The Quantum Command Inventory dashboard gives program managers, security leaders, and analysts an authoritative fleet-level view of PQC migration progress. It answers a central question: across all observed endpoints, how many are PQC-ready, modern, classical, or legacy?
Use this dashboard to establish overall posture, compare readiness across operating systems, identify the largest legacy populations, and apply tier filters before moving into application-level investigation.
Operational guidance: Use the three interactive tier charts together. Key exchange, protocol, and certificate signature represent separate migration dimensions; improvement in one dimension does not guarantee that an endpoint is fully quantum-ready.
Panels
| Panel | Type | What It Shows |
|---|---|---|
| Navigation Links Bar | Links | Opens the other Quantum Command dashboards without returning to the Elasticsearch dashboard listing. |
| PQC Compliance Progress Map | Vega summary | Shows unique host counts at the PQC READY tier with operating-system and key-exchange context. |
| Crypto Posture Score | Vega scorecard | Provides an executive readiness score across the key exchange, protocol, and certificate-signature dimensions, with an OS-platform breakdown. |
| Key Exchange Tier | Interactive Vega chart | Breaks unique hosts into PQC READY, MODERN, CLASSICAL, and LEGACY key-exchange tiers. Selecting a tier filters the dashboard. |
| TLS Protocol Tier | Interactive Vega chart | Shows unique hosts using TLS 1.3, TLS 1.2, or legacy protocol versions. Selecting a tier filters all panels. |
| Certificate Signature Tier | Interactive Vega chart | Groups unique hosts by PQC-ready, modern, classical, or legacy certificate-signature algorithms. |
| Windows Workstations | OS breakdown | Shows key-exchange, protocol, and signature tier distributions for Windows workstation endpoints. |
| Windows Server | OS breakdown | Shows all three readiness dimensions for Windows Server endpoints. |
| macOS | OS breakdown | Shows all three readiness dimensions for macOS endpoints. |
| CentOS | OS breakdown | Shows all three readiness dimensions for CentOS endpoints. |
| Red Hat Enterprise Linux | OS breakdown | Shows all three readiness dimensions for RHEL endpoints. |
| Ubuntu | OS breakdown | Shows all three readiness dimensions for Ubuntu endpoints. |
Key Data Fields
| Field | Description |
|---|---|
| omb.kex_tier | Key-exchange readiness tier: PQC READY, MODERN, CLASSICAL, or LEGACY. |
| omb.protocol_tier | TLS protocol tier: TLS 1.3, TLS 1.2, or LEGACY. |
| omb.sig_tier | Certificate-signature readiness tier: PQC READY, MODERN, CLASSICAL, or LEGACY. |
| host.id | Unique endpoint identifier used for host cardinality calculations. |
| host.os_category | Normalized OS category used by the six platform panels. |
Reading the Dashboard
Begin with the Crypto Posture Score
Use the composite score as an executive indicator, then validate it against the three independent tier charts.
Prioritize LEGACY populations
Select LEGACY in the key-exchange or certificate-signature chart to isolate endpoints requiring the most immediate remediation.
Compare OS categories
Use the six platform panels to determine whether risk is concentrated in a particular operating system or distributed across the fleet.
Count hosts, not records
All tier values use unique host counts so repeated scans do not inflate the reported endpoint population.
Filtering and Performance
The dashboard opens with a default time range of Last 90 days. Global Elasticsearch dashboard filters apply to the panels unless a panel description states otherwise. Preserve relevant filters when navigating between related dashboards so the investigation remains scoped to the same application, host, tier, or certificate population.