Frequently asked questions
What does Dutch guidance ask government organizations to do first?
Find the cryptography your systems use, assess the risks and prepare a migration plan. That is the starting point in Dutch NCSC guidance. Check separately which national, sector and EU milestones apply to your services.
Does the inventory data leave our environment?
The application and inventory run on infrastructure you control. You decide whether to transfer or share results. Normal inventory results include information about private and symmetric keys, but exclude their secret values by default. Check files and exports for sensitive information before sharing them.
How does this relate to the TNO market survey of CADI tooling?
The survey recommends starting with a defined test scope and checking what tools actually find. You can evaluate Cryptoramic that way on your own systems. Cryptoramic was not one of the products assessed by TNO.

