Select assets from inventory
Harvest-now-decrypt-later exposure scoring
RISK · GOVERNANCE PRODUCT / PLATFORM MODULE
Rank migration work by data lifetime, signature lifetime, business value, exposure and dependency complexity.
CUSTOMER PROBLEM
Not every cryptographic dependency has the same urgency. Migration must balance data lifetime, signature lifetime, exposure, business criticality and replacement complexity.
PRODUCT-SPECIFIC IMPLEMENTATION FLOW
Assessment workshops, data-classification input and dependency data from the inventory. Scoring criteria, assumptions, approvals and a traceable prioritized backlog.
Harvest-now-decrypt-later exposure scoring
Long-lived signature and evidence scoring
System criticality and dependency weighting
Migration wave and budget proposal
Assumption and approval record
Executive heatmap and technical backlog
NAMED COMPONENTS AND RESPONSIBILITIES
The descriptions below state concrete technical behaviour rather than generic support language.
Scores harvest-now-decrypt-later exposure from confidentiality lifetime, collection feasibility, external connectivity and current key-establishment methods.
Evaluates how long signatures, timestamps and archived evidence must remain verifiable compared with the expected migration and renewal window.
Weights service criticality, regulatory impact, outage tolerance, customer reach and recovery complexity instead of relying on algorithm age alone.
Groups assets into migration waves using shared libraries, trust anchors, suppliers, maintenance windows and available budget.
Records scoring assumptions, owner challenges, risk acceptance and approval decisions so the heatmap can be audited and repeated.
Produces an executive heatmap linked to a technical backlog, with clear owners, target dates, dependencies and residual-risk statements.
Assessment workshops, data-classification input and dependency data from the inventory.
Collectors run against approved sources; findings are reviewed before entering the governed inventory.
Scheduled collectors and connectors feed the inventory, risk and policy workflows under customer control.
Mobile-ID facilitates refresh, review and reporting while the customer retains ownership and approval authority.
PRODUCT-SPECIFIC BOUNDARIES
These points come from the product profile, not from a shared disclaimer.
NEXT STEP
Review the exact operating model, interfaces and evidence needed for deployment.