Education
Crypto discovery methods compared
No single discovery method inventories your full cryptographic estate. Here is the structural divide every PQC vendor is anchored to — and why Qtangl leads with agentless external plus verifiable evidence.
Five discovery methods
| Method | What it finds | Blind spots |
|---|---|---|
| Agentless external | TLS, JWKS, SSH, email, CT logs | Internal hosts, code, dormant keys |
| Host / endpoint agents | Keystores, memory, filesystem crypto | Legacy/OT without agents |
| Source / binary scan | Algorithms in repos and builds | Runtime-loaded crypto |
| Key / KMS | Keys in cloud KMS, Vault, HSM | Wire-exposed protocol posture |
| Certificate / CLM | Managed certs and issuance | JWKS, SSH, non-cert crypto |
NIST NCCoE and industry guidance: combine 2–3 methods for a complete picture.
How vendors anchor
- Qtangl, Qinsight, ExeQuantum, QuSecure R3, Palo Alto — agentless or network-telemetry first
- SandboxAQ, Keyfactor — host-agent depth
- IBM Quantum Safe — code-first
- Fortanix — KMS-centric
- DigiCert, AppViewX, CyberArk — CLM-centric
Qtangl's position
We are the fastest external baseline — minutes to inventory without agent rollout. We do not claim full-estate coverage. We are the neutral evidence layer that signs merged CBOMs from any source.
See the discovery method heatmap and full comparison hub.
Continue on the Q-Day hub: Vendor comparison hub
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- NIST IR 8547: Transition to Post-Quantum Cryptography StandardsNIST · 2024Federal transition guidance with deprecation timelines for quantum-vulnerable algorithms.
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.