Mark System as Exception

PQC Manager

Post-Quantum Cryptography Preparedness & Asset Governance System

Enter the code from your authenticator app.

PQC Manager Dashboard

Post-Quantum Cryptography Preparedness & Asset Governance System

Signed in as β€” β€”
0
Total Registered Systems
0
PQC-Ready Systems
0
High Risk Systems
0
Vulnerable Crypto Assets
0
Active Remediation

Add New System for Scanning

Bulk Import from CSV

Upload a CSV file with columns hostname,ip_address to bulk-add systems and run scans automatically.

Systems Inventory & Scanner

Loading systems inventory...

Remediation Tickets

Actionable security tickets automatically created when quantum-vulnerable cryptographic algorithms are detected during system scans.

Loading remediation items...

Cryptography Register & System Ownership

Comprehensive register of scanned infrastructure, quantum vulnerability ratings, detected algorithms, and system owner assignments.

System & Network System Owner Business Criticality PQC Risk Score Discovered Crypto Assets & Vulnerabilities Last Scan Operating System Department Description
Loading Cryptography Register...

NCSC PQC Migration Roadmap

Alignment view computed from live inventory, assessments and remediation data, following NCSC Timelines for migration to post-quantum cryptography (March 2025): 2028 prepare · 2031 migrate · 2035 complete.

Loading NCSC roadmap...
System Criticality Owner 2028 Prepare 2031 Migrate 2035 Complete Quantum-Vulnerable Assets
Loading systems...

Trend Reporting

Progress over time from scan assessments, ticket lifecycle events and daily readiness snapshots. Snapshots are captured automatically after each scan and by the nightly cron.

Loading...

Remediation Tickets Over Time

Reconstructed from ticket creation and resolution dates.

Loading...

Roadmap Status Over Time

From daily readiness snapshots β€” systems per milestone status.

Loading...

Exception Register

Formally approved exceptions for systems that cannot yet meet the NCSC migration gates. Exempt systems are excluded from roadmap gate scoring while the exception is active. Use Mark Exception on a system card to grant one; a reason is required.

System Reason Granted By Granted At Review By Status Actions
Loading exceptions...

Settings

Audit log, account security, and remediation ticket assignees.

Audit Log

Chronological record of system activities for compliance.

Timestamp User Action Entity Details IP
Loading audit log...

Multi-factor Authentication

Protect your account with a time-based one-time password (TOTP) authenticator app. This setting is separate from the server-wide privileged-user enforcement switch.

Loading MFA status...

1. Scan this QR code with your authenticator app

Open your authenticator app, choose β€œAdd account” or β€œScan QR code”, and scan the image below.

MFA setup QR code

If you cannot scan it, use the secret key manually:

2. Confirm setup

Remediation Ticket Assignees

Manage the list of users who can be assigned to remediation tickets.

Loading assignees...

Add New Assignee

Help & Documentation

Guidance for every part of the PQC Manager system, including risk scoring and access roles.

Jump to a section

Click any topic to jump straight to it, or scroll through the full guide below.

  1. Overview
  2. Getting Started
  3. The Dashboard
  4. Systems Inventory & Scanner
  5. Remediation Tickets
  6. Cryptography (PQC) Register
  7. NCSC Roadmap
  8. Reporting
  9. Exceptions
  10. Access Roles & Permissions
  11. How the PQC Risk Score Works
  12. Account Security & MFA
  13. Audit Log
  14. Settings & Assignees
  15. Glossary

Overview

PQC Manager is a post-quantum cryptography preparedness and asset governance system. It inventories the cryptographic assets used across your network, scans systems for algorithms that are vulnerable to quantum attacks (such as Shor's algorithm), assigns each system a risk score, and produces a prioritised list of remediation tickets. It also tracks the cryptography in use, records business criticality and ownership, and reports progress against the NCSC migration roadmap.

Getting Started

Sign in with your username and password. If your account is configured for multi-factor authentication (MFA), you will be prompted to provide a six-digit code from your authenticator app after entering your password.

Administrators create accounts via Settings β†’ Assignees. Privileged users (admins and managers) may have MFA enforced server-wide, which means they cannot sign in without an authenticator code.

Once signed in you land on the Dashboard, which summarises your estate. Use the tabs across the top to move between areas.

The Dashboard

The dashboard shows five headline numbers for your whole estate:

  • Total Registered Systems β€” the number of inventoried systems.
  • PQC-Ready Systems β€” systems whose latest assessment has a PQC risk score below 3 (see Risk Score).
  • High Risk Systems β€” systems with a PQC risk score of 8 or above.
  • Vulnerable Crypto Assets β€” the count of detected cryptographic assets deemed vulnerable.
  • Active Remediation β€” the number of remediation tickets currently open.

A Quick Actions area on the dashboard lets managers add new systems manually or upload systems in bulk from a CSV file.

Systems Inventory & Scanner

Every known system is listed as a card. Each card shows the system's hostname, IP address (where known), operating system, department, owner, business criticality, PQC risk score and last scan time.

From a card you can:

  • Scan β€” run the cryptographic scanner against the system to detect the algorithms/ciphers in use and identify any that are vulnerable to quantum attacks.
  • Assign an owner β€” record who is responsible for the system.
  • Set business criticality β€” low, medium, high or critical (this feeds into prioritisation).

Managers can Add System manually (hostname, IP, department, OS, etc.) or upload a CSV batch. Each scan generates remediation tickets automatically for any vulnerable assets that are found.

Remediation Tickets

When a scan identifies a vulnerable cryptographic asset, the system automatically opens a remediation ticket for it. Tickets have a severity level and a priority, and record the expected PQC impact so you know why the change matters.

  • Open tickets need action.
  • In progress tickets have an assignee actively working them.
  • Closed / resolved tickets indicate the asset has been upgraded or otherwise made safe.

Assignees are managed by administrators under Settings β†’ Assignees. When the underlying vulnerability is remediated and rescanned, the corresponding ticket is automatically marked resolved.

Cryptography (PQC) Register

The register is a per-system inventory of cryptographic details. For each system it tracks:

  • System & network identity.
  • System owner and business criticality.
  • PQC risk score and the discovered assets / vulnerabilities.
  • Last scan.
  • Operating system, department and a free-text description.

Managers can use the pencil icon to edit the Operating System, Department and Description fields for a system, and to update the owner and criticality, then confirm with the checkmark or cancel with the β€œX”. The description is limited to 200 characters. You can also search the register across these fields.

NCSC Roadmap

The roadmap tab tracks your migration progress against the NCSC's phased timeline for moving to post-quantum cryptography. It shows which phases have been completed and which high-priority systems (those marked high or critical) have no vulnerable assets. Use it to understand which preparations should happen ahead of upcoming quantum-safe milestones.

Reporting

The reporting tab aggregates data across the estate β€” counts of systems by criticality, risk distributions, vulnerability counts and remediation state. Use it to produce a snapshot of your organisation's overall post-quantum posture for stakeholders and audits.

Exceptions

When a system cannot (yet) be remediated β€” for example where a legacy protocol is still required for interoperability β€” an exception can be raised to record the risk formally. An active exception documents why the vulnerable asset remains, who approved it, and when it should be reviewed.

Access Roles & Permissions

The system has four roles in increasing order of privilege. What you can do is determined by your role.

RoleWhat you can do
ViewerSign in and view the dashboard, systems inventory, register, reporting and roadmap. Read-only.
AuditorEverything a Viewer can do, plus access to the Audit Log for compliance review.
ManagerEverything an Auditor can do, plus operational changes: add/scan systems, register & edit owner/criticality/operating-system/department/description, manage tickets.
AdminEverything a Manager can do, plus user administration: create users, assign roles, manage assignees. Admins (and managers, if enforced) are required to use MFA.

MFA is required for privileged accounts (admin and manager) when enforcement is switched on server-wide, regardless of an individual user's own MFA setting.

How the PQC Risk Score Works

Each assessed system gets a PQC risk score on a 0–10 scale. It is the proportion of the system's crypto assets that are vulnerable to quantum attacks, scaled to ten:

score = round((vulnerable assets Γ· total assets) Γ— 10, 2)

  • A score of 0 means no detected asset is vulnerable β€” fully PQC-ready.
  • A score of 10 means every detected asset is vulnerable.
  • Systems with no detected assets score 0.

The dashboard thresholds are:

  • PQC-Ready β€” score below 3.
  • High Risk β€” score of 8 or above.

Alongside the score, each system is labelled with a business criticality β€” low, medium, high or critical. Criticality is a business judgement, set by a manager, and combined with risk it informs the NCSC roadmap prioritisation: high/critical systems are treated as high-priority for migration and drive your remediation roadmap. Vulnerable assets automatically create a high-severity remediation ticket so the risk can be actioned.

Account Security & MFA

Under Settings β†’ Account Security you can secure your own account with multi-factor authentication. This is a time-based one-time password (TOTP) scheme and works with any standard authenticator app.

  1. Click Set up MFA.
  2. Scan the QR code shown (or enter the secret key manually) into your authenticator app.
  3. Enter the current six-digit code to confirm and enable MFA.

This per-account setting is separate from the server-wide switch that requires MFA for privileged (admin/manager) accounts.

Audit Log

The audit log (available to admins and auditors) is a chronological, tamper-evident record of meaningful actions β€” sign-ins, user administration, scans, register and criticality changes. Each entry records the timestamp, acting user, action type, affected entity, details and source IP, giving you a compliance-grade trail.

Settings & Assignees

Under Settings β†’ Assignees (admin only) administrators manage the list of users who can be assigned to remediation tickets. Add a user by providing their name, username, email, role, department and an initial password. Roles here follow the same hierarchy described in Access Roles.

Glossary

  • PQC β€” post-quantum cryptography: algorithms designed to resist attacks from quantum computers.
  • Vulnerable asset β€” a crypto algorithm/cipher on a system susceptible to quantum attack (e.g. RSA/ECC reliant on integer factorisation or discrete log).
  • Shor's algorithm β€” a quantum algorithm that can break widely used asymmetric cryptography.
  • PQC risk score β€” a 0–10 measure of what share of a system's crypto assets are vulnerable.
  • PQC-Ready β€” score below 3 (no substantial vulnerable exposure).
  • MFA β€” multi-factor authentication; a second verification step beyond the password.
  • Criticality β€” business importance of a system (low/medium/high/critical).