Third-Party Cryptographic Risk

Third-Party Cryptographic Risk.

Your own estate is only part of the exposure. Every supplier and third party carries a cryptographic position of its own.

Navigator's supplier register makes that position visible, evidenced and current, instead of assumed.

Supplier post-quantum position
  1. 1
    No position
    Nothing recorded yet
  2. 2
    Stated
    Supplier has made a public statement
  3. 3
    Committed
    A published roadmap exists
  4. 4
    Certified
    Backed by a formal certification
The supplier register

Every supplier's position, on a four-step scale.

A supplier register records each supplier's post-quantum position — no position, stated, committed, or certified — alongside its evidence: a link to the supplier's own published statement, roadmap or certification, and the date it was last assessed.

Every change to a supplier's recorded position is written to the audit log, so the history of what was known and when is never lost to an overwrite.

Coverage

Gaps in supplier coverage surface on their own.

A coverage view shows what percentage of registered suppliers have a recorded position, and flags it the moment any do not.

That figure recalculates automatically as suppliers are added or assessed, and clears once the gap is addressed — it is a live view of coverage, not a point-in-time report.

The register supports third-party cryptographic risk assessment as part of a broader governance and operational-resilience programme.

Where this stops

“The register records posture — it does not yet propagate it. That's the difference between knowing your supply chain has a gap and knowing which of your assets sit behind it.”

Talk to us

Know where every supplier stands, not just your own estate.

Request a Navigator demo to see how the supplier register and coverage view fit into your governance programme.

Request a Navigator demo