IT Brief US - Technology news for CIOs & IT decision-makers
United States
SafeLogic launches platform for post-quantum migration

SafeLogic launches platform for post-quantum migration

Fri, 24th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

SafeLogic has launched SafeLogic Cryptographic Posture Management, a platform designed to help organisations manage the shift to post-quantum cryptography by giving them a clearer view of current cryptographic use.

The platform combines continuous discovery of cryptographic assets, inventory management, risk-based prioritisation and remediation in a single system. It is intended to help security teams identify where cryptography is used across software, infrastructure and network traffic, then decide what to address first.

The launch comes as governments and regulators step up efforts to move organisations towards post-quantum cryptography, a set of methods intended to resist attacks from future quantum computers. For many businesses, the main obstacle is not replacement technology itself but a lack of visibility into where existing cryptographic tools, libraries and certificates sit across their estates.

SafeLogic says the platform continuously discovers cryptography across the software lifecycle rather than relying on one-off assessments. It uses a mix of CI/CD pipeline scanning, host-based analysis, network TLS discovery and runtime telemetry to build a single inventory of cryptographic assets.

That inventory can be exported as a CycloneDX cryptographic bill of materials, or CBOM, which is increasingly used to support compliance and audit work. The platform also adds operational context to technical findings so teams can focus on the highest-risk assets.

Migration focus

The product is intended to support both discovery and remediation. SafeLogic says customers can use it to replace vulnerable cryptography with its own FIPS 140-validated post-quantum cryptography while keeping existing software delivery processes in place.

It also includes policy-based governance features that allow organisations to define approved cryptographic standards, enforce compliance and identify policy violations across their environments. SafeLogic describes the system as modular, with integrations designed to work alongside existing telemetry sources, discovery tools and reporting dashboards.

The broader market for cryptographic management is drawing more attention as businesses confront the practical implications of post-quantum migration. Standards bodies and government agencies have been issuing guidance on the need to prepare for new cryptographic approaches, while security teams also grapple with technical debt in legacy systems.

According to SafeLogic, the company has been active in FIPS 140-validated cryptographic software for more than 15 years, with products used across enterprise, cloud, mobile, embedded, IoT and mainframe environments. It also pointed to its involvement in post-quantum cryptography standardisation work, including participation in NIST NCCOE's Cryptographic Visibility and Risk Based Management workstream.

Evgeny Gervis outlined the problem the product is intended to address. "The biggest obstacle to post-quantum migration is understanding where cryptography exists, determining what actually matters, and remediating it without disrupting operations. Paralysis by analysis that often comes from wading through noisy data from traditional cryptographic discovery tools is no longer an option. The time to prioritize, remediate and govern cryptographic use is here and that is exactly what SafeLogic CPM does," said Evgeny Gervis, Chief Executive Officer, SafeLogic.

The launch reflects a wider shift in cyber security from static audits to continuous monitoring, particularly in areas where software changes quickly and cryptographic use can spread through third-party code, developer tools and production systems. By tying discovery to governance and replacement, suppliers are trying to turn what has often been a consulting exercise into an operational process.

For organisations preparing for post-quantum standards and tighter regulatory scrutiny, the challenge is likely to be less about a single migration event and more about maintaining an accurate picture of cryptographic use over time. The platform is available immediately.