An inventory is not a plan.
QSRAP is the governance tier above discovery. It consolidates every CADP estate you run, enriches each asset with the business context that discovery cannot see, scores quantum risk quantitatively, and turns the result into a migration plan somebody can actually be held to.
Live and multi-tenant today with early-access customers. There can be several CADP instances per region; there is one QSRAP above them.
Discovery answers what. It cannot answer what first.
CADP will tell you that four thousand systems use RSA-2048. It has no way of knowing which of them carries data that must stay confidential into the 2040s, or which one a regulator will ask about first.
No business context
A sensor sees a certificate on a host. It does not see the owner, the data classification, the contractual retention period or the fact that the system is due for decommission anyway.
Many estates, one obligation
Regions, subsidiaries and acquisitions each end up with their own discovery. The regulator asks one question of the whole group, and nobody can answer it from four separate consoles.
Risk without arithmetic
High, medium and low on a slide is not a risk position. Mosca's inequality gives you an actual inequality, and it needs numbers you have to collect deliberately.
Plans that go stale
A migration plan built on last quarter's spreadsheet diverges from the estate the moment it is published. A plan built on live discovery does not.
Shelf life + migration time > time to a cryptographically relevant quantum computer
Mosca's inequality. If it holds for a system, you are already late for that system — and QSRAP tells you which ones.
From observed facts to a defensible plan.
QSRAP never recomputes what CADP already decided. It ingests the verdicts and the full artifacts losslessly, then does the work discovery cannot.
Consolidate
Pull inventories from every CADP instance you operate. Assets keep their provenance, so a finding can always be traced back to the sensor that observed it.
Enrich
Attach owner, business criticality, data sensitivity and required confidentiality lifetime — the inputs discovery has no way to determine.
Score
Compute a multi-factor quantum risk score per asset and roll it up by system, business unit and framework control.
Plan
Sequence the migration by score and dependency, track it against the plan, and produce the evidence pack when someone asks.
What it adds.
Everything here is work that has to happen somewhere. Today it usually happens in a spreadsheet that one person maintains.
Cryptographic inventory
Beyond what sensors see
Twenty-five-plus asset types including HSMs, certificate authorities, keys, protocols and vendor components — so the parts of the estate no scanner can reach are still governed.
Quantitative risk scoring
MQRS
A multi-factor quantum risk score built on Mosca's inequality and the CARAF framework, producing a number you can sort by and defend, rather than a colour.
Compliance mapping
Framework-agnostic
Map assets and findings to control sets across NIST CSF, SP 800-53, ISO 27001, PCI DSS and regional frameworks, and show the same estate through whichever lens the auditor brought.
Migration planning
Sequenced and tracked
Turn the ranked inventory into projects with owners, dependencies and dates, then track actual progress against the plan as new discovery arrives underneath it.
Vendor readiness
The supply chain
Track each vendor's post-quantum roadmap and assess it. A significant share of your migration is not yours to perform, and that needs managing as its own workstream.
Findings workflow
Including risk acceptance
Assessment findings with ownership, remediation and formal risk acceptance, so a decision not to act is recorded as a decision rather than a gap.
Multi-tenant by design, with schema-level isolation between tenants.
What goes into a score.
The inputs are deliberately few and deliberately explicit. A score nobody can reconstruct is a score nobody will trust.
| Input | Source | Why it matters |
|---|---|---|
| Algorithm and key strength | CADP discovery | Determines whether the asset is broken by Shor, weakened by Grover, or unaffected |
| Confidentiality lifetime | Business enrichment | How long the data must stay secret — the shelf life in Mosca's inequality |
| Migration effort | Business enrichment | How long this system realistically takes to change, including vendor dependencies |
| Business criticality | Business enrichment | Weights the consequence of getting it wrong |
| Data sensitivity | Business enrichment | Regulatory and contractual exposure attached to the data in transit or at rest |
| Exposure | CADP discovery | Whether the usage faces the internet, a partner, or only an internal segment |
| Vendor readiness | Vendor assessment | Whether a fix exists to migrate to at all |
Every score decomposes back to these inputs, and every input carries its provenance.
Where it is, honestly.
QSRAP is live with early-access customers. That is not the same as generally available, and the difference is worth being straight about.
Early access, not GA
It runs as multi-tenant software with real tenants today. Onboarding is hands-on and deliberately paced while the model settles.
It needs CADP underneath
QSRAP governs discovered estates. Without discovery feeding it, you are back to maintaining an inventory by hand.
Enrichment is human work
Owner, criticality, data sensitivity and confidentiality lifetime cannot be discovered. The platform makes collecting them tractable; it does not make them free.
One governance tier
Several CADP instances per region, one QSRAP above them. If you need independently governed estates, that is separate deployments, not tenants.
It does not recompute verdicts
Classification is CADP's. QSRAP consumes the verdict and the artifacts losslessly, so the two tiers can never disagree about what was found.
Risk scoring is a model
Mosca's inequality depends on an estimate of when a cryptographically relevant quantum computer arrives. We show the assumption, and you can change it.
Start with discovery, then decide whether you need the tier above it.
Most organisations should prove CADP first. QSRAP earns its place when you have more than one estate, a regulator with a timetable, or a migration that needs a budget line.
