Quantum Readiness FAQs

Simplifying Cryptographic Discovery, Inventory, and Risk Assessment for the Federal Government and Commercial Enterprise

About This FAQ

This FAQ section provides comprehensive answers to common questions about TYCHON Quantum Command, its compliance with federal mandates, and how it helps organizations prepare for the post-quantum cryptography era.

Compliance & Requirements

How does TYCHON Quantum Command support current federal cryptographic inventory and PQC migration requirements?

Federal guidance has progressed beyond a periodic inventory requirement to a phased, risk-based migration program supported by continuously updated cryptographic data.

OMB Memorandum M-26-15 directs civilian federal agencies to develop and submit a PQC Migration Plan, prioritize High Value Assets, high-impact systems, and systems containing highly sensitive data, and mitigate as much quantum risk as feasible by December 31, 2030. The memorandum specifically identifies automation as critical for cryptographic inventory management, policy enforcement, continuous monitoring, and compliance reporting. It also calls for a dynamic, continuously updated inventory of cryptographic assets.

Read OMB M-26-15

TYCHON Quantum Command supports these objectives by helping organizations:

  • Automatically discover cryptographic algorithms, certificates, keys, protocols, libraries, keystores, applications, and related dependencies.
  • Identify quantum-vulnerable cryptography, including RSA, ECC, Diffie-Hellman, and DSA implementations.
  • Associate cryptographic findings with the endpoints, applications, services, ports, and systems that rely on them.
  • Maintain a centralized and continuously updated cryptographic inventory.
  • Assess risk and prioritize systems for remediation or migration.
  • Track readiness and migration progress through dashboards and compliance-oriented reports.
  • Export inventory data for agency, DoW CIO, OMB, and ONCD planning and reporting workflows.

Coverage includes application binaries, executables, cryptographic libraries, Java archives, certificates, OpenSSH keys, OpenPGP keys, PKCS formats, Java keystores, TLS configurations, non-TLS protocols, encrypted files, and other cryptographic assets.

What laws, policies, and strategies establish federal cryptographic inventory and PQC migration requirements?

The current federal PQC policy environment includes the following major authorities and guidance:

May 12, 2021: Executive Order 14028 — Improving the Nation's Cybersecurity

Established broader federal cybersecurity modernization requirements, including improved software supply-chain security and movement toward stronger security practices.

Read Executive Order 14028

May 4, 2022: NSM-10 — Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems

Directed agencies to inventory cryptographic systems and prioritize systems that could be significantly affected by a cryptographically relevant quantum computer.

Read NSM-10

December 21, 2022: Quantum Computing Cybersecurity Preparedness Act

Required federal agencies to inventory information systems using cryptography that may be vulnerable to quantum computing and develop plans for migration to post-quantum cryptography.

View the legislation on Congress.gov

November 18, 2022: OMB M-23-02 — Migrating to Post-Quantum Cryptography

Established initial annual cryptographic inventory and reporting requirements for federal civilian agencies.

Read OMB M-23-02

April 1, 2026: Department of War CIO — Post-Quantum Cryptography Strategy

Establishes the Department's strategy for migrating National Security Systems and non-NSS environments. It requires identification of cryptography across DoW systems, risk and mission-impact assessments, component-level migration roadmaps, and consideration of automated cryptographic discovery and inventory tools. The strategy states that all DoW systems must support PQC or be phased out by December 31, 2030, and must use PQC by December 31, 2031, unless otherwise noted.

Read the DoW Post-Quantum Cryptography Strategy

June 12, 2026: NSPM-12 — National Security System Cyber Governance

Re-establishes the Committee on National Security Systems and designates the NSA Director as the National Manager and cryptologic authority for National Security Systems. It requires agencies to maintain annual NSS inventories and establishes CNSS issuances, including CNSSP-15 or its successor, as governing cryptographic requirements for NSS.

Read NSPM-12

June 22, 2026: Executive Order 14412 — Securing the Nation Against Advanced Cryptographic Attacks

Accelerates the federal transition to NIST-approved PQC standards. It requires agencies to designate PQC migration leads and establishes deadlines for migrating High Value Assets and high-impact systems: December 31, 2030, for PQC key establishment and December 31, 2031, for PQC digital signatures.

Read Executive Order 14412

June 24, 2026: OMB M-26-15 — Execution of the Migration to Post-Quantum Cryptography

Provides implementation guidance for Executive Order 14412. Agencies must establish governance, submit risk-based migration plans, use automated discovery where feasible, coordinate with vendors, incorporate PQC into modernization programs, and complete phased migration activities through 2035. M-26-15 applies to federal information systems but expressly excludes National Security Systems, which remain governed through NSA and CNSS authorities.

Read OMB M-26-15

Is quantum readiness only a government requirement, or should commercial enterprises also establish a cryptographic inventory and risk-assessment program?

Federal mandates apply primarily to government agencies and National Security Systems, but the underlying quantum risk affects every organization that relies on public-key cryptography to protect sensitive data, identities, transactions, software, communications, or critical operations.

Commercial enterprises should begin preparing now because:

  • Adversaries can collect encrypted information today and retain it for future decryption.
  • Cryptographic dependencies are embedded throughout applications, infrastructure, cloud services, connected devices, and third-party products.
  • Large-scale migration requires years of discovery, vendor coordination, testing, modernization, and implementation.
  • Government contractors and Defense Industrial Base organizations may need to support federal and DoW migration requirements through contracts, supply-chain obligations, or systems that process government data.
  • Critical-infrastructure owners and operators are specifically identified in Executive Order 14412 as needing federal assistance with their PQC transitions.

TYCHON Quantum Command helps government agencies, defense contractors, critical-infrastructure providers, and commercial enterprises establish a comprehensive cryptographic inventory, identify quantum-vulnerable implementations, prioritize remediation, and track migration progress.

How does TYCHON Quantum Command align with current OMB, NIST, CISA, DoW, NSA, and CNSS guidance?

TYCHON Quantum Command provides technical capabilities that support the discovery, inventory, assessment, prioritization, monitoring, and reporting activities established by current federal guidance. It can serve as a foundational technical capability within an organization's broader PQC governance and migration program.

Key areas of alignment include:

  • OMB M-26-15: Automated, continuously updated cryptographic discovery; risk-based prioritization; migration-planning data; compliance reporting; and progress monitoring.
  • Executive Order 14412 (EO 14412): Inventory management and prioritized planning for High Value Assets, high-impact systems, sensitive data, key establishment, and digital-signature migration.
  • DoW Post-Quantum Cryptography Strategy: Discovery of cryptography across NSS and non-NSS environments; identification of quantum-vulnerable systems; impact assessment; migration-roadmap development; and centralized progress tracking.
  • NSPM-12 and CNSS governance: Support for NSS inventory, cybersecurity-posture measurement, and implementation of cryptographic requirements established by NSA and CNSS.
  • NIST guidance: Identification of quantum-vulnerable cryptography and support for migration planning aligned with NIST PQC standards and NIST IR 8547.
  • CISA guidance: Cryptographic inventory, quantum-readiness assessment, vendor coordination, and identification of technology categories requiring PQC support.

TYCHON Quantum Command does not replace agency governance, risk acceptance, system authorization, or formal compliance determinations. It supplies the detailed, continuously updated cryptographic evidence organizations need to build migration plans, prioritize investments, demonstrate progress, and support compliance reporting.

Technical Capabilities

How does TYCHON Quantum Command work?

TYCHON Quantum Command is a discovery and risk classification solution based on the fast-moving and daunting cryptographic space. We parse the complexity of algorithms and their implementations into discrete components, analyzing each step in the process, pinpointing the most urgent risks.

Why is it important to use an endpoint-centric cryptographic inventory toolset vs a network-only scanner?

Network-only monitoring solutions cannot effectively track enterprise-wide operations because they do not detect cryptographic operations that occur locally on endpoints. Without endpoint visibility, organizations only see encrypted data traversing the network, missing crucial information about the encryption process and implementation.

Critical Insight:

On-device discovery captures both cryptography in use, and just as important: cryptography available for use. Bad ciphers must be found and removed from the system. Once they are used on the network, it is often too late to stop the negative impact.

Does TYCHON Quantum Command provide both endpoint and network device cryptographic inventory?

Yes. TYCHON's lightweight endpoint scripts deliver network-based information, but also continuous visibility regardless of location, ensuring that organizations maintain oversight of their cryptographic assets and operations.

What datasets does TYCHON Quantum Command deliver?

Category Dataset Description
General Host OS Info Device Guard, Trusted Platform Module (TPM), UEFI Settings
Quantum Readiness PQC Client TLS Protocols Data Protocols Used to Originate a Client Session
PQC Discovered Cipher Method to Transform Plaintext to Cipher Text
PQC Listening Port Certificate Attributes of Application Certificates
PQC System Certificates Certificates Used to Verify Secure Connections
Network Data Network PQC Discovered Ciphers TLS Cipher Data in Network Packets
Non-TLS Protocol Discovery Protocols such as SSH, S/MIME and VPNs
Network PQC Listening Port Certificate Certificate Data in Network Packets

Integration & Deployment

How does TYCHON provide visualization of the Quantum Readiness inventory?

TYCHON Quantum Command includes pre-built dashboards for inventory and risk assessment for Splunk and Elastic integrations.

Can TYCHON Quantum Command also perform remediation and migration to new quantum-resistant algorithms?

TYCHON Quantum Command can be paired with TYCHON Enterprise or other systems management tools like Microsoft Intune and BigFix to perform remediation and migration to quantum-resistant algorithms.

Does TYCHON Quantum Command work with Splunk and Elastic?

Yes. TYCHON Quantum Command integrates seamlessly with both Splunk and Elastic platforms.

Pre-built dashboard content packs are available for both platforms. Note that you need to bring your own license (BYOL) for these platforms.

Does TYCHON support other big data platforms, business intelligence tools, or SIEMS?

Yes. TYCHON supports a wide range of enterprise platforms including:

SIEM Platforms

  • IBM QRadar
  • LogRhythm
  • Splunk Enterprise

Data Platforms

  • Elasticsearch
  • Amazon OpenSearch
  • Datadog
  • Snowflake

Does TYCHON work with any providers of quantum-resistant algorithms and solutions?

Yes. TYCHON offers integrations with companies like SafeLogic and Qrypt to provide end-to-end cryptographic solutions.

Can TYCHON Quantum Command be used on systems that are not managed by HCL BigFix?

Yes. TYCHON Quantum Command is designed to deliver comprehensive cryptographic discovery and inventory across the entire enterprise, regardless of whether an endpoint is managed by HCL BigFix.

In environments where BigFix is deployed, TYCHON Quantum Command can integrate directly with those managed endpoints. For systems that fall outside the BigFix footprint, such as unmanaged endpoints, isolated networks, or third-party devices, TYCHON Quantum Command can be deployed independently to assess those assets as well.

Deployment Flexibility:

This flexibility ensures organizations can achieve a complete and accurate cryptography inventory by:

  • Utilizing BigFix-managed endpoints where available
  • Deploying TYCHON Quantum Command directly to non-managed systems to eliminate visibility gaps

The result is a unified, enterprise-wide view of cryptographic assets and algorithms without requiring universal BigFix coverage.

Procurement & Support

Does TYCHON offer pilots or proof of concept for Quantum Readiness?

Yes. TYCHON offers pilot programs and proof of concept deployments for organizations interested in evaluating Quantum Readiness capabilities. Contact us to learn more.

Is TYCHON Quantum Command available for purchase on government contract vehicles?

Yes. TYCHON Quantum Command is available through Carahsoft, our government contracting partner.

View Government Contract Vehicles →

Why Isn't TYCHON Quantum Command FedRAMP Authorized?

Because TYCHON is not a cloud service, it is an on-premise assessment and analytics capability that runs entirely inside the customer's accredited enclave.

TYCHON Quantum Command is intentionally architected as a customer-hosted, on-premise analytic capability, not a SaaS platform and not a managed cloud service. It does not host, transmit, or persist customer data outside the customer's own accredited environment.

All discovery, analysis, storage, dashboards, and reporting occur entirely within the customer's existing FedRAMP / ATO-approved environments, such as:

  • Microsoft GCC High / Azure Government
  • On-premise data centers
  • DoD IL4/IL5 cloud enclaves
  • Existing Splunk, Elastic, BigFix, and SIEM infrastructures

TYCHON never becomes a system of record, never receives customer data, and never introduces an external boundary. As a result, TYCHON does not meet the definition of a Cloud Service Offering (CSO) under FedRAMP and therefore does not require FedRAMP authorization.

Why FedRAMP Would Add No Security Value

FedRAMP authorizes the service provider's cloud boundary, not customer-hosted analytic software. Because TYCHON runs inside already-authorized government enclaves:

  • All data remains under the agency's existing ATO
  • All access controls, audit logging, encryption, and retention policies are inherited
  • All monitoring remains under agency SOC control
  • No new external attack surface is introduced

Requiring FedRAMP would add compliance cost without reducing risk while delaying deployment of urgently needed quantum readiness capabilities.

What TYCHON Does Provide Instead

TYCHON is delivered as a stateless, agentless binary and analytic content package that:

  • Deploys through existing admin platforms (BigFix, Intune, SCCM, Ansible, etc.)
  • Streams results into existing SIEMs (Splunk, Elastic, Sentinel, QRadar)
  • Creates no persistent external data store
  • Requires no outbound connectivity
  • Introduces no third-party data boundary

Security ownership, accreditation, and authority remain entirely with the agency.

What is the product roadmap and some of the future capabilities expected for TYCHON Quantum Command?

TYCHON is continuously enhancing Quantum Readiness capabilities, including the forthcoming consolidated binary and additional features to streamline cryptographic discovery and risk assessment. Contact us to discuss upcoming features and roadmap details.

Have More Questions?

Our team is here to help you understand how TYCHON Quantum Command can meet your organization's cryptographic inventory and risk assessment needs.