The Application Report dashboard provides an application-centric view of post-quantum cryptography readiness. It combines readiness metrics with operational details, allowing analysts to evaluate key exchange, TLS protocol adoption, certificate signature posture, cryptographic risks, and supporting application and certificate information.
Operational guidance: Begin with the readiness summary to understand overall application compliance, then review risk and usage panels to identify technologies requiring modernization. Use the detailed application, certificate, and DoD OMB reporting tables to investigate individual findings.
Panels
| Panel | Type | What It Shows |
|---|---|---|
| Post-Quantum Cryptography Readiness | Table | Key-exchange technologies grouped by PQC READY, MODERN, CLASSICAL, and LEGACY tiers, with counts. |
| Application PQC Dashboard | Readiness summary | Application compliance indicators for key exchange, TLS protocol, and certificate signatures, including percentages and application counts. |
| Certificate Signature | Table | Certificate-signature technologies grouped by readiness tier, with counts. |
| Web Server Distribution | Stacked bar chart | Distribution of web-server families by PQC key-exchange tier. |
| Weak Ciphers In Use | Table | Weak cipher algorithms currently observed and the number of applications associated with each. |
| Insecure Ciphers In Use | Table | Insecure cipher algorithms currently observed and the number of applications associated with each. |
| Port Usage | Table | Observed ports divided between quantum-resilient and not-resilient activity. |
| Vulnerable Software | Table | Software packages identified as not quantum ready. |
| Non-Quantum Ready KX | Table | Key-exchange technologies that do not match recognized post-quantum patterns. |
| Non-Quantum Ready Signatures | Table | Signature technologies that do not match recognized post-quantum patterns. |
| Application Detail | Table | Detailed application cryptography inventory, including key exchange, cipher suite, protocol, readiness, host, port, and certificate information. |
| Certificate Detail | Table | Certificate subjects, counts, issuance and expiration dates, remaining time, lifespan, curve, algorithm, and key size. |
| DoD OMB Report Detail | Table | Detailed DoD OMB reporting fields for software, algorithms, protocols, certificates, cryptographic parameters, and timestamps. |
Key Data Fields
| Field | Description |
|---|---|
| process.executable / process.name | Identifies the service application used in application-level reporting and filtering. |
| omb.kex_tier | Provides the key-exchange readiness tier. |
| omb.protocol_tier | Provides the TLS protocol readiness classification. |
| omb.sig_tier | Provides the certificate-signature readiness tier. |
| tls.supported_ciphers | Lists supported TLS cipher suites used in detailed reporting. |
| tls.kx | Identifies the preferred key-exchange technology. |
| x509.subject.distinguished_name | Identifies the certificate subject shown in Certificate Detail. |
| certificate.not_before / certificate.not_after | Provide certificate issuance and expiration dates. |
| certificate.subject_public_key_info.algorithm / x509.server.port / destination.port / host_id | Support algorithm, port, and host-level detail used throughout the dashboard. |
Reading the Dashboard
Start with the readiness summary
Compare key-exchange, protocol, and certificate-signature compliance for service applications.
Review application risk and usage
Examine web-server distribution, weak and insecure ciphers, port usage, vulnerable software, and non-quantum-ready key exchange and signatures.
Investigate detailed records
Use Application Detail for application-level cryptography, Certificate Detail for certificate lifecycle and key information, and DoD OMB Report Detail for the complete reporting record.
Expect certificate gaps in some filters
Application, key-exchange, and protocol selections can legitimately produce no Certificate Detail results when those fields are not present in the certificate events.
Filtering and Implementation Notes
Use the Time Range, Key Exchange, TLS Protocol, Cert Signature, and Application filters to focus the dashboard. Category filters default to All and apply across the dashboard.
The Certificate Detail table depends on certificate records, so some valid application-level filters can return no certificate rows.