VPQ Audit · PCI DSS v4.0.1 Requirement 12.3.3

The cipher and protocol inventory, read off the wire.

Requirement 12.3.3 asks you to document and review, at least once every 12 months, the cryptographic cipher suites and protocols you actually use. VPQ Audit reads them from the systems themselves and exports the inventory as a CSV your assessor can open, one row per protocol or algorithm and place.


What 12.3.3 asks

Three things,
every year.

An up-to-date inventory

All cryptographic cipher suites and protocols in use, including their purpose and where they are used.

Monitoring of their continued viability

Active tracking of industry guidance on whether each cipher suite and protocol is still acceptable.

A strategy for anticipated change

A documented plan for responding when an algorithm you rely on becomes weak or deprecated.

What it does not ask

12.3.3 does not require post-quantum cryptography. It became mandatory on 31 March 2025 and asks you to know what you run and to have a plan. Post-quantum timelines are simply the largest "anticipated change" now on the calendar. Source: PCI SSC document library.


How VPQ Audit maps to it

What the tool fills in,
and what stays yours.

Inventory and where used: what was negotiated

Each row names the place (host and port, and the position in the certificate chain), the component (key exchange, bulk cipher, handshake hash, certificate key, certificate signature) and the protocol or algorithm observed, for example TLS 1.3 with X25519MLKEM768, AES-128-GCM or an ECDSA P-256 leaf certificate.

Purpose: left for you

Purpose cannot be observed on the wire, so the column is left empty for your team to complete. We would rather leave it blank than guess.

Viability: rated

Every row carries a status (acceptable, weak, broken, or quantum-vulnerable and in the migration plan), a risk level and a note tied to NIST IR 8547 (draft) and CNSA 2.0, so the "continued viability" review has a dated reference.

Strategy: a starting point

A planned-action column names the replacement for each algorithm. The strategy itself is your decision; the column gives it a concrete first draft.

The yearly review: two dated exports

Each export is dated. Comparing this year's export with last year's, or the before/after report comparing two assessments, is the evidence that the review happened and what changed.


The export

Nine columns,
nothing hidden.

Where used · Component · Protocol / algorithm · Status · Risk level · Planned action · Note · Purpose (to be completed by the entity) · Assessed on

Sample: the export for our own three sites (4 October 2026, VPQ Audit 1.0.2), published as it came out.

Spreadsheet formulas in scanned banners or certificate names are neutralised before export, so a hostile certificate cannot run a formula in your assessor's spreadsheet.

Where the export comes from

The CSV export is part of the self-hosted product (PQC Readiness Audit, Team and Business), which reads TLS, SSH and VPN configuration, certificates and source code on your own network. The Free Check reads only the public TLS handshake of up to 5 hostnames and grades them A–F; it is a quick look, not a 12.3.3 inventory.

What the export does not list yet

It records the protocol and cipher suite each endpoint negotiates with the scanner. It does not yet enumerate every suite and protocol version a server would accept, and it does not yet flag TLS 1.0 or 1.1. Until the next release adds both, check legacy protocol versions separately; your assessor will.

Your assessor decides

Whether an inventory generated this way is sufficient evidence is your QSA's call, not ours. Show them the column list above before you rely on it.


Start

One handshake first,
then the estate.

Free Check · free

Up to 5 public hostnames you own or are authorised to assess, graded A–F on key exchange, negotiated protocol and certificate chain.

Free check of your public hosts →

PQC Readiness Audit · USD 4,500, tax included

A 30-day licence installed on your own network, the 12.3.3 export among the outputs, and one review of the resulting report by an ATK analyst. Prices and the founding-customer offer are on the main page.

Assessors and consultancies

If you run 12.3.3 or readiness work for clients and want the inventory under your own report, see For consultancies or write to support@atkvn.com.