Post-quantum
What a cryptographic bill of materials actually requires
A CBOM is not a scan result. It is an inventory with provenance, ownership, and a lifetime attached to every entry.
7 min read
Practice 01
Know exactly where your cryptography is exposed, then retire it on a schedule you can defend to a regulator and a board.
Rapid exposure review
2 weeks
Full assessment
6 to 8 weeks
Migration advisory
Retainer, quarterly cadence
Pilot delivery
8 to 12 weeks
Most organisations cannot answer a basic question: where are RSA and ECC actually used, in source code, in configuration, in certificates, in appliances, and in third-party services.
Without that answer a migration plan is guesswork. Budgets get set against an inventory nobody has built, and the first real discovery exercise invalidates the plan.
Meanwhile encrypted traffic captured today can be decrypted once a cryptographically relevant quantum computer exists. For long-lived data the clock started before the plan did.
Exposure model
X is how long your data stays sensitive. Y is how long migration takes. Z is how long until a cryptographically relevant quantum computer exists. Where X plus Y runs past Z, data created today is already exposed.
Illustrative values. Z is an estimate with a wide range, and we present it as a range with the source named rather than as a date. The ordering of your systems by X plus Y is the roadmap.
What we do
Source code, configuration, certificates, network endpoints, key stores, hardware security modules, and third-party services, consolidated into one inventory.
Mosca's inequality applied against real data-sensitivity lifetimes, so exposure is ranked by the data that actually stays sensitive.
How fast can you change an algorithm today. We measure the real answer per system and name the specific blockers.
Target algorithms mapped to the NIST selections, ML-KEM in FIPS 203, ML-DSA in FIPS 204, and SLH-DSA in FIPS 205, plus hybrid TLS transition patterns.
A vendor questionnaire, a tracked response register, and an escalation path for the vendors that cannot answer.
A migration roadmap ordered by exposure and effort, with a board reporting cadence that survives a change of sponsor.
One path taken end to end: hybrid TLS, code signing, PKI issuance, or a data-at-rest store, with a runbook you can repeat.
Deliverables
You keep all of it, including the method behind it, so the work can be repeated without us.
Engagement shapes
Durations are indicative and depend on estate size. Scope and price are fixed in writing before the engagement starts.
| Shape | Duration | What you get |
|---|---|---|
| Rapid exposure review | 2 weeks | Top-20 exposure list, HNDL view, and a roadmap outline |
| Full assessment | 6 to 8 weeks | Complete CBOM, exposure register, roadmap, target architecture, and board pack |
| Migration advisory | Retainer, quarterly cadence | Governance, sequencing, vendor pressure, and progress reporting |
| Pilot delivery | 8 to 12 weeks | One migrated path in production with a repeatable runbook |
Related insights
Post-quantum
A CBOM is not a scan result. It is an inventory with provenance, ownership, and a lifetime attached to every entry.
7 min read
Post-quantum
Three numbers decide whether your post-quantum timeline is already late. None of them require a cryptography background to discuss.
6 min read
Next step
Thirty minutes on pqc migration. We will tell you whether we are the right firm for the problem, and who to talk to if we are not.