SaQura

SaQura Crypto Inventory

When does your most important certificate expire — and which encryption will quantum computers break?

Since March 2026, new TLS certificates are capped at 200 days; from March 2027 it's 100. Anyone renewing by hand will soon renew four times as often — and a single forgotten certificate takes down a shop, portal or API. SaQura Crypto Inventory shows you in a single day which certificates and which encryption run where, when they expire — and which of it quantum computers will break. The app runs on your own computer with no installation, reads only, and sends nothing out.

Packages & pricing

Pro

€5,900/ year

Your inventory and ongoing readiness across the company

  • Full scan: source code, dependencies, key files, network (TLS/SSH) & certificates
  • Clear report (PDF) + technical inventory (CBOM)
  • Sealed reports — later changes are provable offline
  • History & audit timeline: measure progress and evidence it
  • One combined report across all units and sites
  • Guided questionnaire for systems without code access
  • Email support
  • For companies with up to 249 employees (counted across the group)
Enquire

Enterprise

On request

From 250 employees

  • Everything in Pro
  • Group-wide license
  • Custom terms
Enquire

Prices net, plus VAT where applicable · annual license · pay in your currency.

SaQura Crypto Inventory for your system

Standalone app — no installation, no Node.js needed.

macOS

.dmg · Apple Silicon & Intel · notarized

Download

Windows

.zip · 64-bit

Download

Linux

.tar.gz · ARM64 & x86-64

Download

Requirements: none — the app is standalone (Windows 10/11 · macOS 12 or later · Linux x86-64/ARM64).

Certificate lifetimes are shrinking in fixed steps

200 days

since 15 March 2026

100 days

from 15 March 2027

47 days

from 15 March 2029

The maximum lifetime of publicly trusted TLS certificates is dropping in fixed steps, set by industry ballot. Manual renewal simply doesn't scale any more — first you need the overview, then the automation.

And NIS2 demands the evidence

Germany's NIS2 implementation act has been in force since December 2025. Affected companies must present documented policies for the use of cryptography — and such a policy starts with knowing which encryption and which certificates are in use at all. That is exactly what the report delivers: a clear PDF for management and a technical inventory (CBOM) for the auditor.

What the app does — in plain words

Almost every piece of software encrypts data — but hardly anyone knows where each certificate expires or which method is used where. The app builds an inventory: every certificate with its expiry date, all encryption in use — plus which of it coming quantum computers will break, and in which order to replace it. Clear enough for management, detailed enough for engineering.

Three steps to clarity

1 · Scan

Start the app — it checks source code, network & certificates. Read-only, nothing is changed.

2 · Report

A clear report with a traffic-light view: what's safe and what isn't — saveable as PDF.

3 · Roadmap

Prioritised steps to quantum-safe — and ready to implement with SaQura.

Build it in yourself — or let us do it

The roadmap shows what needs to happen. You can act on it yourself: the packages and documentation are open, and your team builds SaQura straight into your systems. Would you rather hand it over? Then we take care of it — from the first integration to the completed migration. The inventory is included. Tell us what you run, and you get a fixed quote.

Request implementation

Who it's for

For organisations that must show where they stand on quantum security — e.g. for BSI, NIS2 or GDPR. No prior knowledge needed: download the app, run it, get a finished report.

Every package includes

  • Standalone app for Windows, macOS & Linux — no installation, no Node.js needed
  • Report and app in German, English and Japanese
  • Runs entirely locally and read-only — your data never leaves the device
  • Annual license including updates — the detection state is versioned and follows NIST/BSI

The report shows which certificates expire soon and where renewal still happens by hand. If you want, we then set up automated renewal in your environment at a fixed price — you'll find the packages and how it works on the certificates page.

Go to the certificates page

Frequently asked questions

Why an annual license if the inventory is a one-off task?

Because in practice a cryptographic inventory isn't a one-time photo but a moving target: code, dependencies, TLS/SSH configurations and certificates change constantly, and the move to quantum-safe algorithms is a multi-year process. The real value is tracking progress over time — re-scanning after major releases, quarterly, or before an audit. The annual license also includes ongoing updates, so detection keeps pace with the standards (NIST/BSI) and with new algorithms, formats and system environments. Audits for BSI, NIS2 or GDPR (state of the art) require a current inventory anyway.

How do I show auditors that a report is unchanged?

Every scan seals its results: the app writes a verification file with checksums of the report and data, bound to your license. The included verify command proves offline that nothing has changed since the scan — any later modification shows up. The report also states the scan ID, the app version and the detection-rule state, so it stays traceable which rule set produced a finding. This is technical tamper evidence, not a certification.

Ready for your inventory?

Not sure which package fits? We'll show you a sample report and advise you. Enterprise is planned individually.

Get in touch

Lifetime steps per CA/Browser Forum ballot SC-081v3 (April 2025): max. 200 days since 15 Mar 2026, 100 days from 15 Mar 2027, 47 days from 15 Mar 2029; applies to publicly trusted TLS certificates. Germany's NIS2 implementation act in force since December 2025; Art. 21(2)(h) of the NIS2 Directive names policies and procedures regarding the use of cryptography and, where appropriate, encryption.