All scenarios

// Scenario 02

Post-quantum readiness, before it is urgent

A quantum computer that breaks today’s encryption does not exist yet. The data it will break is being collected now. This is the calm, practical move to post-quantum cryptography, sized for a company that is not a bank.

For
Fintech, health, legal, government suppliers, anyone keeping data for years
Scenario
This is a scenario we deliver, not a past client result.
Ask for this scenario

Why it matters in 2026

In August 2024 NIST published the first post-quantum standards: ML-KEM for key exchange and ML-DSA and SLH-DSA for signatures. NIST’s transition plan deprecates RSA and elliptic-curve cryptography after 2030 and disallows them after 2035. The EU’s coordinated roadmap, published in June 2025, asks organisations to start the move by the end of 2026 and to protect high-risk systems by 2030. Meanwhile attackers can “harvest now, decrypt later”: copy encrypted traffic and archives today and read them in a few years. If your contracts, health records or client files must stay private for longer than that, the clock has already started.

You need this if

  • You keep client, health, legal or financial data that must stay confidential for 5 years or more.
  • You sell to banks, insurers, public bodies or large European companies that are starting to ask suppliers about it.
  • Nobody can tell you where your company uses encryption: websites, VPN, email, backups, signed files, APIs.
  • Your systems hard-code one algorithm, so changing it would mean rewriting software.

How we deliver it

  1. 1 Inventory

    We list every place you rely on public-key cryptography: TLS on sites and APIs, VPN and SSH access, email, code and document signing, tokens, encrypted backups, and the vendors who handle your data.

  2. 2 Rank the risk

    Each item gets a score from two questions: how long must this data stay secret, and how hard is it to change. Long-lived data on hard-to-change systems comes first.

  3. 3 Switch on the quick wins

    Where your stack already supports it, we enable hybrid post-quantum key exchange (classic X25519 plus ML-KEM), move to TLS 1.3 and update the libraries that make it possible. Browsers and major CDNs already speak it.

  4. 4 Make it agile, then plan

    We move cryptography behind configuration instead of code, so the next change is a setting, and hand you a dated roadmap with owners, vendor questions and the checkpoints for 2026, 2030 and 2035.

What you get

  • A cryptography inventory you can keep up to date
  • A risk-ranked list of what to migrate, and in what order
  • Hybrid post-quantum key exchange on the services that support it today
  • A questionnaire to send to your vendors and hosting providers
  • A one-page roadmap for your board, your clients and your auditors

What we will not promise

We will not sell you a “quantum-proof” badge. Nobody can honestly give one: the standards are new, products are still adding support, and some systems will wait on their vendors. What we promise is that you will know exactly where you stand and what happens next.

Questions

Is a quantum computer able to break encryption today?

No. Public estimates of when one could break RSA vary, and nobody can give a date. The risk today is data recorded now and decrypted later, plus the years a migration takes, which is why standards bodies set deadlines in 2030 and 2035.

Do we need to replace all our software?

Usually not. Much of the work is configuration and library updates, and a lot of it lands through your existing providers. The inventory shows what you control, what your vendors control and what can wait.

Does post-quantum encryption slow a website down?

Hybrid key exchange adds a little data to the first connection. Major browsers and CDNs have run it by default since 2024, and visitors do not notice it.

Prev
Next