S—01
Post-quantum readiness assessment
Six to eight weeks. The cheapest way to find out how exposed you are.
Before any migration, you need to know where your cryptography lives. Most organisations have never had that inventory built.
Discovery
- Cryptographic bill of materials
- Certificate and key inventory
- Protocol and cipher-suite scanning
- Third-party and supply-chain dependencies
Risk
- Exposure ranked by confidentiality lifetime
- Harvest-now-decrypt-later modelling
- Regulatory deadline mapping
- Business impact and prioritisation
Roadmap
- Costed, sequenced migration plan
- Crypto-agility target architecture
- Vendor and product gap analysis
- Board-level summary and technical annex
Standards
- NIST FIPS 203 / 204 / 205 alignment
- Entropy source validation, SP 800-90B
- Key management policy review
- Cryptographic governance framework