Unified Security Margin Calculator
USMC
Turn cryptographic evidence into a defensible, auditable assessment.
USMC brings together cryptographic strength, entropy quality, implementation evidence, protocol behaviour and architectural exposure within one structured assessment. It helps organisations identify weaknesses, compare configurations and prioritise post-quantum remediation.
Instant access · No minimum term · Cancel anytime
Est. security margin: +48.5 bits
Conservative lower bound vs 128-bit post-quantum threshold
Evidence Confidence
B
Assessment Coverage
77%
PQC Coverage
FULL
Critical Findings
0
Move cursor across the panel to shift the assurance posture · Illustrative preview
What USMC produces
One Assessment. Six Evidence Dimensions. Clear Remediation Priorities.
USMC evaluates six cryptographic and operational dimensions through the QRESB framework. It produces an overall assurance result, a dimension-by-dimension assessment, evidence confidence, assessment coverage and prioritised remediation guidance.
USMC reports two complementary outputs. The QRESB Assurance Index is a composite decision-support metric that summarises overall posture for boards, auditors and assurance stakeholders. Where the assessment mode and available evidence support it, the report also states an estimated security margin in bits: a conservative lower bound on attacker work-factor relative to the 128-bit post-quantum threshold, always identified as an estimate and accompanied by its assumptions and evidence confidence. Where evidence coverage is too low to assess, USMC returns Insufficient Evidence rather than a verdict.
Every assessment generates a timestamped, branded PDF report with overall assurance, the QRESB Assurance Index, evidence confidence, assessment coverage, regulatory relevance mapping, and per-dimension assessment. Use the report as supporting evidence for board discussions, remediation planning, supplier reviews and wider assurance or compliance documentation.
Cryptographic Assurance Report
USMC v1.0 · QRESB
Overall Assurance
MARGINAL
QRESB Assurance Index: B · Moderate Assurance
Estimated security margin: +11.2 bits (conservative lower bound)
Evidence confidence: B · Assessment coverage: 82%
Dimension Assessment
Critical findings are counted at evidence level and may occur within any dimension rating.
How strong is our cryptographic posture, and can we evidence it?
Every CISO faces versions of this question from boards, regulators, customers and insurers. Today the honest answer is usually qualitative. We follow best practices. We use strong encryption. We passed the audit.
These statements are not wrong. But they are hard to compare, hard to track over time and hard to defend under scrutiny. Cryptographic assurance is fragmented across silos: cryptographers select algorithms, implementation specialists test for leakage, network teams map exposure, compliance teams check frameworks. Each produces valuable evidence. None of it is combined into a structured, auditable assessment.
USMC does exactly that.
Six Cryptographic Dimensions, One Structured Assessment
Entropy Quality
Assesses the quality, validation and available min-entropy of the randomness used for keys, seeds and nonces.
Post-Quantum Cryptography
Assesses algorithm selection, parameter sets, implementation status, authentication coverage and migration maturity.
Protocol and Reconciliation Leakage
Assesses protocol information leakage, including QKD reconciliation where relevant.
Side-Channel Resistance
Assesses evidence concerning timing, power, electromagnetic, cache, fault and other implementation-level attacks.
Architecture and Network Exposure
Assesses reachability, segmentation, trust concentration, shared dependencies and potential attack paths.
Finite-Size Effects
Assesses statistical penalties caused by finite samples, blocks or observations where the protocol requires this analysis.
See USMC in Action
How strong is your cryptographic posture?
Select a scenario to assess cryptographic assurance, or compare two configurations side by side. The full tool produces timestamped, auditable PDF reports.
Illustrative Preview · Not the Production ToolOverall Assurance
AT RISK
PQC Coverage: NOT DEPLOYEDMargin not established (no post-quantum cryptography deployed)
Classical-only cryptography exposed to public networks. Without post-quantum migration, this configuration carries material exposure to harvest-now-decrypt-later threats.
Security Profile
Dimension Assessment
Key insight: PQC coverage is the critical gap. Without post-quantum cryptography, this system carries material exposure. Migration is no longer optional.
Includes radar chart · dimension breakdown · remediation guidance · regulatory relevance mapping
Remediation Planner
Toggle steps below to model how your cryptographic assurance would improve
Impact:
Current Assurance
AT RISK
QRESB Assurance Index: Abstention
Dimensions
Toggle remediations above
to model your projected assurance improvement
Critical findings are counted at evidence level and may occur within any dimension rating.
QRESB framework · Patent Pending · The production tool generates full PDF reports with audit trail
Scope Statement
USMC assesses cryptographic assurance and technical exposure. It does not independently calculate complete organisational cybersecurity risk, which also requires threat likelihood, business context and impact analysis.
Built For Security Leaders Where Cryptographic Posture Matters
USMC is designed for organisations where security posture must be measurable, defensible, and continuously verifiable.
How USMC Works
From parameters to an auditable assessment in minutes
01
Select your assessment mode
Choose from Enterprise PQC, QKD, Hybrid, Implementation Review, or Network Cryptographic Posture. The selected mode determines which dimensions are applicable.
02
Provide your evidence
Enter your cryptographic configuration across the applicable QRESB dimensions. Evidence-quality fields, evidence source, and reviewer details are captured for each input.
03
Review your assessment
USMC produces an overall assurance verdict, a QRESB Assurance Index, evidence confidence, assessment coverage, PQC coverage, and prioritised remediation guidance.
04
Export your report
Download a timestamped PDF with overall assurance, QRESB Assurance Index, evidence confidence, assessment coverage, regulatory relevance mapping, and per-dimension assessment. Use it as supporting evidence for board discussions, remediation planning, supplier reviews and wider assurance or compliance documentation.
See How USMC Works
Watch a narrated journey through the portal, from assessment mode to a finished report with compliance mapping.
Watch how USMC worksPricing for Every Stage of Cryptographic Maturity
Professional
or £25,000/year (save 17%)
For security consultants and mid-market teams
- Unlimited USMC assurance assessments
- PDF report downloads with full breakdown
- 90-day calculation history
- Email support (48-hour SLA)
- Single user account
Enterprise
For large organisations and security teams
- Everything in Professional
- Advanced calculator (25+ parameters)
- Network topology builder
- API access for CI/CD integration
- Batch assessments via CSV
- Unlimited users with SSO/SAML
- Custom report branding
- Compliance mapping (NIST, ISO, PCI, DORA)
- Priority support (24-hour SLA)
Defence & Critical Infrastructure
For government, defence, and regulated industries
- Everything in Enterprise
- Classified scenario templates
- On-premise deployment
- Air-gapped installation
- Custom integrations (SIEM, GRC)
- Dedicated account manager
- Audit support & on-site training
- Custom SLA (4-hour critical response)
Frequently Asked Questions
Assess Your Cryptographic Posture
Join organisations that have moved from qualitative assurance to evidence-backed assessment.
QRESB Framework · Patent Pending · physivitis.tech