CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Roadmap

Live, partial, roadmap — labeled, not blurred.

CyberDragon Core is available for Proof of Value and pilot deployments. Anything not shipping yet is marked so buyers can plan around it.

In development

Next on the build list.

Threat Hunt workspace

roadmap

Guided hypothesis hunting over the unified Enterprise/OT event store.

UEBA

roadmap

Behavior analytics for operator and service accounts.

AI Copilot chat

roadmap

Analyst-facing assistant grounded in tenant evidence.

EU CRA bridge mapping

roadmap

Cyber Resilience Act control bridge on top of existing framework packs.

Edge Analyst UI routes

roadmap

Until then, use the local Edge operations dashboard.

Unified SOC dashboard

partial

Live and shipping; visual and workflow hardening in progress.

Attack-path graph detail

partial

Neo4j graph is live; incident-detail depth expanding.

MSSP portal

partial

Cross-tenant operations available to partner program members.

ML-KEM key exchange

roadmap

Post-quantum key encapsulation (NIST FIPS 203) alongside the existing ML-DSA-65 + Ed25519 hybrid signing.

Executive reporting depth

partial

Board PDFs and CISO digests ship; template and scheduling depth still expanding.

Marketplace catalog growth

partial

Detection pack and partner integration catalog live; catalog breadth still growing.

Risk engine scenario library

partial

FAIR-style scoring is live; the pre-built scenario library is still expanding past the initial set.

PQC

Already live — still hardening inventory views

  • Hybrid identity is not a future epic.
  • Readiness UI will keep gaining crypto-inventory depth.
  • We label partial vs live on the platform page.
Quantum Readiness
Maturity table

Feature status at a glance.

FeatureStatusWhere you see it
Incident QueueliveShow prominently
Login / JWT / MFAliveShow prominently
Evidence verify/exportliveShow prominently
Tenant create/suspendliveAdmin section only
Unified SOC DashboardpartialEnhanced / hardening
Incident Detail / Attack GraphpartialReal screenshots when available
Risk / Compliance DashboardspartialFramework cards
Threat Hunt / UEBAroadmapComing soon
AI Copilot ChatroadmapComing soon
MSSP PortalpartialPartner page
Edge Analyst UI routesroadmapUse local Edge Dashboard
Full production-grade certification is pending external penetration test.
Shipping today

Fifteen Core modules with their real status.

01 · Sovereign Identity (PQC)

live

ML-DSA-65 + Ed25519 hybrid JWTs; MFA; API keys; Vault-backed signing keys.

02 · Kill-Chain Detection

live

Cascading W15 (15 min) / W60 (1 hr) / W24 (24 hr) correlation windows.

03 · Enterprise→OT Pivot Detection

live

Explicit signaling when enterprise compromise precedes OT-side anomalies.

04 · Threat Intelligence Fusion

live

OTX, Abuse.ch, ThreatFox, MITRE TAXII, GreyNoise — in-flight enrichment.

05 · Vulnerability Intelligence (VSI)

live

Mirrored NVD/CVE/CPE, CISA ICS-KEV, and OSV for local, offline-safe query.

06 · Risk Engine

partial

Asset risk plus FAIR-style scenario scoring, 0–100.

07 · Compliance Auto-Mapper

partial

Events mapped to controls automatically — roughly 7 controls per network event.

08 · Framework Packs

partial

IEC 62443-3-3, NERC CIP, NIST CSF 2.0, ISO 27001:2022, SOC 2.

09 · SOAR / Response

live

Temporal-orchestrated playbooks with human approval workflows.

10 · OT Safety Guardrails

live

OPA policy can deny actions even after human approval on OT-affecting classes.

11 · Evidence Vault

live

Hash-chained, Ed25519-signed, tamper-evident audit trail with ZIP export.

12 · Attack-Path Graph

partial

Neo4j-backed cyber-physical knowledge graph.

13 · Executive Reporting

partial

Board PDFs, CISO monthly digests, auditor packets.

14 · Marketplace

partial

Detection packs and partner integration catalog.

15 · MSSP Portal

partial

Cross-tenant operations, client onboarding, portfolio views.

Already delivered

How the platform got here.

01

Platform foundation

Kafka-backed Core, PostgreSQL RLS multi-tenancy, and the first Modbus/DNP3 Edge collector.

02

Post-quantum identity

Hybrid ML-DSA-65 + Ed25519 session JWTs with Vault-backed signing material went live.

03

Kill-chain correlation

Cascading W15 / W60 / W24 windows plus explicit Enterprise→OT pivot signalling.

04

Evidence vault

Hash-chained, signed audit trail with auditor ZIP export and verified 66-entry lab chain.

05

Lab validation

22.4-hour baseline: 41,959 events, 6/6 attack scenarios detected, 0 false incidents, 8.0–20.5s MTTD.

06

Threat Atlas

Public IoT/ICS threat, malware, and ICS advisory board built on live CISA and ransomware disclosure feeds.

Post-quantum outlook

Where post-quantum cryptography goes over the next twenty years.

Industry outlook — not a CyberDragon delivery date. Public roadmaps from NIST, NSA CNSA 2.0, and ENISA are the basis; CyberDragon's own hybrid ML-DSA-65 + Ed25519 signing is live today, not part of this forward-looking timeline.

01

Now – 2026

Hybrid classical + post-quantum signing (ML-DSA-65 + Ed25519) is live in CyberDragon on every session JWT — crypto agility in production, not a slide.

02

2026 – 2028

NIST FIPS 203/204/205 (ML-KEM, ML-DSA, SLH-DSA) move from published standard to mandatory in US federal and adjacent regulated procurement; crypto-agility inventories become a standard audit line item.

03

2028 – 2030

"Harvest now, decrypt later" risk peaks for data with long confidentiality windows — utilities, healthcare, and defense-adjacent estates — as public quantum-hardware roadmaps mature; migration shifts from optional to contractual.

04

2030 – 2033

Post-quantum key exchange (ML-KEM) is expected at most TLS termination points for regulated industrial and financial estates; classical-only stacks risk procurement exclusion in several jurisdictions.

05

2033 – 2036

A cryptographically relevant quantum computer is treated as a live planning scenario in national critical-infrastructure programs (per public NIST, NSA CNSA 2.0, and ENISA roadmaps); crypto-agility — not a single algorithm choice — is the deciding factor for survivors.

06

2036 – 2045

Legacy classical-only systems still in the field become the dominant quantum-risk surface; retrofit cost on old estates, not new deployments, drives most of the remaining migration spend.

Forward-looking industry outlook, not a guarantee or a CyberDragon product commitment.
FAQ

Frequently asked questions.

Can we get early access to roadmap features?
Pilot and MSSP partners can request early access. Roadmap timing is not contractual unless written into your agreement.
What does partial mean?
The capability is real and running, with hardening or depth work still in progress. It is safe to evaluate, and we will show you exactly where the edges are.
Is the 20-year PQC outlook a CyberDragon commitment?
No. It is industry context drawn from public NIST, NSA CNSA 2.0, and ENISA roadmaps. CyberDragon's own hybrid ML-DSA-65 + Ed25519 signing is live today, independent of that outside timeline.

Start your 7-day free trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.