Skip to content
Audit

Post-quantum readiness, certified.

A senior cryptographer maps every place asymmetric cryptography lives in your systems, ranks your exposure, and gives you a roadmap — and a certificate you can show investors, customers, and regulators.

Engagements

Three tiers, one standard of rigour

Every engagement begins with a paid scoping & discovery call. From there, choose the depth that fits.

Tier I≈ 4 weeks

Crypto-Agility Readiness

For · SMBs, crypto-native startups, consultancies

A focused readiness assessment: self-assessment questionnaire, document review, and a working session to establish your exposure and a crypto-agility baseline.

from €8,000· Annual renewal €3,000 / year
  • Structured readiness questionnaire & review
  • Crypto-agility baseline report
  • One guided workshop with your engineers
  • Readiness badge on completion
Start with discovery
Tier II8–12 weeks

Standard Audit

For · Mid-market, fintech, regulated industries

A full crypto inventory and migration roadmap, with staff training. We map every place asymmetric cryptography is used and order the migration against your threat model.

from €25,000· Annual renewal €8,000 / year
  • Complete cryptographic inventory
  • Threat-model-ordered migration roadmap
  • Hybrid & primitive selection guidance
  • Three workshops + staff training
  • quantakrypto certificate + annual renewal
Start with discovery
Tier III3–6 months

Enterprise / Regulated

For · Banks, insurance, telco, government

Everything in the Standard Audit, plus a board-level report and regulatory alignment mapping across ISO 27001, DORA, and NIS2, with quarterly check-ins.

Custom· Annual renewal from €20,000 / year
  • Everything in Tier II
  • Board report & executive briefing
  • Regulatory alignment mapping (27001 · DORA · NIS2)
  • Quarterly check-ins for the renewal year
  • Named senior cryptographer throughout
Start with discovery
Methodology

How an audit runs

Open, repeatable, and ordered against your threat model — not a checklist.

01

Scoping & discovery

Always first, always a paid engagement. We agree the scope, map your systems at a high level, and deliver a scope document with indicative pricing before any deeper work begins.

02

Cryptographic inventory

We find every place asymmetric cryptography is used — TLS, PKI, signing pipelines, identity keys, prekeys, backups, multi-device sync. There is no single switch; each location is its own decision.

03

Exposure analysis

We assess harvest-now-decrypt-later exposure, select primitives and hybrid constructions, evaluate library fitness, and map findings against the regulatory regimes that apply to you.

04

Migration roadmap

A prioritised, threat-model-ordered plan — including a rollout strategy from dark launch through gradual ramp to default-on and hardening, with explicit rollback paths.

05

Certification & renewal

A point-in-time quantakrypto certificate you can show investors, customers, and regulators, with an annual renewal that keeps your posture current as the standards and library landscape move.

Conformance & compliance

Standards & regulation we map against

We assess against the standards as written and align findings to the regime that governs you.

FIPS 203/204/205US · Global

NIST PQC Standards

The finalised ML-KEM, ML-DSA, and SLH-DSA standards. We audit against the standards as written — not earlier round-3 candidates.

CNSA 2.0US

NSA Commercial National Security Algorithm Suite

The NSA's algorithm suite and migration timeline for national-security systems and their suppliers.

DORAEU

Digital Operational Resilience Act

Operational resilience obligations for EU financial entities — including the cryptographic posture of critical systems.

NIS2EU

Network & Information Security Directive 2

Expanded cybersecurity obligations across essential and important entities, with state-of-the-art cryptography expectations.

ISO/IEC 27001Global

Information Security Management

We align findings to the 27001 family so your PQC work slots into an existing certification cycle rather than running beside it.

BSI TR-02102 · ANSSIEU

National guidance (DE · FR)

Germany's BSI and France's ANSSI publish their own migration guidance and timelines; we map exposure to the regime that governs you.

Questions

Before you book

Do you certify the company or the product?

The organisation. The quantakrypto certificate attests to your post-quantum readiness posture at a point in time, scoped to the systems we assessed.

Is the discovery call really paid?

Yes. Scoping & discovery is always a separate, paid engagement. It delivers a scope document and indicative pricing so you can decide on the full audit with real information.

What if no PQC standard exists for our exact case?

We assess against the finalised NIST standards and align to the ISO 27001 family, DORA, and NIS2. You get credibility today without waiting for a dedicated PQC accreditation scheme.

Is a certificate a guarantee?

No — and we say so on every certificate. An assessment is point-in-time. The annual renewal keeps your posture current as standards and libraries move.

Engagements

Find out where you stand.

Book a paid discovery call and leave with a scope and indicative pricing.