No control plane. No subscription to keep the lights on. Every deliverable ships as a standalone document you can act on independently.
What this means
Every MCRS deliverable is a standalone artifact (a document, a data file, a Crypto-SBOM) that you own outright and can act on with any vendor, any auditor, or your own team. There is no platform login, no subscription that keeps the results visible, no vendor dependency embedded in your security posture.
The risk without it
Most PQC platforms are control planes. The inventory, the policy, the migration state, all of it lives in the vendor's system. Cancel the subscription and you lose visibility into your own cryptographic posture. You are not buying a finding; you are renting access to it. That creates a permanent vendor dependency at the center of your compliance stack.
How we do it
MCRS delivers: a PDF finding with full methodology, raw circuit output data (JSON), a Crypto-SBOM (machine-readable cryptographic inventory of the scoped surface), and a migration priority map. All files transfer at delivery. No login. No follow-on platform. You can take the Crypto-SBOM to any migration vendor. The finding stands as an independent audit record regardless of what happens to MCRS.
Evidence
- -Deliverable format: PDF + JSON raw data + Crypto-SBOM
- -No platform, no login, no subscription dependency
- -Crypto-SBOM is vendor-agnostic, works with any migration partner
- -Finding stands as an independent audit record
