For a cryptographic inventory aimed at a post-quantum transition, allocate 60% of the budget to human resources, 25% to tools/licenses, and 15% to operating expenses.
This indicative estimate is calibrated to the profile of an organization with around 10,000 employees and a primary datacenter. It appears in a guide produced by a Campus Cyber* working group.
This guide proposes a four-phase approach:
- Preparation in 2026 (assessing the cryptographic footprint and developing the transition strategy)
- Starting deployment in 2026-2027 (integration and testing of PQC in a controlled environment)
- Migration of critical systems between 2028 and 2030
- Wider deployment and finalization between 2030 and 2035
About Fifteen Tools from Eight French Vendors
In parallel, the working group publishes a panorama of tools available for the migration to the post-quantum era.
It appears that inventory tools do not all allow adding sensors and/or providing external data sources, nor necessarily configuring security policy.
On the certificate management side, the scoring is often not customizable.
On the HSM side, many do not yet support PQC algorithms, and some frameworks are not crypto‑agile.
The panorama includes about fifteen products and services from French companies.
The Inventory Tools
On the inventory front, there is one: Compass, from CryptoNext Security. It operates under a proprietary license and carries no certifications by default, and it does not ship sensors by default. But its open architecture allows adding sensors as well as data formats. Analysis is performed on-site, with the generated elements stored in a local relational database. The security policy is configurable.
The Certificate Management Tools
In certificate management, there is BerryCert from DigitalBerry and Horizon from Evertrust.
The former is expected to become PQC-ready by H2 2026. It operates on-site and features a customizable scoring. Managed automation protocols: SCEP, ACME, CMP, and REST API.
The post-quantum capability is also on the roadmap for the latter, but without a calendar deadline. The scoring is also customizable. There is a SaaS version. Several probes enable certificate discovery (network, cloud services, containers, endpoints) and there is a partnership with CryptoNext for inventory. Managed automation protocols: SCEP, ACME, CMP, EST, WCCE, and REST API.
The HSMs
For HSMs, it’s either Eviden or Thales.
Eviden has two referenced solutions. On one hand, Crypt2pay, intended for encrypting financial flows. On the other, Protaccio, for general use, supporting three PQC algorithms (ML-DSA, ML-KEM, SLH-DSA) and offering a crypto‑agile framework via software integration.
Thales has three referenced solutions. Among them, payShield, specific to the banking and payments sector, which currently has neither PQC algorithms nor crypto agility. There are also Luna general-use HSMs, both crypto‑agile and PQC-ready. The Campus Cyber working group adds an offering inherited from Gemalto and “still used in some environments”: ProtectServer.
Cryptographic Libraries
CryptoNext Security is also mentioned for its Quantum-Safe Library, which enables key exchange (ML-KEM, FrodoKEM) and signing (ML-DSA, SLH-DSA, Falcon, XMSS). Developed in C, C++, and assembly, with wrappers for Go, Rust, Python, and Java, it is distributed in three versions: standard, embedded, and side-channel resistant (with masking).
Another option: Sphere, from IDEMIA Secure Transactions. Developed in C with Python and Java wrappers, it also offers standard and embedded variants, the latter described as resistant to side-channel attacks. Currently managed post-quantum algorithms include: ML-KEM, ML-DSA, SLH-DSA, and LMS.
PortyQ, which participated in the working group, is mentioned three times in the panorama. These refer to its LibCryptyq library, its OpenSSL provider, and its embedded version.
PKI
Evertrust appears again on the PKI side with the Stream offering, deployable on-site or SaaS. Under a proprietary license and CSPN-certified, it supports ML-DSA, ML-KEM, SLH-DSA, Falcon, and XMSS/LMS.
Another option: Eviden PKI (formerly IDnomic). Also on-prem or SaaS under a proprietary license, with CSPN certification criteria (EAL4+). It handles ML-DSA and Catalyst hybrid certificates.
A similar spec sheet (EAL4+, Catalyst, on-prem and SaaS…) for Nexus Certificate Manager PKI, credited to a subsidiary of IN Groupe.
Open Source: An Inventory Solution from Spain
Beyond France, the panorama lists about twenty European solutions. Some are open source. For example, for inventory, CryptoBOM-Forge from Banco Santander. It handles sensor integration but not external data sources (only CodeQL output). The security policy is configurable, but inventory is performed only in code (no protocol analysis). The tool outputs CBOM (CycloneDX).
Pcert Scanner, by Datawarehouse (Germany), scans a broader scope (endpoints, registries, network), with protocols HTTPS, FTPS, SSH, LDAP, NMAP and LDIF. Storage and analysis can be on-site or in SaaS.
QCBOM, from Synergy Quantum (Switzerland-India), handles binary analysis but not sensor integration. Nor security policy customization. External data sources can be supplied. It analyzes TLS, SSH, and VPN protocols. Outputs CBOM, CDV and PDF.
With SSHerlock from SSH.com (Finland), there is no sensor customization, no data sources, or security policy customization. The tool relies on system data (agent/script) and SSH protocol queries. It outputs PDF or HTML reports.
… as well as HSM and PKI made in Germany
Another European open-source offering: NetHSM, by Nitrokey (Germany). Aimed at SMBs, it has no certifications and post-quantum cryptography is on its roadmap.
The panorama includes other German-made HSMs. Specifically Ultimaco’s offerings. One of them is dedicated to protecting intellectual property and license management. Yubico (Sweden-USA) is also represented with its YubiHSM 2 in USB format. Also Securosys (Switzerland), with Primus HSM CyberVault.
Two of the European PKI solutions mentioned have open-source cores. One comes from the Czech Republic: CZERTAINLY. The other, from Germany: XiPKI.
* Air France-KLM, Banque de France, BNP Paribas, CryptoNext Security, Eviden, Orange Cyberdefense, PortyQ and QuRISK were involved in both deliverables. AXA participated in the guide’s development; ENSTA and HeadMind Partners contributed to the panorama.