Post-quantum readiness

0dq

You cannot migrate cryptography you cannot see.

ReadsYour source codeProducesA scored posture across six pillars

Every institution knows it will have to move to post-quantum cryptography. Almost none can answer the first question a regulator will ask. That inventory does not exist, because no scanner has ever produced it — they look for vulnerabilities, not for cryptography.

0dq scores six pillars as one number with the arithmetic shown: quantum readiness at 30%, then code, dependencies, secrets, infrastructure and licences. Five of those you already have from other tools. The first one you do not, and it is the one a post-quantum programme starts with.

Findings carry a reachability verdict — called, not called, dead code, dev only — so the list is ordered by what can actually run rather than by severity alone. Where a fix is mechanical, it opens the pull request. Point it at a repository and it answers in minutes: no agent, no integration project.

The question it answers

Which cryptography are we running, in which systems, protecting what?

Asked by: The regulator

What is known

Every figure below carries its source. Where we have not measured something, we do not have a figure for it.

  • NIST published ML-KEM, ML-DSA and SLH-DSA in August 2024. What to migrate to is no longer an open question — only what to migrate, and in what order.

    NISTThird-party, published
  • Cryptography and key management are already named control domains under the CBUAE Information Security Regulation and Operational Risk Standard.

    CBUAEThird-party, published
  • Six pillars, weighted into one score: quantum readiness 30%, code 18%, dependencies 17%, secrets 13%, infrastructure 12%, licences 10%.

    0dq scoring modelProduct behaviour
  • Static analysis runs 2,452 rules across OWASP Top Ten and CWE Top 25. Secrets are found in commit history, not only the working tree.

    0dq scannerProduct behaviour
  • Every finding carries a reachability verdict — called, not called, dead code, dev only — so the queue is ordered by what can run, not by severity alone.

    0dq findings viewProduct behaviour
  • Runs in the browser, on the command line, as a pipeline gate, and as a pre-commit hook that stops a credential locally in under a second.

    0dq surfacesProduct behaviour