Cryptography Baseline Assessment CBA — a read on what your crypto is, from the outside. CBA — what your crypto actually is.

// diptych — CMB · CBA

Get an external, attacker's-eye view of your exposure and a prioritized plan to close the gap. Expert-led, done in 4–8 weeks.

Who this is for

CISOs, heads of security, and compliance leads at organizations running critical infrastructure who:

What you get

How it works

Sample finding: "TLS 1.0 still active on 3 externally-facing endpoints."

What the scan looks at

Three things, in that order, because each one narrows the next.

Why the timing matters

Crypto agility is the ability to inventory, assess and change cryptography without redesigning the whole estate. It matters because algorithms, dependencies and regulatory expectations change at different speeds.

The assessment does not make that work disappear. It gives you the order: which exposed paths to address first, what evidence is missing and where a broader migration needs design work.

CMB vs CBA

The CMB is self-reported and tells you what you believe your cryptography is. The CBA reveals what it truly is.

Questions only the CBA answers:

Cryptography Maturity Benchmark (CMB)free · ~15 min · questionnaire · identifies gaps
Cryptography Baseline Assessment (CBA)€10–15K · 4–8 weeks · deep scan · prioritizes fixes

CMB tell you what you think your crypto is. CBA tell you what it really is. And where to start fix.

CMB find inner hole by question. CBA scan real edge. See what attacker see.

You get

CMB vs CBA

CMBfree · ~15 min · questionnaire
CBA€10–15K · 4–8 weeks · deep scan

What scan looks at

Why now

Quantum breaks RSA and ECC. NIST standardised the replacements. Regulators start naming dates. Zero-trust wants finer crypto.

Low agility: run exposed, or rip it all out. Roadmap makes you agile while fixing, not after.

Questions CMB cannot answer

CBA — Cryptographic Baseline Assessment. Expert-led external perimeter scan. Paid engagement.

Spec

price€10–15K
duration4–8 weeks
methodexternal perimeter scan + expert review
viewattacker's-eye (outside-in)
outputfindings + risk-ranked remediation roadmap

CMB vs CBA

CMBfree · ~15 min · questionnaire · inner view
CBA€10–15K · 4–8 weeks · deep scan · edge view

Assessment inputs

inventoryalgorithms, key sizes, protocols, implementations, locations, configuration
vulnerabilitycipher suites, deprecated protocols, TLS endpoint configuration, key management and rotation
comparisonestate against industry standard and against its own majority cluster

Drivers

Quantum computing against RSA and ECC; NIST post-quantum standardisation; regulatory quantum-safe timelines; zero-trust requiring dynamic, granular cryptography.

Answers only CBA gives