[{"data":1,"prerenderedAt":134},["ShallowReactive",2],{"blog-\u002Fresources\u002Fblog\u002Fseven-places-quantum-crypto-hides":3},{"id":4,"title":5,"author":6,"authorTitle":7,"authorUrl":7,"body":8,"canonical":7,"category":94,"date":95,"description":96,"draft":97,"extension":98,"faqs":99,"findingsSource":7,"howto":7,"howtoTitle":7,"image":106,"keyFindings":7,"meta":107,"modified":95,"navigation":108,"path":109,"pullquote":7,"recommendations":7,"references":110,"related":7,"seo":120,"signposts":7,"slug":121,"stats":122,"stem":125,"tags":126,"tldr":132,"__hash__":133},"blog\u002Fresources\u002Fblog\u002Fseven-places-quantum-crypto-hides.md","The Seven Places Quantum-Vulnerable Cryptography Hides","ArcQubit Team",null,{"type":9,"value":10,"toc":87},"minimark",[11,16,20,24,71,75,78],[12,13,15],"h2",{"id":14},"the-answer-up-front","The answer, up front",[17,18,19],"p",{},"Quantum-vulnerable cryptography does not live in one place. It is scattered across seven distinct surfaces of a modern software stack, and the reason most organizations underestimate their exposure is simple: the tool they use inspects one surface and reports it clean, while the other six go unexamined.",[12,21,23],{"id":22},"the-seven-surfaces","The seven surfaces",[25,26,27,35,41,47,53,59,65],"ol",{},[28,29,30,34],"li",{},[31,32,33],"strong",{},"Source code."," Hardcoded algorithms, key sizes, and cipher suites written directly into your application.",[28,36,37,40],{},[31,38,39],{},"Dependencies."," Cryptography pulled in transitively through libraries you never audited.",[28,42,43,46],{},[31,44,45],{},"SBOMs and CBOMs."," The declared inventory, which is only as accurate as the process that generated it.",[28,48,49,52],{},[31,50,51],{},"Certificates."," TLS and code-signing certificates whose signature algorithms quietly age into risk.",[28,54,55,58],{},[31,56,57],{},"Infrastructure."," Load balancers, service meshes, and managed services terminating cryptography outside your code.",[28,60,61,64],{},[31,62,63],{},"Binaries."," Compiled artifacts where the algorithm is baked in and invisible to a source scan.",[28,66,67,70],{},[31,68,69],{},"Runtime tokens."," JWTs, session tokens, and signed payloads generated and verified live in production.",[12,72,74],{"id":73},"why-single-surface-tools-mislead","Why single-surface tools mislead",[17,76,77],{},"A scanner that reads only source code will pass a repository whose real exposure lives in a five-year-old certificate or a vendored binary. The clean report is worse than no report, because it creates false confidence. Credible discovery has to span all seven surfaces at once.",[17,79,80,81,86],{},"Run ",[82,83,85],"a",{"href":84},"\u002Fqucode","QuCode"," to see where quantum-vulnerable cryptography actually lives in your stack.",{"title":88,"searchDepth":89,"depth":89,"links":90},"",2,[91,92,93],{"id":14,"depth":89,"text":15},{"id":22,"depth":89,"text":23},{"id":73,"depth":89,"text":74},"Security","2026-07-08","Quantum-vulnerable cryptography hides across seven surfaces of your stack. Here is the field guide, and why single-surface scanners leave you exposed.",false,"md",[100,103],{"q":101,"a":102},"What does it mean for cryptography to be quantum-vulnerable?","It means the algorithm can be broken by a sufficiently large quantum computer. RSA and ECC are the primary examples, because Shor's algorithm defeats the math they rely on.",{"q":104,"a":105},"Why isn't one cryptographic scanner enough?","Because vulnerable cryptography appears on seven different surfaces, from source code to runtime tokens. A scanner that only reads source misses certificates, binaries, and dependencies entirely.","\u002Fassets\u002Fblog\u002Fseven-places-quantum-crypto-hides.png",{},true,"\u002Fresources\u002Fblog\u002Fseven-places-quantum-crypto-hides",[111,114,117],{"label":112,"url":113},"NIST FIPS 203","https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Ffips\u002F203\u002Ffinal",{"label":115,"url":116},"Executive Order 14412 (2026)","https:\u002F\u002Fwww.whitehouse.gov\u002Fpresidential-actions\u002F2026\u002F06\u002Fsecuring-the-nation-against-advanced-cryptographic-attacks\u002F",{"label":118,"url":119},"UK NCSC: Timelines for migration to post-quantum cryptography","https:\u002F\u002Fwww.ncsc.gov.uk\u002Fguidance\u002Fpqc-migration-timelines",{"title":5,"description":96},"seven-places-quantum-crypto-hides",[123,124],"Most cryptographic scanning tools inspect a single surface, leaving the other six unexamined (ArcQubit, 2026).","Government mandates worldwide set post-quantum migration deadlines between 2030 and 2035 (U.S. EO 14412, EU roadmap, UK NCSC).","resources\u002Fblog\u002Fseven-places-quantum-crypto-hides",[127,128,129,130,131],"post-quantum cryptography","cryptographic discovery","cryptographic inventory","SBOM","primer","Quantum-vulnerable cryptography hides across seven distinct surfaces, and most scanning tools inspect only one of them.","devewd3D-ZCRZoF6aIF2LDusIhAGU4k6BfirgHA-ON0",1784747240090]