Consulting Product
Post-Quantum Discovery and Risk Assessment
Know exactly where your cryptography is exposed — and what to do about it, in weeks, not quarters.
What It Covers
Cryptographic Exposure Inventory
Every instance of RSA, ECC (ECDSA, ECDH), and related classical algorithms across the systems in scope, categorised by exposure level and migration priority.
Authentication and Signing
Where digital signatures underpin long-term verifiability: regulatory submissions, audit trails, transaction records, identity credentials.
Harvest-Now-Decrypt-Later Risk
Data and systems where current encryption could be retrospectively broken once quantum capability matures, classified by sensitivity and exposure window.
Long-Lived Keys and Certificates
The highest-priority migration targets: keys still in service when quantum decryption becomes feasible.
How It Works
A fixed, three-phase methodology — the same one whether your estate is ten systems or fifty.
Discover
Intake, systems inventory, and scope confirmation. We agree exactly what's in and out before work begins.
Assess
Every dependency identified, classified, and risk-rated. Each finding is mapped to relevant NIST and FIPS standards.
Prepare
Findings sequenced into a standards-aligned roadmap. You leave with a clear, prioritised path to post-quantum readiness.
What YouReceive
- Cryptographic Exposure Inventory
- Priority-Ranked Migration Roadmap
- HNDL Risk Classification
- Findings and Recommendations
- Executive Summary
Standards Alignment
Methodology and risk classification are aligned to NIST FIPS 203, 204, and 205, NIST IR 8547 deprecation timelines, and NSA CNSA 2.0. Every finding is traceable to a documented source.






