PQC Migration

Know exactly where quantum breaks your cryptography.

A fixed-scope, fixed-price assessment. In about three weeks you get a complete map of your cryptographic exposure, ranked by real-world risk, and a phased, costed roadmap to become quantum-safe — written plainly enough for the board and precisely enough for the auditor.

The problem

Harvest now, decrypt later.

Quantum computers will break RSA and elliptic-curve cryptography — the public-key algorithms behind TLS, VPNs, signing and key exchange. The threat isn't only future: an adversary can record your encrypted traffic and stored data today and decrypt it when the hardware matures. Every secret with a multi-year confidentiality requirement is already exposed.

NIST published the standardized replacements in August 2024 (ML-KEM, ML-DSA, SLH-DSA), and government mandate timelines are landing in the early 2030s. Migration is a multi-year program, and it can't start until you know where your cryptography actually lives.


The method

A repeatable five-step assessment.

  1. 1

    Discover Cryptographic inventory

    Interviews, config, certificate and PKI review, targeted scans and document review to find every place crypto is used — TLS, VPNs, code signing, HSMs, databases, APIs, embedded and third-party. You can't migrate what you can't see.

  2. 2

    Expose Harvest-now-decrypt-later risk

    Overlay data confidentiality lifetimes. Which secrets outlive the quantum horizon and are therefore already at risk from capture-today attacks? This is where urgency becomes concrete.

  3. 3

    Map Dependencies & crypto-agility

    Trace what each system depends on — vendors, libraries, protocols, hardware — and score how easily each can swap algorithms. Crypto-agility is the real migration bottleneck.

  4. 4

    Prioritize Gap vs standards & mandate

    Measure the gap against NIST’s standardized PQC (ML-KEM / ML-DSA / SLH-DSA — FIPS 203/204/205) and your own mandate, then rank remediation by risk against effort.

  5. 5

    Roadmap Phased, costed plan

    A sequenced plan — hybrid-crypto first, quick wins, agility upgrades, then full PQC — with dependencies, indicative effort and cost, and a board-ready executive summary, delivered in a live readout.


What you get

Six things you walk away with.

Cryptographic inventory register

The asset itself — a living record of where crypto lives. Doubles as ISO 27001 evidence.

Quantum-risk heat map

Every system ranked by harvest-now exposure and migration difficulty. The one-glance board slide.

Gap analysis

Current state vs NIST FIPS 203/204/205 and your mandate, with named gaps.

Phased migration roadmap

Sequenced plan with quick wins, dependencies, timeline and indicative cost.

Executive summary

One or two pages a CISO takes straight to the board and the auditor.

Live readout

A 90-minute presentation of findings and next steps with your leadership team.


Engagements

Start small, or go comprehensive.

Snapshot

Readiness Snapshot

1–2 weeks · one domain

A focused first look: snapshot report and risk heat map for a single domain or business unit. The low-risk way to start.

Most chosen Assessment

Migration Readiness Assessment

3–5 weeks · full estate

The full inventory, risk ranking, dependency map and board-ready phased roadmap. Scales with organization size.

Engagement

Migration Engagement

custom · scoped

Execution of the migration itself — priced directly from the roadmap the assessment delivers.

Fixed scope and fixed price agreed up front. Talk to us about sizing for your estate.

Not sure where quantum leaves you exposed?

Book a PQC Migration Readiness Assessment — fixed scope, fixed price, a board-ready roadmap in about three weeks.

Book a PQC Assessment