Post-quantum
What a cryptographic bill of materials actually requires
A CBOM is not a scan result. It is an inventory with provenance, ownership, and a lifetime attached to every entry.
7 min read
Practice 02
An honest picture of where you stand, mapped to a framework your board and your customers already recognise.
Focused review
2 weeks
Full programme assessment
4 to 8 weeks
Certification readiness
6 to 10 weeks
Advisory retainer
Monthly
A scanner tells you what is broken on the day it ran. It does not tell you whether the programme that produced the breakage will produce it again next quarter.
Boards ask for a position against a recognised framework. Engineering asks for a backlog it can actually schedule. Most assessments serve one audience and leave the other unconvinced.
The gap is usually evidence discipline. Findings without a named artifact behind them get argued away, and nothing changes.
What we do
Measured against NIST CSF 2.0, ISO 27001, or CIS Controls v8, with the evidence recorded behind each score.
SDLC gates, SAST, SCA and secrets coverage, threat modelling practice, and dependency and supply-chain posture.
Identity, network, data, and workload configuration across the accounts that matter.
Human and non-human identities, service credentials, privilege paths, and joiner-mover-leaver reality against policy.
How vendors are assessed, what evidence is kept, and what happens when a vendor fails.
A facilitated tabletop exercise, with findings written into an updated runbook.
Gap-to-readiness for ISO 27001 or SOC 2, sequenced against your target audit date.
Deliverables
You keep all of it, including the method behind it, so the work can be repeated without us.
Engagement shapes
Durations are indicative and depend on estate size. Scope and price are fixed in writing before the engagement starts.
| Shape | Duration | What you get |
|---|---|---|
| Focused review | 2 weeks | One domain assessed in depth |
| Full programme assessment | 4 to 8 weeks | Scorecard, risk register, backlog, roadmap, and board summary |
| Certification readiness | 6 to 10 weeks | Gap analysis, control evidence plan, and an audit-ready sequence |
| Advisory retainer | Monthly | Standing security counsel and roadmap stewardship |
Related insights
Post-quantum
A CBOM is not a scan result. It is an inventory with provenance, ownership, and a lifetime attached to every entry.
7 min read
Next step
Thirty minutes on cyber security assessment. We will tell you whether we are the right firm for the problem, and who to talk to if we are not.