Simplifying Cryptographic Discovery, Inventory, and Risk Assessment for the Federal Government and Commercial Enterprise
This FAQ section provides comprehensive answers to common questions about TYCHON Quantum Command, its compliance with federal mandates, and how it helps organizations prepare for the post-quantum cryptography era.
Federal guidance has progressed beyond a periodic inventory requirement to a phased, risk-based migration program supported by continuously updated cryptographic data.
OMB Memorandum M-26-15 directs civilian federal agencies to develop and submit a PQC Migration Plan, prioritize High Value Assets, high-impact systems, and systems containing highly sensitive data, and mitigate as much quantum risk as feasible by December 31, 2030. The memorandum specifically identifies automation as critical for cryptographic inventory management, policy enforcement, continuous monitoring, and compliance reporting. It also calls for a dynamic, continuously updated inventory of cryptographic assets.
TYCHON Quantum Command supports these objectives by helping organizations:
Coverage includes application binaries, executables, cryptographic libraries, Java archives, certificates, OpenSSH keys, OpenPGP keys, PKCS formats, Java keystores, TLS configurations, non-TLS protocols, encrypted files, and other cryptographic assets.
The current federal PQC policy environment includes the following major authorities and guidance:
Established broader federal cybersecurity modernization requirements, including improved software supply-chain security and movement toward stronger security practices.
Read Executive Order 14028Directed agencies to inventory cryptographic systems and prioritize systems that could be significantly affected by a cryptographically relevant quantum computer.
Read NSM-10Required federal agencies to inventory information systems using cryptography that may be vulnerable to quantum computing and develop plans for migration to post-quantum cryptography.
View the legislation on Congress.govEstablished initial annual cryptographic inventory and reporting requirements for federal civilian agencies.
Read OMB M-23-02Establishes the Department's strategy for migrating National Security Systems and non-NSS environments. It requires identification of cryptography across DoW systems, risk and mission-impact assessments, component-level migration roadmaps, and consideration of automated cryptographic discovery and inventory tools. The strategy states that all DoW systems must support PQC or be phased out by December 31, 2030, and must use PQC by December 31, 2031, unless otherwise noted.
Read the DoW Post-Quantum Cryptography StrategyRe-establishes the Committee on National Security Systems and designates the NSA Director as the National Manager and cryptologic authority for National Security Systems. It requires agencies to maintain annual NSS inventories and establishes CNSS issuances, including CNSSP-15 or its successor, as governing cryptographic requirements for NSS.
Read NSPM-12Accelerates the federal transition to NIST-approved PQC standards. It requires agencies to designate PQC migration leads and establishes deadlines for migrating High Value Assets and high-impact systems: December 31, 2030, for PQC key establishment and December 31, 2031, for PQC digital signatures.
Read Executive Order 14412Provides implementation guidance for Executive Order 14412. Agencies must establish governance, submit risk-based migration plans, use automated discovery where feasible, coordinate with vendors, incorporate PQC into modernization programs, and complete phased migration activities through 2035. M-26-15 applies to federal information systems but expressly excludes National Security Systems, which remain governed through NSA and CNSS authorities.
Read OMB M-26-15Federal mandates apply primarily to government agencies and National Security Systems, but the underlying quantum risk affects every organization that relies on public-key cryptography to protect sensitive data, identities, transactions, software, communications, or critical operations.
Commercial enterprises should begin preparing now because:
TYCHON Quantum Command helps government agencies, defense contractors, critical-infrastructure providers, and commercial enterprises establish a comprehensive cryptographic inventory, identify quantum-vulnerable implementations, prioritize remediation, and track migration progress.
TYCHON Quantum Command provides technical capabilities that support the discovery, inventory, assessment, prioritization, monitoring, and reporting activities established by current federal guidance. It can serve as a foundational technical capability within an organization's broader PQC governance and migration program.
Key areas of alignment include:
TYCHON Quantum Command does not replace agency governance, risk acceptance, system authorization, or formal compliance determinations. It supplies the detailed, continuously updated cryptographic evidence organizations need to build migration plans, prioritize investments, demonstrate progress, and support compliance reporting.
TYCHON Quantum Command is a discovery and risk classification solution based on the fast-moving and daunting cryptographic space. We parse the complexity of algorithms and their implementations into discrete components, analyzing each step in the process, pinpointing the most urgent risks.
Network-only monitoring solutions cannot effectively track enterprise-wide operations because they do not detect cryptographic operations that occur locally on endpoints. Without endpoint visibility, organizations only see encrypted data traversing the network, missing crucial information about the encryption process and implementation.
Critical Insight:
On-device discovery captures both cryptography in use, and just as important: cryptography available for use. Bad ciphers must be found and removed from the system. Once they are used on the network, it is often too late to stop the negative impact.
Yes. TYCHON's lightweight endpoint scripts deliver network-based information, but also continuous visibility regardless of location, ensuring that organizations maintain oversight of their cryptographic assets and operations.
| Category | Dataset | Description |
|---|---|---|
| General | Host OS Info | Device Guard, Trusted Platform Module (TPM), UEFI Settings |
| Quantum Readiness | PQC Client TLS Protocols Data | Protocols Used to Originate a Client Session |
| PQC Discovered Cipher | Method to Transform Plaintext to Cipher Text | |
| PQC Listening Port Certificate | Attributes of Application Certificates | |
| PQC System Certificates | Certificates Used to Verify Secure Connections | |
| Network Data | Network PQC Discovered Ciphers | TLS Cipher Data in Network Packets |
| Non-TLS Protocol Discovery | Protocols such as SSH, S/MIME and VPNs | |
| Network PQC Listening Port Certificate | Certificate Data in Network Packets |
TYCHON Quantum Command includes pre-built dashboards for inventory and risk assessment for Splunk and Elastic integrations.
TYCHON Quantum Command can be paired with TYCHON Enterprise or other systems management tools like Microsoft Intune and BigFix to perform remediation and migration to quantum-resistant algorithms.
Yes. TYCHON Quantum Command integrates seamlessly with both Splunk and Elastic platforms.
Pre-built dashboard content packs are available for both platforms. Note that you need to bring your own license (BYOL) for these platforms.
Yes. TYCHON supports a wide range of enterprise platforms including:
Yes. TYCHON offers integrations with companies like SafeLogic and Qrypt to provide end-to-end cryptographic solutions.
Yes. TYCHON Quantum Command is designed to deliver comprehensive cryptographic discovery and inventory across the entire enterprise, regardless of whether an endpoint is managed by HCL BigFix.
In environments where BigFix is deployed, TYCHON Quantum Command can integrate directly with those managed endpoints. For systems that fall outside the BigFix footprint, such as unmanaged endpoints, isolated networks, or third-party devices, TYCHON Quantum Command can be deployed independently to assess those assets as well.
Deployment Flexibility:
This flexibility ensures organizations can achieve a complete and accurate cryptography inventory by:
The result is a unified, enterprise-wide view of cryptographic assets and algorithms without requiring universal BigFix coverage.
Yes. TYCHON offers pilot programs and proof of concept deployments for organizations interested in evaluating Quantum Readiness capabilities. Contact us to learn more.
Yes. TYCHON Quantum Command is available through Carahsoft, our government contracting partner.
View Government Contract Vehicles →Because TYCHON is not a cloud service, it is an on-premise assessment and analytics capability that runs entirely inside the customer's accredited enclave.
TYCHON Quantum Command is intentionally architected as a customer-hosted, on-premise analytic capability, not a SaaS platform and not a managed cloud service. It does not host, transmit, or persist customer data outside the customer's own accredited environment.
All discovery, analysis, storage, dashboards, and reporting occur entirely within the customer's existing FedRAMP / ATO-approved environments, such as:
TYCHON never becomes a system of record, never receives customer data, and never introduces an external boundary. As a result, TYCHON does not meet the definition of a Cloud Service Offering (CSO) under FedRAMP and therefore does not require FedRAMP authorization.
FedRAMP authorizes the service provider's cloud boundary, not customer-hosted analytic software. Because TYCHON runs inside already-authorized government enclaves:
Requiring FedRAMP would add compliance cost without reducing risk while delaying deployment of urgently needed quantum readiness capabilities.
TYCHON is delivered as a stateless, agentless binary and analytic content package that:
Security ownership, accreditation, and authority remain entirely with the agency.
TYCHON is continuously enhancing Quantum Readiness capabilities, including the forthcoming consolidated binary and additional features to streamline cryptographic discovery and risk assessment. Contact us to discuss upcoming features and roadmap details.
Our team is here to help you understand how TYCHON Quantum Command can meet your organization's cryptographic inventory and risk assessment needs.