Cryptography Baseline Assessment CBA — a read on what your crypto is, from the outside. CBA — what your crypto actually is.
Get an external, attacker's-eye view of your exposure and a prioritized plan to close the gap. Expert-led, done in 4–8 weeks.
Who this is for
CISOs, heads of security, and compliance leads at organizations running critical infrastructure who:
- Want to prepare for an audit or a compliance deadline.
- Realize cryptographic hygiene is a priority before committing to a migration plan.
- Want a clear, manageable roadmap they can act on.
What you get
- An outside view, from the attacker's angle.
- Expert interpretation of your exposure.
- A remediation roadmap, ranked by business risk: high-impact systems first, then medium, then low.
- Clear next steps.
How it works
- 1. Interviews and questionnaires, scoped to your organization's size.
- 2. An external perimeter scan — no access to your systems needed.
- 3. A report and remediation roadmap, delivered in 4–8 weeks for €10–15K.
Sample finding: "TLS 1.0 still active on 3 externally-facing endpoints."
What the scan looks at
Three things, in that order, because each one narrows the next.
- Inventory. Which algorithms, key sizes, protocols and implementations run on your perimeter, where they are and how they are configured. This is where ancient algorithms still in production, mismatched key sizes across identical systems and protocols deprecated years ago turn up.
- Vulnerability. Which of those create real, exploitable risk in your environment rather than in theory: weak cipher suites, legacy protocol fallbacks, misconfigured TLS endpoints, and gaps in key management and rotation.
- Comparison. How the estate measures against the relevant standard, your stated policy and its own majority behaviour. This turns a list of findings into an order to work through.
Why the timing matters
Crypto agility is the ability to inventory, assess and change cryptography without redesigning the whole estate. It matters because algorithms, dependencies and regulatory expectations change at different speeds.
The assessment does not make that work disappear. It gives you the order: which exposed paths to address first, what evidence is missing and where a broader migration needs design work.
CMB vs CBA
The CMB is self-reported and tells you what you believe your cryptography is. The CBA reveals what it truly is.
Questions only the CBA answers:
- Which certs are exposed?
- Which protocols are negotiable?
- What looks vulnerable to recon?
CMB tell you what you think your crypto is. CBA tell you what it really is. And where to start fix.
CMB find inner hole by question. CBA scan real edge. See what attacker see.
You get
- Outside view — attacker's eyes.
- Expert read of findings.
- Fix roadmap, ranked by business risk.
- Clear next steps.
CMB vs CBA
What scan looks at
- Inventory. What runs on the perimeter, where, configured how.
- Vulnerability. Which of it bites here. Not theory.
- Comparison. How it stacks against the standard. Turns findings into an order.
Why now
Quantum breaks RSA and ECC. NIST standardised the replacements. Regulators start naming dates. Zero-trust wants finer crypto.
Low agility: run exposed, or rip it all out. Roadmap makes you agile while fixing, not after.
Questions CMB cannot answer
- What certs are exposed?
- What protocols are negotiable?
- What look vulnerable to recon?
CBA — Cryptographic Baseline Assessment. Expert-led external perimeter scan. Paid engagement.
Spec
CMB vs CBA
Assessment inputs
Drivers
Quantum computing against RSA and ECC; NIST post-quantum standardisation; regulatory quantum-safe timelines; zero-trust requiring dynamic, granular cryptography.
Answers only CBA gives
- Which certificates are exposed.
- Which protocols are negotiable.
- What is vulnerable to reconnaissance.