Requirement 12.3.3 asks you to document and review, at least once every 12 months, the cryptographic cipher suites and protocols you actually use. VPQ Audit reads them from the systems themselves and exports the inventory as a CSV your assessor can open, one row per protocol or algorithm and place.
All cryptographic cipher suites and protocols in use, including their purpose and where they are used.
Active tracking of industry guidance on whether each cipher suite and protocol is still acceptable.
A documented plan for responding when an algorithm you rely on becomes weak or deprecated.
12.3.3 does not require post-quantum cryptography. It became mandatory on 31 March 2025 and asks you to know what you run and to have a plan. Post-quantum timelines are simply the largest "anticipated change" now on the calendar. Source: PCI SSC document library.
Each row names the place (host and port, and the position in the certificate chain), the component (key exchange, bulk cipher, handshake hash, certificate key, certificate signature) and the protocol or algorithm observed, for example TLS 1.3 with X25519MLKEM768, AES-128-GCM or an ECDSA P-256 leaf certificate.
Purpose cannot be observed on the wire, so the column is left empty for your team to complete. We would rather leave it blank than guess.
Every row carries a status (acceptable, weak, broken, or quantum-vulnerable and in the migration plan), a risk level and a note tied to NIST IR 8547 (draft) and CNSA 2.0, so the "continued viability" review has a dated reference.
A planned-action column names the replacement for each algorithm. The strategy itself is your decision; the column gives it a concrete first draft.
Each export is dated. Comparing this year's export with last year's, or the before/after report comparing two assessments, is the evidence that the review happened and what changed.
Where used · Component · Protocol / algorithm ·
Status · Risk level · Planned action · Note ·
Purpose (to be completed by the entity) · Assessed on
Sample: the export for our own three sites (4 October 2026, VPQ Audit 1.0.2), published as it came out.
Spreadsheet formulas in scanned banners or certificate names are neutralised before export, so a hostile certificate cannot run a formula in your assessor's spreadsheet.
The CSV export is part of the self-hosted product (PQC Readiness Audit, Team and Business), which reads TLS, SSH and VPN configuration, certificates and source code on your own network. The Free Check reads only the public TLS handshake of up to 5 hostnames and grades them A–F; it is a quick look, not a 12.3.3 inventory.
It records the protocol and cipher suite each endpoint negotiates with the scanner. It does not yet enumerate every suite and protocol version a server would accept, and it does not yet flag TLS 1.0 or 1.1. Until the next release adds both, check legacy protocol versions separately; your assessor will.
Whether an inventory generated this way is sufficient evidence is your QSA's call, not ours. Show them the column list above before you rely on it.
Up to 5 public hostnames you own or are authorised to assess, graded A–F on key exchange, negotiated protocol and certificate chain.
A 30-day licence installed on your own network, the 12.3.3 export among the outputs, and one review of the resulting report by an ATK analyst. Prices and the founding-customer offer are on the main page.
If you run 12.3.3 or readiness work for clients and want the inventory under your own report, see For consultancies or write to support@atkvn.com.