Skip to content

Assessment Overview

Use Assessment to understand the loaded scan and choose which operations to review next. The overview draws on the available function, operation-group, and assessment reports. Load the complete scan folder to make the related detail available.

The five dimensions and their result meanings are explained in Assessment Dimensions. This page explains how to use the overview and interpret its counts.

Summary cards

The current overview separates operation groups, files scanned, crypto-relevant files, unique CWEs, and the five assessment dimensions. These measures have different units.

Summary How to read it
Operation groups Related cryptographic operations in the loaded report.
Files scanned Source files included in the scan, when supplied by the report.
Crypto-relevant files Files represented in the detected cryptographic inventory.
Unique CWEs Distinct weakness identifiers, not the number of affected operations.
Quantum exposure Groups reported as quantum broken or quantum weakened.
Crypto weaknesses Groups with at least one reported CWE.
FIPS source Groups with a potential FIPS issue or a source-evidence gap.
Crypto agility Groups with reported replaceability-review indicators.
Risk signals Reported signal occurrences, including context and anti-pattern observations.

A group can contribute to several dimensions. Signal occurrences, affected groups, distinct CWEs, and files cannot be added into a single vulnerability total. A zero attention count also does not rule out unknown, unassessed, or context-dependent results.

Distributions

The overview organizes the available breakdowns into three sections:

Section What you can explore
Inventory Cryptographic operations and algorithms.
Assessments Quantum categories, CWE identifiers, FIPS results, agility indicators, and risk-signal observations.
Actions Remediation themes, discovery follow-ups, and assessment-review requirements.

The dimension pages define the categories shown in these breakdowns. Rows can overlap: one group may have several algorithms, CWEs, signals, or actions. File counts describe files associated with a category, not additional findings.

Open the evidence behind a count

  1. Select a category or its Groups count to open the matching operation groups.
  2. Select a Files count to review the same selection organized by file.
  3. Check the active filters. The selected category becomes a visible filter you can change or clear.
  4. Open a group and inspect its source sequence, parameters, assessment, and reasoning.
  5. Clear the relevant filters to return to a broader review.

These links work across the standalone viewer, VS Code, and Eclipse. Filters use the same review fields as the ordinary filter controls. Multiple selected values within a field are alternatives; selections across different fields narrow the result together.

Experimental Migration Review

The standalone viewer also offers Experimental Migration Review when the loaded assessment report supplies migration-analysis information. It presents scanner-provided summaries and review guidance. It does not currently provide a priority-operation table, interactive filters, or a selection export, and this view is not available in the IDE integrations.

Use it as input to a planning discussion. Business priorities, data lifetime, compatibility, implementation effort, and evidence of a completed migration remain part of your team's review. It is not an agility score or deployment-readiness certification.

Readiness in the assessment file

The crypto-finding-assessment.json file can also contain a repository readiness summary. This is a separate planning summary, not another assessment dimension.

Readiness value Meaning
CRITICAL_REVIEW_REQUIRED Critical findings require review.
HIGH_RISK_REVIEW_REQUIRED High-risk findings or group assessments require review.
MANUAL_ASSESSMENT_REQUIRED Available results call for manual assessment when the earlier risk categories do not apply.
NO_HIGH_RISK_FINDINGS_REPORTED The summary did not identify the preceding risk or manual-assessment conditions. This is not a security guarantee.

Older or incomplete report sets

Available sections depend on the reports loaded and their format version. Missing scan counts, dimension details, or migration-analysis information are not equivalent to zero findings. Rescan with the current scanner to obtain newly available information; loading an older report does not reassess its source.

Keep reports from the same scan together. See Report File Reference for file purposes and Interpret Results for the detailed review process.