Why Choose Ciphersound Cipherscan

Fast-track your PQC compliance review with a simple, purpose-built tool

We provide a fast, secure, low-friction way to conduct a basic cryptographic posture assessment.

The invisible risk

PQC risk assessment is not a future problem. PQC compliance deadlines are in motion at the federal level, with NIST and CNSA 2.0 mandates already here and other frameworks expected to roll out soon. While no one knows for certain when “Q-Day” will arrive, organizations with long-value data are already at risk of “harvest now, decrypt later” attacks. With PQC migration alone taking months — and potentially years in complex environments — many companies are effectively already behind in their PQC implementation.

While manual cryptographic inventory auditing is time- and labor-intensive, automated tools available on market are complex and costly. To get board or leadership buy-in for investing into PQC migration, security and compliance leaders need to articulate the invisible risk with credible data about PQC readiness and posture. Ciphersound’s basic PQC posture assessment tool, Cipherscan, gives them exactly that — for free.

Fast answers without the overhead

  • Quickly get real data about PQC compliance to understand your cryptographic posture, with no agents to deploy and no complicated platforms to stand up.
  • Use Cipherscan reports to guide PQC readiness conversations in the boardroom and start the journey toward organizational preparedness.
  • Bring the same data to client conversations, giving consulting teams an accurate starting point for PQC discussions.

How Cipherscan gets it right

  • How Cipherscan works: Cipherscan runs a lightweight scan of your SSH and SSL/TLS services to check whether each host uses approved PQC algorithms or still relies on classical cryptography. Use a downloadable command-line tool (CLI), which uploads results to your dashboard automatically, or — if your environment doesn’t allow third-party tools — export your scan results and upload them manually through the browser instead.
  • What it doesn’t do: Cipherscan isn’t a full penetration test or a comprehensive cryptographic inventory tool. Currently, it focuses specifically on algorithm inventory across your internal SSH and TLS services.
  • What the report shows: Every scanned host receives a pass or fail status, along with an overall percentage indicating your PQC-ready share across all hosts. Regular scans, such as weekly over a quarter, help you monitor changes and track readiness progress.
  • How the data is handled: Cipherscan supports SSH and SSL/TLS scanning only. When results are imported, only data mapped to your configured scopes comes in; all other data is automatically discarded. The tool collects no telemetry beyond the scan data you choose to upload. Scan results are retained for two weeks.
  • Segregated environments: For consultants and security providers managing multiple organizations, Cipherscan ensures environments remain separated, preventing any customer data from crossing between organizations.

Register for a PQC risk assessment of your network’s assets

What we’re working on

The free-tier Cipherscan is available today with a simple registration. We are further developing the tool to help security and compliance teams go deeper and implement an ongoing PQC posture assessment program. 

Some of the capabilities under consideration include:

  • Policy creation and selection: Define policies such as hybrid cryptography, PQC-only or PQC fallback, or align with frameworks such as NIST and NIS2, and map scan results and reports accordingly.
  • Unlimited retention: Retain the scan data and report indefinitely to track PQC compliance over time.
  • Multi-organization access: Enable multiple organizations to onboard the same user to their accounts, allowing consultants to manage several clients from a single dashboard.
  • Advanced capabilities: Additional potential features include cryptographic inventory management and network traffic analysis.

Sign Up

Sign up for our newsletter