New research project by MTG and CryptoNext Security: We're building the cryptographic inventory of tomorrow—evolving from a static asset list into an active tool for automation, risk management, and post-quantum migration.
September 14, 2026
New research project by MTG and CryptoNext Security: We're building the cryptographic inventory of tomorrow—evolving from a static asset list into an active tool for automation, risk management, and post-quantum migration.
As part of the EU roadmap for quantum-safe cryptography, Germany’s Federal Office for Information Security (BSI) recommends establishing a cryptographic inventory by the end of 2026. We’re taking it a step further: together with our partner CryptoNext Security, we’re launching a new three-year research project that turns a classic cryptographic inventory into an active cryptographic inventory—featuring automated risk detection, smart certificate management, and a solid foundation for post-quantum migration.
We’re excited to announce funding approval for this German-French collaborative project through Germany’s Central Innovation Programme for SMEs (ZIM) and France’s Bpifrance. At the heart of the project lies a key question for the future of IT security: How do you turn a static overview of your cryptographic landscape into an active tool for security, automation, and post-quantum migration?
As IT, OT, and IoT systems become increasingly interconnected, the number of cryptographic objects within organizations is growing fast. Certificates, keys, algorithms, and protocols are now embedded in countless applications, devices, and infrastructures—with increasingly complex dependencies between them. At the same time, regulatory requirements are piling up: the EU Cyber Resilience Act (CRA), NIS2, DORA, and the upcoming migration to post-quantum cryptography (PQC) are all pushing organizations to finally gain visibility into their cryptography.
This is exactly where a cryptographic inventory comes in: it reveals which certificates, keys, and cryptographic algorithms are in use—the foundation for any risk management or migration planning effort. Such an inventory is often documented in the form of a Cryptography Bill of Materials (CBOM)—a structured, machine-readable record of cryptographic assets that is increasingly becoming a standard format for transparency and traceability. However, a classic cryptographic inventory tends to remain passive: it documents the current state but doesn’t actively intervene in processes.
An active cryptographic inventory shouldn’t just know what exists—it should understand relationships and derive concrete actions from them. Changes to certificates, keys, or systems are no longer viewed in isolation, but in the context of the entire cryptographic infrastructure. Building on this, processes are automated: above all certificate management, but also risk analysis and post-quantum migration planning.
CryptoNext Security (CNS) and MTG are pooling their respective expertise for this effort. Over the next three years, we’ll research, develop, and validate this approach in a practical demonstrator—with the clear goal of building a European, sovereign, and post-quantum-resilient cryptographic infrastructure for complex industrial, OT, and IoT environments.
Wondering how well-prepared your organization already is for post-quantum migration? We can help, drawing on our expertise in PKI, CLM, and crypto-agility—from your first cryptographic inventory to fully automated certificate management.
A cryptographic inventory is a structured overview of the cryptography deployed across an IT, OT, or IoT environment. It captures items such as certificates, keys, cryptographic algorithms, and protocols, and shows which systems and applications use them. A comprehensive cryptographic inventory lays the groundwork for crypto-agility and a well-planned post-quantum migration.
You can only migrate to post-quantum cryptography in a targeted way if you know which cryptographic methods and objects are in use across your infrastructure. A cryptographic inventory provides that transparency, helping you identify affected systems, assess risk, and prioritize migration efforts. Under the EU roadmap for quantum-safe cryptography, organizations are expected to establish a cryptographic inventory by the end of 2026.
A classic cryptographic inventory primarily documents which cryptographic objects exist. An active cryptographic inventory goes further: it maps dependencies, analyzes risk, and provides the information needed for automated processes. In our joint research project, CryptoNext Security and MTG are exploring how such an active cryptographic inventory can support organizations with certificate management, risk analysis, and post-quantum migration going forward.
A CBOM is a structured, machine-readable inventory of all of an organization's cryptographic assets—comparable to a Software Bill of Materials (SBOM), but for cryptography. It documents algorithms, keys, and certificates, providing a standardized foundation on which a cryptographic inventory can be built.
Learn more about CryptoNext Security
external WebsiteCentral Innovation Programme for small and medium-sized enterprises (SMEs)
external WebsiteFederal Office for Information Security (BSI) Press Release
NIS Cooperation Group Publishes EU Roadmap for Quantum-Safe Cryptography (Article in German)Article by heise
Create a Cryptographic Inventory: Cryptography Bills of Materials (CBOMs) (Article in German)Overview MTG PQC Research Projects
Learn more about our involvement in post-quantum cryptography (PQC) research projects.For further information feel free to contact us!