Export
The artifact you take away
A migration plan a security lead can read without opening this application: every score, every factor, every citation, and the seal the numbers were computed under.
Preview
# Demo: billing-gateway — post-quantum migration plan > Generated by PQC Triage 1.0.0 · engine `hndl@1.0.0` · 2026-10-04 This plan is an engineering aid, not an assurance. Every number below is produced by a deterministic function you can read and re-run; none of it is a certification, and it does not tell you whether a specific system is safe. ## Deadline arithmetic Mosca's rule: if data must stay confidential for **X** years after capture, the migration takes **Y** years, and a cryptographically relevant quantum computer arrives in **H**, work must start by **H − (X + Y)**. | Setting | Value | Source | | --- | --- | --- | | Quantum-capability horizon (H) | 2033 | Analyst assumption, editable in Settings | | NIST deprecates 112-bit public key | 2030 | [NIST IR 8547](https://csrc.nist.gov/pubs/ir/8547/ipd) | | NIST disallows quantum-vulnerable public key | 2035 | [NIST IR 8547](https://csrc.nist.gov/pubs/ir/8547/ipd) | | NIST disallows 112-bit-level symmetric | 2030 | [NIST IR 8547](https://csrc.nist.gov/pubs/ir/8547/ipd) | ## Portfolio - **Weighted exposure score:** 58 / 100 (high) - **After the recorded decisions:** 58 / 100 (high) - **Surfaces:** 12, of which 0 triaged and 6 already past their start date - **First thing that breaks:** in -3.8 years - **Highest risk:** Math.random() for a secret in source at 90 ## Surfaces | Surface | Primitive | Role | X (yrs) | Score | Start by | Decryptable from | Replacement | Decision | | --- | --- | --- | --- | --- | --- | --- | --- | --- | | bcrypt@5.1.1 · bcrypt | bcrypt | password-storage | 0 | 4 | 2033 | 2033 | Keep bcrypt or move to Argon2id | untriaged | | jsonwebtoken@9.0.2 · HMAC-SHA-256 | hmac-sha256 | session-establishment | 5 | 14 | 2028 | 2028 | Keep HMAC-SHA-256 | untriaged | | node-forge@1.3.1 · RSA-2048 | rsa-2048 | session-establishment | 5 | 79 | 2025 | 2028 | ML-KEM-768 (FIPS 203), hybrid with X25519 | untriaged | | elliptic@6.5.4 · ECDSA P-256 | ecdsa-p256 | code-signing | 10 | 81 | 2020 | 2023 | ML-DSA-65 (FIPS 204) | untriaged | | libsodium-wrappers@0.7.15 · ChaCha20-Poly1305 | chacha20-poly1305 | data-in-transit | 3 | 6 | 2030 | 2030 | Keep ChaCha20-Poly1305 | untriaged | | tweetnacl@1.0.3 · X25519 | x25519 | session-establishment | 5 | 76 | 2026 | 2028 | ML-KEM-768 (FIPS 203), hybrid with X25519 | untriaged | | HMAC-SHA-256 in source | hmac-sha256 | session-establishment | 5 | 14 | 2028 | 2028 | Keep HMAC-SHA-256 | untriaged | | RSA-2048 in source | rsa-2048 | session-establishment | 5 | 78 | 2025 | 2028 | ML-KEM-768 (FIPS 203), hybrid with X25519 | untriaged | | 3DES in source | triple-des | data-at-rest | 7 | 78 | 2025 | 2026 | AES-256-GCM | untriaged | | MD5 in source | md5 | unknown | 5 | 86 | 2027 | 2028 | SHA-256 | untriaged | | Math.random() for a secret in source | math-random | key-generation | 5 | 90 | 2028 | 2028 | crypto.randomBytes / secrets.token_bytes | untriaged | | ECDH P-256 in source | ecdh-p256 | session-establishment | 5 | 77 | 2025 | 2028 | ML-KEM-768 (FIPS 203), hybrid with X25519 | untriaged | ## Why each score is what it is ### bcrypt@5.1.1 · bcrypt bcrypt gives 6.2 years before captured data is decryptable, so start migration by 2033. Quantum strength: **128 bits**. NIST SP 800-57 Part 1 Rev. 5, Key Management. | Factor | Weight | Severity | Points | Why | | --- | --- | --- | --- | --- | | Harvest-now-decrypt-later window | 0.26 | 0.00 | 0.0 | A bcrypt hash is not decryptable; it is attacked by brute force, so the lever is the work factor rather than a migration deadline. _X=0, Y=0, H=2033; NIST has no disallowance date for this primitive._ | | Quantum security strength | 0.22 | 0.00 | 0.0 | bcrypt retains 128 bits against a quantum adversary. _NIST SP 800-57 Part 1 Rev. 5, Key Management; symmetric strength halves under Grover._ | | Migration headroom | 0.18 | 0.00 | 0.0 | bcrypt is already standardised post-quantum with no disallowance date, so there is no deadline to miss. _Earliest NIST deprecation none, disallowance no … truncated in the preview; the download is complete.