Docs / TRUST & COMPLIANCE
TRUST & COMPLIANCE
Compliance
Written and maintained by Hendrik Schneider · Last reviewed · How we check this
Korthex automatically maps findings to recognized compliance frameworks, helping organizations demonstrate adherence to cryptographic security standards.
NIST FIPS 203/204/205
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) define the first NIST-standardized post-quantum cryptographic algorithms. Korthex evaluates your codebase against these standards: Each finding includes a compliance.nist field indicating which FIPS standards apply and the current compliance status.
| Standard | Algorithm | Korthex Check |
|---|---|---|
| FIPS 203 | ML-KEM (Kyber) | Identifies key encapsulation mechanisms that need PQC upgrade. |
| FIPS 204 | ML-DSA (Dilithium) | Flags digital signature schemes vulnerable to quantum attack. |
| FIPS 205 | SLH-DSA (SPHINCS+) | Detects hash-based signature opportunities. |
BSI IT-Grundschutz
For organizations operating under German/EU regulatory requirements, Korthex maps findings to BSI IT-Grundschutz controls: Findings include a compliance.bsi field with the relevant Grundschutz module references and requirement IDs.
| BSI Module | Description |
|---|---|
| CON.1 | Crypto concept - algorithm selection and key management. |
| APP.3.6 | DNS security and DNSSEC cryptographic configuration. |
| NET.3.3 | VPN - IPsec and TLS tunnel cryptographic requirements. |
| OPS.1.2.4 | Patch and change management for crypto libraries. |
Severity Model
Korthex uses a five-level severity model: Severity levels are automatically adjusted by the Context Engine. Taint analysis may promote or demote findings based on evidence about key sources and code context.
| Severity | Description | Examples |
|---|---|---|
| CRITICAL | Immediate security risk. Exploitable without quantum computers. | Hardcoded private keys, MD5 for passwords, DES in production |
| HIGH | Significant weakness. Vulnerable to near-term attacks or quantum. | RSA-2048 for long-term secrets, SHA-1 certificates, ECB mode |
| MEDIUM | Suboptimal cryptography that should be upgraded. | AES-128 (vs 256), PKCS#1 v1.5 padding, 2048-bit DH |
| LOW | Minor improvement opportunity. | Non-PQC algorithms in non-sensitive contexts |
| INFO | Informational finding for inventory purposes. | Detected crypto usage with no identified weakness |