Skip to content

How to run your first cryptographic scan

A step-by-step for the first discovery run — pick a scope, run qScan, read the findings, and turn them into a prioritized starting backlog.

IT & securityIntro5 min· Updated Jul 22, 2026
TL;DR

Start small, then widen

Do not try to scan everything at once. Pick one important repository or service, run qScan, read the findings by exposure, and produce a short prioritized list. That first pass builds the muscle and the baseline you widen from.

Steps

  • **1. Choose a scope.** Pick one high-value target — a customer-facing service or a repository that handles sensitive data. Narrow scope makes the first results readable.
  • **2. Grant read access.** Give qScan read-only access to that repository or point it at the service endpoint. No write access is needed.
  • **3. Run the scan.** Trigger a scan and let it inventory algorithms in code, dependencies, certificates, and configuration.
  • **4. Read findings by exposure.** Sort by the exposure weighting, not the raw count. Focus first on quantum-vulnerable key exchange (RSA, ECDH) protecting long-lived or externally-facing data.
  • **5. Record the baseline.** Save this run as your baseline readiness score so future scans show a trend.
  • **6. Produce a prioritized list.** Turn the top findings into a short backlog: what to migrate, in what order, using the harvest-now-decrypt-later lens.
  • **7. Widen scope.** Add the next repositories or services, and move toward continuous scanning in CI.
Pitfall

Do not drown in the first report

A first scan of a real codebase can surface a lot. The mistake is treating every finding as equally urgent. Prioritize ruthlessly by data shelf life and external exposure — a handful of high-exposure items is a better week-one outcome than a triaged list of hundreds nobody acts on.