Skip to main content
YavoraInnovations
Open menu

Practice 01

Post-Quantum Cryptography Migration

Know exactly where your cryptography is exposed, then retire it on a schedule you can defend to a regulator and a board.

Engagement shapes

  • Rapid exposure review

    2 weeks

  • Full assessment

    6 to 8 weeks

  • Migration advisory

    Retainer, quarterly cadence

  • Pilot delivery

    8 to 12 weeks

Who this is for

  • CISOs and heads of PKI in regulated sectors
  • Product companies whose data stays sensitive for a decade or more
  • Teams answering cryptographic inventory questions in customer security reviews

The problem

Most organisations cannot answer a basic question: where are RSA and ECC actually used, in source code, in configuration, in certificates, in appliances, and in third-party services.

Without that answer a migration plan is guesswork. Budgets get set against an inventory nobody has built, and the first real discovery exercise invalidates the plan.

Meanwhile encrypted traffic captured today can be decrypted once a cryptographically relevant quantum computer exists. For long-lived data the clock started before the plan did.

Exposure model

Mosca's inequality, drawn to scale.

X is how long your data stays sensitive. Y is how long migration takes. Z is how long until a cryptographically relevant quantum computer exists. Where X plus Y runs past Z, data created today is already exposed.

Illustrative values. Z is an estimate with a wide range, and we present it as a range with the source named rather than as a date. The ordering of your systems by X plus Y is the roadmap.

What we do

The workstreams in an engagement

01

Cryptographic discovery

Source code, configuration, certificates, network endpoints, key stores, hardware security modules, and third-party services, consolidated into one inventory.

02

Harvest-now-decrypt-later exposure

Mosca's inequality applied against real data-sensitivity lifetimes, so exposure is ranked by the data that actually stays sensitive.

03

Crypto-agility review

How fast can you change an algorithm today. We measure the real answer per system and name the specific blockers.

04

Standards mapping

Target algorithms mapped to the NIST selections, ML-KEM in FIPS 203, ML-DSA in FIPS 204, and SLH-DSA in FIPS 205, plus hybrid TLS transition patterns.

05

Third-party and supply-chain readiness

A vendor questionnaire, a tracked response register, and an escalation path for the vendors that cannot answer.

06

Sequencing and governance

A migration roadmap ordered by exposure and effort, with a board reporting cadence that survives a change of sponsor.

07

Optional pilot

One path taken end to end: hybrid TLS, code signing, PKI issuance, or a data-at-rest store, with a runbook you can repeat.

Deliverables

What lands on your desk

You keep all of it, including the method behind it, so the work can be repeated without us.

  • Cryptographic Bill of Materials (CBOM)
  • Exposure register with harvest-now-decrypt-later windows per data class
  • Crypto-agility maturity rating with the specific blockers named
  • Prioritised migration roadmap sequenced by exposure and effort
  • Target-state architecture and algorithm policy
  • Vendor readiness pack and tracked response register
  • Board and regulator briefing deck

Standards we work against

  • NIST FIPS 203, 204, and 205
  • NIST SP 1800-38
  • NSA CNSA 2.0 timelines
  • NIST CSF 2.0
  • ISO 27001 Annex A cryptography controls

What we do not do

  • We do not sell you a cryptography product.
  • We do not claim a quantum computer breaks RSA on a date we cannot evidence.
  • We do not run a migration you have no capacity to operate afterwards.

Engagement shapes

Three sizes, not one package

Durations are indicative and depend on estate size. Scope and price are fixed in writing before the engagement starts.

ShapeDurationWhat you get
Rapid exposure review2 weeksTop-20 exposure list, HNDL view, and a roadmap outline
Full assessment6 to 8 weeksComplete CBOM, exposure register, roadmap, target architecture, and board pack
Migration advisoryRetainer, quarterly cadenceGovernance, sequencing, vendor pressure, and progress reporting
Pilot delivery8 to 12 weeksOne migrated path in production with a repeatable runbook

Related insights

Our thinking on this

Next step

Start with a briefing, not a proposal.

Thirty minutes on pqc migration. We will tell you whether we are the right firm for the problem, and who to talk to if we are not.