Crypto-agile security against quantum attacks
Compliance deadlines for CNSA 2.0, NIST, and federal PQC mandates are already here. Quill discovers every key, certificate, and cryptographic operation across your infrastructure, so you can remediate risk and answer to auditors and boards with evidence.

What we do
Research and advise on quantum information science and impact
Create discovery tools for cryptographic asset inventory
Direct migration planning
Orchestrate remediation and evidence-backed compliance
The cryptographic assets to inventory and migrate
Below is a list of the different assets and attack points for quantum computers, organized by discovery and remediation effort. Quill works to streamline both processes in a hands-free manner.
JWT & token signing
TLS / SSL key exchange
Service-mesh / internal mTLS
SSH keys
Email — S/MIME & PGP
Database & storage encryption
DNS / DNSSEC
VPN / IPsec
Code-signing & digital signatures
Auth tokens — FIDO2 / PIV
X.509 PKI & certificate authorities
Third-party / SaaS / supply-chain
HSMs & embedded / IoT firmware
Manual migration costs years you don't have.
Certificates, keys, and code call sites are automatable — Quill discovers them and generates the diff. Redesign and hardware are not, and no tool pretends otherwise. Size your company and see both.
| Class | Count | By hand | Automated | Tool role |
|---|---|---|---|---|
| Discovery | — | $4,200,000 | $24,000 | automated ‡ |
| Certs & keys | 250,000 | $18,750,000 | $2,812,500 | automated ‡ |
| Code sites | 6,000 | $7,200,000 | $1,080,000 | automated ‡ |
| Redesign * | 20 | $600,000 | $600,000 | flag only |
| Hardware † | 40 | $944,000 | $944,000 | flag only |
| Total | $31,694,000 | $5,460,500 |
MeasuredOne Quill scan: 22:22 wall clock, unattended — 47 hosts, 149 cryptographic assets, graded and written to a CycloneDX CBOM.
- †
- Hardware capex — $20,000 per unitA mid-blend of HSM firmware upgrade ($5–15k) against full replacement ($40–60k, Thales Luna-class); appliances typically sit lower. With labor, $23,600 per unit in the model.
- *
- Redesign — $30,000 per system200 hr of structural rework at $150/hr, for a system with no drop-in path. No public per-unit benchmark exists at this granularity; directionally consistent with hardcoded and legacy migrations reported at 4–6+ years.
- †
- Hardware labor — $3,600 per unit24 hr to procure, swap, and revalidate at $150/hr, excluding the capex above.
- ‡
- Automation — 85% of the config and code populationA Quill target, not a measured result. Every row marked automated is contingent on it — replace it with your own recall figure before quoting these numbers.
- ‡
- Tooled discovery — $24,000 fixed160 hr of scan setup and human review at $150/hr, held near-flat regardless of estate size.
The dates are fixed. Your procurement cycle is not.
- Dec 31, 2025CNSSP 15No CNSA 2.0 transition requirement enforced before this date.
- Jan 1, 2027CNSSP 15All new NSS acquisitions must be CNSA 2.0 compliant unless otherwise noted.
- ~Mar 2027EO 14412CISA, with NIST, to publish minimum elements for a cryptographic bill of materials — 270 days from signing, and they must enable automated assessment.
- Dec 31, 2030CNSSP 15Equipment and services that cannot support CNSA 2.0 must be phased out; NSA expects equipment transitions complete. Federal agencies to transition most sensitive systems; contractors to meet PQC FIPS.
- Dec 31, 2031EO / CNSSPCNSA 2.0 algorithms mandated for use; post-quantum authentication required.
- 2035NSM-10Goal: all National Security Systems quantum-resistant.
Which instrument actually binds you.
CNSA 2.0
Binds National Security SystemsNSA states directly that it is not using these requirements to dictate algorithm choices to entities outside NSS, while acknowledging interoperability may lead a wider community to adopt them.
NSS owner, DoD, or Defense Industrial Base: this is a requirement. Commercial enterprise with no NSS interface: authoritative guidance, not a mandate.
Executive Order 14412
Reaches much further · Signed June 22, 2026Sets deadlines for federal agencies and extends obligations to federal contractors via the FAR. First federal directive to name the cryptographic bill of materials as a defined artifact — CISA with NIST to publish minimum elements by roughly March 2027, and those elements must enable automated assessment.
The practical test: do you sell to the federal government, or to anyone who does? If yes, EO 14412 reaches you regardless of CNSA 2.0's NSS scope.
Built for crypto agility.
Quill is built around a single idea: find every place cryptography is invoked, then get the algorithm out of those places and into one. NSA calls that agility, and calls it necessary rather than desirable. Here is why.
See a free scan of your external domain with Quill.
Quill reads what your domain already shows the public internet — TLS key exchange, certificate chains, and signature algorithms — then grades each one against CNSA 2.0. No agent, no access, nothing to install. Tell us where to send it and we'll run the scan and walk you through the result.