412CISA, with NIST, to publish minimum elements for a cryptographic bill of materials, 270 days from signing, and they must enable automated assessment.
- Dec 31, 2030CNSSP 15Equipment and services that cannot support CNSA 2.0 must be phased out; NSA expects equipment transitions complete. Federal agencies to transition most sensitive systems; contractors to meet PQC FIPS.
- Dec 31, 2031EO / CNSSPCNSA 2.0 algorithms mandated for use; post-quantum authentication required.
- 2035NSM-10Goal: all National Security Systems quantum-resistant.
Where the PQC deadlines come from.
Two federal instruments set the migration timeline. Each binds a different scope, and together they shape what the rest of the industry is planning against.
CNSA 2.0
Binds National Security SystemsNSA states directly that it is not using these requirements to dictate algorithm choices to entities outside NSS, while acknowledging interoperability may lead a wider community to adopt them.
NSS owner, DoD, or Defense Industrial Base: this is a requirement. Commercial enterprise with no NSS interface: authoritative guidance, not a mandate.
Executive Order 14412
Reaches much further · Signed June 22, 2026Sets deadlines for federal agencies and extends obligations to federal contractors via the FAR. First federal directive to name the cryptographic bill of materials as a defined artifact. CISA with NIST is to publish minimum elements by roughly March 2027, and those elements must enable automated assessment.
The practical test: do you sell to the federal government, or to anyone who does? If yes, EO 14412 reaches you regardless of CNSA 2.0's NSS scope.
Built for crypto agility.
Quill is built around one idea: crypto-agility. Post-quantum is the migration in front of you, not the last one. If every product, gateway, and store picks its own scheme in code, the next swap is another hunt across the network. Resolve those call sites from one protocol and the transition after this one costs the same single edit instead of another full pass over every call site.
See a free scan of your external domain with Quill.
Quill reads what your domain already publishes: TLS key exchange, certificate chains, and signature algorithms. It grades each one against CNSA 2.0 from the outside, leaving your systems untouched. Tell us where to send the result and we'll walk you through it.