Quantum computers threaten every asymmetric key in your stack today. Bulwark gives security teams a structured 39-control assessment against CNSA 2.0 or the NIST PQC standards (FIPS 203/204/205) โ with live scoring, gap tracking, and board-ready PDF reports.
Free to start ยท Work email required ยท No credit card needed
Framework coverage
The Threat
Adversaries are collecting encrypted traffic today to decrypt once a cryptographically-relevant quantum computer exists. Long-lived secrets โ financial records, health data, classified communications โ are already at risk.
The NSA's CNSA 2.0 suite and NIST's PQC standards (FIPS 203/204/205) both mandate migration to post-quantum algorithms. Financial institutions and government contractors must demonstrate readiness โ but most have no structured way to measure where they stand.
Assessment Framework
Every control maps to a specific CNSA 2.0 or NIST PQC requirement โ with clear evidence criteria, remediation guidance, and maturity targets.
Product Features
From initial gap discovery to board-level reporting, Bulwark handles the full assessment lifecycle.
Scores update in real-time as assessors complete controls. See overall readiness band, per-domain averages, open gaps by priority, and completion percentage at a glance.
Each control shows the framework target (CNSA 2.0 or NIST PQC), evidence requirements, and editable fields for maturity score, notes, gap description, remediation plan, owner, and target date. Auto-saves on every change.
Generate a branded, regulator-ready report with your org name, readiness band, domain breakdown, and full gaps & remediation register sorted by priority. Suitable for board and auditor review.
Score each control from Initial (0) to Optimized (5). Domain and overall scores roll up automatically. Readiness bands give clear program status: Initial โ Aware โ Developing โ Managed โ Optimized.
Admin, Assessor, and Viewer roles. Admins manage members and advance assessment status. Assessors fill out controls. Viewers and executives get read-only access to the dashboard and reports.
Run multiple assessment cycles to track progress over time. Each assessment captures a point-in-time snapshot so you can demonstrate improvement to regulators and leadership.
How It Works
No professional services required. Your security team can complete a full CNSA 2.0 or NIST PQC assessment in a single working day.
Sign up with your work email, verify your identity, and create your organization. Invite assessors and reviewers โ each with the right access level.
Choose CNSA 2.0 or NIST PQC, then work through controls across Transit, At Rest, and Governance. Score each control, add notes, document gaps, assign remediation owners, and set target dates.
Generate a PDF with your overall readiness band, domain scores, and full gap register. Share with your board, auditors, or regulators in one click.
Who It's For
Purpose-built for teams that need to demonstrate CNSA 2.0 or NIST PQC compliance โ not a generic security checklist tool.
Banks, credit unions, and payment processors preparing for post-quantum mandates. Demonstrate readiness to regulators and internal risk committees with structured evidence.
Defense contractors and federal system integrators building or operating national security systems subject to CNSA 2.0 transition requirements.
Get a clear, quantified picture of your organization's cryptographic exposure. Prioritize remediation, allocate resources, and report program progress to leadership.
Work through detailed technical controls with evidence requirements, current-state notes, and remediation planning in a structured collaborative environment.
Get Started Today
Start your free assessment with your organization email. No credit card, no professional services โ just your security team and 39 controls.
Work email required ยท Personal email providers not accepted
More From Cloud Strategy
Tools for reliability, privacy, and security โ built by Cloud Strategy, Inc.
AES-256 encrypted vault for photos, videos, messages, and notes โ hidden behind a fully functional calculator on your iPhone.
Multi-tenant SRE observability โ SLOs & error budgets, incidents, DORA metrics, synthetics, infrastructure, cost, and security KPIs in one dashboard.