Overview
PQC Manager is a post-quantum cryptography preparedness and asset governance system. It inventories the cryptographic assets used across your network, scans systems for algorithms that are vulnerable to quantum attacks (such as Shor's algorithm), assigns each system a risk score, and produces a prioritised list of remediation tickets. It also tracks the cryptography in use, records business criticality and ownership, and reports progress against the NCSC migration roadmap.
Getting Started
Sign in with your username and password. If your account is configured for multi-factor authentication (MFA), you will be prompted to provide a six-digit code from your authenticator app after entering your password.
Administrators create accounts via Settings β Assignees. Privileged users (admins and managers) may have MFA enforced server-wide, which means they cannot sign in without an authenticator code.
Once signed in you land on the Dashboard, which summarises your estate. Use the tabs across the top to move between areas.
The Dashboard
The dashboard shows five headline numbers for your whole estate:
- Total Registered Systems β the number of inventoried systems.
- PQC-Ready Systems β systems whose latest assessment has a PQC risk score below 3 (see Risk Score).
- High Risk Systems β systems with a PQC risk score of 8 or above.
- Vulnerable Crypto Assets β the count of detected cryptographic assets deemed vulnerable.
- Active Remediation β the number of remediation tickets currently open.
A Quick Actions area on the dashboard lets managers add new systems manually or upload systems in bulk from a CSV file.
Systems Inventory & Scanner
Every known system is listed as a card. Each card shows the system's hostname, IP address (where known), operating system, department, owner, business criticality, PQC risk score and last scan time.
From a card you can:
- Scan β run the cryptographic scanner against the system to detect the algorithms/ciphers in use and identify any that are vulnerable to quantum attacks.
- Assign an owner β record who is responsible for the system.
- Set business criticality β low, medium, high or critical (this feeds into prioritisation).
Managers can Add System manually (hostname, IP, department, OS, etc.) or upload a CSV batch. Each scan generates remediation tickets automatically for any vulnerable assets that are found.
Remediation Tickets
When a scan identifies a vulnerable cryptographic asset, the system automatically opens a remediation ticket for it. Tickets have a severity level and a priority, and record the expected PQC impact so you know why the change matters.
- Open tickets need action.
- In progress tickets have an assignee actively working them.
- Closed / resolved tickets indicate the asset has been upgraded or otherwise made safe.
Assignees are managed by administrators under Settings β Assignees. When the underlying vulnerability is remediated and rescanned, the corresponding ticket is automatically marked resolved.
Cryptography (PQC) Register
The register is a per-system inventory of cryptographic details. For each system it tracks:
- System & network identity.
- System owner and business criticality.
- PQC risk score and the discovered assets / vulnerabilities.
- Last scan.
- Operating system, department and a free-text description.
Managers can use the pencil icon to edit the Operating System, Department and Description fields for a system, and to update the owner and criticality, then confirm with the checkmark or cancel with the βXβ. The description is limited to 200 characters. You can also search the register across these fields.
NCSC Roadmap
The roadmap tab tracks your migration progress against the NCSC's phased timeline for moving to post-quantum cryptography. It shows which phases have been completed and which high-priority systems (those marked high or critical) have no vulnerable assets. Use it to understand which preparations should happen ahead of upcoming quantum-safe milestones.
Reporting
The reporting tab aggregates data across the estate β counts of systems by criticality, risk distributions, vulnerability counts and remediation state. Use it to produce a snapshot of your organisation's overall post-quantum posture for stakeholders and audits.
Exceptions
When a system cannot (yet) be remediated β for example where a legacy protocol is still required for interoperability β an exception can be raised to record the risk formally. An active exception documents why the vulnerable asset remains, who approved it, and when it should be reviewed.
Access Roles & Permissions
The system has four roles in increasing order of privilege. What you can do is determined by your role.
| Role | What you can do |
|---|---|
| Viewer | Sign in and view the dashboard, systems inventory, register, reporting and roadmap. Read-only. |
| Auditor | Everything a Viewer can do, plus access to the Audit Log for compliance review. |
| Manager | Everything an Auditor can do, plus operational changes: add/scan systems, register & edit owner/criticality/operating-system/department/description, manage tickets. |
| Admin | Everything a Manager can do, plus user administration: create users, assign roles, manage assignees. Admins (and managers, if enforced) are required to use MFA. |
MFA is required for privileged accounts (admin and manager) when enforcement is switched on server-wide, regardless of an individual user's own MFA setting.
How the PQC Risk Score Works
Each assessed system gets a PQC risk score on a 0β10 scale. It is the proportion of the system's crypto assets that are vulnerable to quantum attacks, scaled to ten:
score = round((vulnerable assets Γ· total assets) Γ 10, 2)
- A score of 0 means no detected asset is vulnerable β fully PQC-ready.
- A score of 10 means every detected asset is vulnerable.
- Systems with no detected assets score 0.
The dashboard thresholds are:
- PQC-Ready β score below 3.
- High Risk β score of 8 or above.
Alongside the score, each system is labelled with a business criticality β low, medium, high or critical. Criticality is a business judgement, set by a manager, and combined with risk it informs the NCSC roadmap prioritisation: high/critical systems are treated as high-priority for migration and drive your remediation roadmap. Vulnerable assets automatically create a high-severity remediation ticket so the risk can be actioned.
Account Security & MFA
Under Settings β Account Security you can secure your own account with multi-factor authentication. This is a time-based one-time password (TOTP) scheme and works with any standard authenticator app.
- Click Set up MFA.
- Scan the QR code shown (or enter the secret key manually) into your authenticator app.
- Enter the current six-digit code to confirm and enable MFA.
This per-account setting is separate from the server-wide switch that requires MFA for privileged (admin/manager) accounts.
Audit Log
The audit log (available to admins and auditors) is a chronological, tamper-evident record of meaningful actions β sign-ins, user administration, scans, register and criticality changes. Each entry records the timestamp, acting user, action type, affected entity, details and source IP, giving you a compliance-grade trail.
Settings & Assignees
Under Settings β Assignees (admin only) administrators manage the list of users who can be assigned to remediation tickets. Add a user by providing their name, username, email, role, department and an initial password. Roles here follow the same hierarchy described in Access Roles.
Glossary
- PQC β post-quantum cryptography: algorithms designed to resist attacks from quantum computers.
- Vulnerable asset β a crypto algorithm/cipher on a system susceptible to quantum attack (e.g. RSA/ECC reliant on integer factorisation or discrete log).
- Shor's algorithm β a quantum algorithm that can break widely used asymmetric cryptography.
- PQC risk score β a 0β10 measure of what share of a system's crypto assets are vulnerable.
- PQC-Ready β score below 3 (no substantial vulnerable exposure).
- MFA β multi-factor authentication; a second verification step beyond the password.
- Criticality β business importance of a system (low/medium/high/critical).