Skip to main content
BTP detects cryptographic algorithms, protocols, and certificate issues across six categories during static binary analysis. Each detected algorithm is assigned a classification status based on its cryptographic strength and industry guidance. Active compliance reporting is scoped to NIST IR 8547 (post-quantum cryptography). The Weak and Deprecated classifications are informational, derived from industry consensus (NIST SP 800-131A, RFC 7568, RFC 8996) - BTP does not generate compliance reports against those standards.

Detection Coverage

See Cryptographic Detection for how detection works by binary type.

Classification

Encryption Algorithms

Hashing Algorithms

Signing Algorithms

Post-quantum algorithms

These algorithms are detected and classified as NIST IR 8547 compliant. Detection confirms their presence; adoption replaces quantum-vulnerable counterparts.
PQC digital signature algorithms are currently only detected in UEFI modules and certificates. These algorithms are not yet supported for detection in Java and Python managed runtimes or ELF native binaries.

Quantum-vulnerable algorithms

Deprecated algorithms

Weak algorithms

MAC Algorithms

Pseudorandom Number Generators

Detection is available for native binaries only.

Protocols

Certificate Issues

PQC Compliance Assessment

BTP’s active compliance reporting for cryptographic algorithms is scoped exclusively to NIST IR 8547. Weak and Deprecated classifications above are informational and do not constitute a compliance report.
Quantum-vulnerable algorithms remain secure against classical computers today. The risk is retroactive decryption by a future cryptographically-relevant quantum computer (CRQC) - a relevant threat for long-lived encrypted data.
BTP identifies all quantum-vulnerable algorithm instances per binary image, maps them to NIST IR 8547 guidance, and surfaces replacement recommendations. This assessment is published as the PQC Compliance Report (PDF and JSON). NIST IR 8547 migration timeline: