"Not assessable" is a state of its own
The assessment knows four levels, not three. Missing particulars are not counted as compliant and not blended into an amber. An algorithm with no known key length is not a green entry.
Metadata about cryptography, never key material
Almost nobody can currently answer which cryptographic algorithms an organisation uses where. Four sources demand that answer: BSI C5 (CRY-01), the Cyber Resilience Act (Annex I Part I (2)(e)), ISO 27001 A.8.24 and DORA Regulation (EU) 2024/1774, Articles 6 and 7. The trigger is therefore not the year 2030 but a catalogue being audited today. The module keeps this register with algorithm, parameter set, length, mode of operation, purpose, location, key custodian and origin, and it keeps metadata only: key material is never held here.
The assessment knows four levels, not three. Missing particulars are not counted as compliant and not blended into an amber. An algorithm with no known key length is not a green entry.
The module holds metadata about cryptography and never keys themselves. That is not merely a promise: a guard test fails as soon as a column or a writable field sounds like key material.
Which algorithms are being phased out or are impermissible follows BSI TR-02102 and CNSA 2.0. Every entry therefore carries not just a colour but a reference.
An answer to the question that comes up in audits and that no organisation currently has in a list: which algorithms do we use where.
Schedule a no-obligation demo – we will show you the module with your own use cases.