You cannot migrate what you have not seen — and you cannot defer what you have not scoped. IFG is the independent practice that enumerates the cryptography in the scope you choose, and states plainly what it could not reach. We produce the map. We never sell the hammer.
No single technique sees the whole cryptographic picture, at any scope. Each mode has its own visibility and its own blind spots. The discipline is the integration of all five into a coherent inventory — and the honesty to mark what none of them reached.
We call the method Step Zero℠ — the enumeration that must be complete before any migration decision can be trusted. Not the first phase of a migration program. The work that has to be finished before that program's outputs mean anything.
The cryptography in transit announces itself. We read the handshakes traversing your network — the protocols, key exchanges, and cipher suites in active use — without sending a single probe packet.
The capability that ships inside your software, whether or not it is running. We surface the cryptographic libraries and constants embedded in deployed binaries — the dormant algorithms a system could invoke.
What the cryptographic layer does as the system runs. Live observation of cryptographic calls in execution, catching what static inspection cannot — the algorithm constructed at runtime, the path only exercised under load.
The cryptography declared in your stores and config. We parse certificate stores, key stores, and configuration to enumerate the trust material and cryptographic policy the estate is set up to use.
The cryptography held by your cloud and managed services. We enumerate keys, algorithms, and rotation posture exposed through managed key-service interfaces across your cloud footprint.
Every inventory has a boundary. Ours is written down. Where the five modes leave an asset unseen — the hardware-isolated key, the offline system, the path never run — we name it. A coverage map that hides its edges is not an inventory. It is theater.
Three applications of the Step Zero℠ method, scoped to the size and shape of your estate. Start with a fast read, move to a full inventory, and license the method when discovery becomes a standing capability. No tier sells remediation.
A fast, bounded scan to tell you whether your current inventory holds.
The full discipline across the estate in scope, producing an inventory you can act on.
License the Step Zero℠ method as a standing internal capability.
No published price list. Every estate is different — we scope to yours.
A building inspector who also owned the construction company would not be an inspector. They would be a salesperson with a clipboard. The independence is the value.
IFG enumerates cryptographic assets and stops there. We do not sell the migration, the tooling, or the remediation contract that follows. That boundary is not a limitation — it is the reason the inventory can be trusted. When we tell you what is in your walls, nothing in our business depends on the answer.
It is also why we name the residual. A discovery practice that profits from the fix has every reason to make the map look complete. We have none. So we draw the edge of what we could see, and we hand it to you straight.
IFG, LLC is collaborating with the National Cybersecurity Center of Excellence (NCCoE) in the Migration to Post-Quantum Cryptography Building Block Consortium to bring awareness to the issues involved in migrating to post-quantum algorithms and to develop practices to ease migration from current public-key algorithms to replacement algorithms. NIST does not evaluate commercial products under this Consortium and does not endorse any product or service used. Additional information on this Consortium can be found at: https://www.nccoe.nist.gov/projects/building-blocks/post-quantum-cryptography.
The discipline this practice applies is not proprietary framing. It is published, dated, and citable — so anyone assessing this work, or applying it themselves, can read the reasoning rather than take it on assertion. All four records are open access under CC BY 4.0.
Defines the terms this practice operates on: complete enumeration as a precondition rather than a phase; discovery theater, output that is authoritative in form and silent about its own coverage; the honest residual, the assets a methodology could not reach, named explicitly; and the distinction between automable collection and non-automable coverage — an instrument cannot establish the completeness of its own output.
Inventories record what a cryptographic asset is — algorithm, library, version, location. They do not record what it needs: the external services each operation requires in order to keep functioning. Defines six classes of operational dependency and distinguishes what can be enumerated from what would require intrusive testing to establish.
The assurance professions settled the grammar of scope more than a century ago: an attestation report states what was examined and, where an intended procedure could not be performed, a scope limitation that modifies the conclusion. This note maps that element onto cryptographic inventory. It separates claims about the inventory record from the claim that the record describes the estate, and sets out a five-element coverage declaration — subject matter and boundary; criteria; methods applied by boundary segment; scope limitation, with each unreached class marked closable by further effort or closed by construction; and a conclusion modified by that limitation. It also identifies the schema element no current bill-of-materials specification provides: a first-class object for an examined-and-not-reached class, carrying a reason code and a permanence flag. Absent it, the absence of a record and the record of an absence are indistinguishable.
Written for the assessor rather than the buyer: what can and cannot be concluded from an inventory handed over as evidence. It separates the first-order claim that a set of cryptographic assets exists in an environment from the second-order claim that a stated method, applied to a stated scope at a stated time, reached a stated boundary — and argues that only the second can be evaluated without independently enumerating the estate. An inventory submitted without a coverage declaration is unfalsifiable at the point of assessment. Sets out a three-part residual taxonomy (catalog, detection, temporal), a six-item triage of an inventory's face, six questions that surface a method's boundary, and where discovery scope and cardholder data environment scope interact.
Tell us the shape of your environment and what you are trying to protect. We scope an engagement to fit — and tell you honestly what we will and will not be able to see.
A 30-minute conversation to size your estate and outline the right engagement depth. No preparation needed.
Choose a time →Share a few details and we will come back with a scoped engagement and an honest read on coverage.
We will read it and come back with a scoped engagement. Expect a reply from a person.