Framework / CRYPTO

Cryptography & PQC — operationalised.

Crypto-agility before the quantum clock runs out.

CRYPTO

Post-quantum readiness aligned to NIST FIPS 203/204/205 and ENISA guidance — ahead of harvest-now-decrypt-later risk.

Cryptographically relevant quantum computers are not here yet, but the data they will decrypt is being harvested today. Long-life confidential data — health records, intellectual property, defence intelligence, financial settlements — is already being captured against the day a quantum machine can break RSA and elliptic-curve cryptography. ENISA, NIST and national agencies are now unanimous: organisations must begin cryptographic discovery and migration planning immediately, even though full migration will take years.

Open Cryptography topic on ENISA
/ KEY.FACTS
NIST FIPS 203
ML-KEM — Key Encapsulation Mechanism (Kyber)
NIST FIPS 204
ML-DSA — Digital Signature Algorithm (Dilithium)
NIST FIPS 205
SLH-DSA — Stateless Hash-Based Signatures (SPHINCS+)
Standards ratified
August 2024
ENISA position
Begin crypto inventory & agility work now
/ GUIDANCE

What this framework covers

§ 01

Harvest-now-decrypt-later (HNDL) risk

Adversaries capable of long-term traffic capture can store encrypted material today and decrypt it once they have a quantum computer. Any data that must remain confidential beyond the expected arrival of cryptographically relevant quantum computers is already at risk, even though the threat has not yet materialised.

  • Healthcare records — lifelong sensitivity
  • Government and defence intelligence — decades of relevance
  • Trade secrets and pre-patent R&D
  • Long-life financial contracts and settlement systems
§ 02

Crypto-agility — the architectural prerequisite

Migration to post-quantum algorithms is not a single cut-over. It requires the ability to swap algorithms, key sizes and protocols across the estate without re-architecting applications each time. Crypto-agility is the design property that makes this possible.

  • Algorithm-agnostic APIs in application code
  • Centralised key and certificate management with policy-driven rotation
  • Protocol upgrades planned in tandem — TLS 1.3, SSH, IPsec, S/MIME
  • Hybrid modes (classical + PQC) during the transition window
§ 03

Migration roadmap

We deliver PQC migration as a four-phase programme over 12 to 36 months, prioritised by data lifetime and exposure.

  • Phase 1 — Crypto inventory: keys, certificates, libraries, HSMs, protocols, third-party dependencies
  • Phase 2 — Risk prioritisation: HNDL exposure and data-lifetime classification
  • Phase 3 — Pilot deployment: hybrid TLS, signed software supply chain, code-signing
  • Phase 4 — Estate-wide rollout with ongoing crypto-agility governance
/ THECYBERCO.SERVICE

PQC readiness programme

  • Automated cryptographic inventory across applications, infrastructure and supply chain
  • HNDL exposure assessment by data class and retention requirement
  • Crypto-agility architecture review and remediation roadmap
  • Hybrid TLS pilot with measurable performance baselines
  • Code-signing and software supply chain migration to ML-DSA
  • Board-level reporting on quantum risk posture and migration progress

Talk to a cyber advisor.

Confidential consultation with our senior team.

Request Assessment