Statically inventories every cryptographic asset in a codebase, grades each for quantum and classical weakness, and emits a prioritized migration roadmap to the NIST post-quantum standards.
Lattice is a crypto-agility and post-quantum-readiness scanner. It statically analyzes a codebase, produces a Cryptographic Bill of Materials (CBOM), grades every cryptographic usage for both quantum vulnerability and classical weakness, and emits a prioritized migration roadmap toward the NIST post-quantum standards. It is defensive and fully offline: it reads files locally, writes reports locally, makes no network calls, never attempts to break cryptography, and never writes key material into a report. Released as an installable product (v0.4.0, src-layout) with a MkDocs docs site, a reproducible benchmarks harness, CodeQL CI, and a citable Zenodo DOI (CITATION.cff).
The post-quantum threat in three sentences: adversaries can record encrypted traffic today and decrypt it once a cryptographically relevant quantum computer exists — 'harvest now, decrypt later'. Shor's algorithm breaks RSA, Diffie-Hellman, and all elliptic-curve cryptography outright, while Grover's algorithm halves the effective strength of symmetric keys and hashes. NIST has standardized the replacements — ML-KEM (FIPS 203) for key establishment and ML-DSA (FIPS 204) / SLH-DSA (FIPS 205) for signatures — and migrating to them starts with knowing what cryptography you actually have. Lattice builds that inventory, grades it, and turns it into an actionable, CI-gate-able roadmap.
Python 3.11+, Standard library only (0 runtime deps), AST analysis, CycloneDX-style CBOM, SARIF 2.1.0, Bandit (SAST), pip-audit, NIST FIPS 203/204/205, CNSA 2.0