← Solutions

Post-quantum cryptography readiness

Inventory your cryptography and plan a staged move to the NIST post-quantum standards, prioritised by how long your data must stay secret.

Typical timing
6–10 weeks
Engagement
Fixed scope
Delivery framework
User researchDiscoveryAlphaBetaLive

Prepare for quantum computers able to break today’s public-key cryptography. Data harvested now can be decrypted later, and the NCSC has set out a migration timeline running to 2035. We find where cryptography is used, rank systems by exposure and build a crypto-agile migration roadmap to the NIST standards.

  • You hold data that must remain confidential for ten years or more
  • Customers or regulators are asking about quantum readiness
  • No inventory of where and how encryption is used
How it runs

Activities, step by step

The plan follows our delivery framework. Steps that do not apply to this kind of work are left out rather than padded.

  1. 02 · Discovery3–4 weeks

    Cryptographic inventory

    • Discovery of algorithms, certificates, keys and libraries
    • Supplier and product roadmaps collected
    • Data classified by required confidentiality lifetime
  2. 03 · Alpha2–4 weeks

    Prioritise and pilot

    • Systems ranked by harvest-now-decrypt-later exposure
    • Hybrid post-quantum key exchange piloted on a priority system
    • Crypto-agility gaps identified
  3. 04 · Beta1–2 weeks

    Roadmap

    • Migration roadmap aligned to NCSC timelines
    • Procurement requirements for suppliers
    • Board briefing

Deliverables

What you keep at the end.

  • Cryptographic bill of materials
  • Risk-ranked system register
  • Pilot results
  • Post-quantum migration roadmap
  • Supplier requirements

Outcomes

What it is built to change.

  • A clear, early start on a multi-year migration
  • Long-lived sensitive data protected first
  • Crypto-agility that makes future changes cheaper