PQCAT · Post-Quantum Compliance Assessment Tool

Find what the quantum era will break.

PQCAT discovers and inventories the cryptography across your code, certificates, and infrastructure — then classifies what’s quantum-vulnerable against the compliance frameworks you answer to. Built by engineers who’ve completed the migration.

~/ pqcat — cryptographic exposure scan
$ pqcat scan ./infra --report ────────────────────────────────── RSA-2048 TLS certs ⚠ vulnerable ECDSA P-256 signing ⚠ vulnerable ECDH key exchange ⚠ vulnerable ML-DSA-44 — PQ-ready ────────────────────────────────── 142 assets · 138 vulnerable · 4 ready
An inventory of every algorithm in use, ranked by quantum exposure and data lifetime.
§ 01 — What PQCAT does
Discover
Cryptographic asset inventory · code, TLS, signing, key exchange
Classify
Quantum vulnerability vs 12 compliance frameworks
Report
Federal-grade reporting · for auditors & regulators
Prioritize
Risk-ranked migration plan · to NIST FIPS 203 / 204
Credential
Patent-pending · SDVOSB, sole-source eligible
§ 02 — Built for high-assurance industries
Government & defense
Long-lifetime classified data · CNSA 2.0 timelines
Institutional finance
Payment rails, custody, signing keys
Healthcare
Decades-long record confidentiality
Critical infrastructure
Long-deployment, hard-to-patch systems

pqcat.io is the canonical PQCAT site. This page is the Soqucoin Labs overview; the product, documentation, and trial live at pqcat.io.