Skip to content
Guides

Post-quantum guides, by what you need to do

Practical, sourced explainers on the concepts and decisions behind a post-quantum migration — the threat model, crypto-agility, inventory, roadmaps, and conformance. Grouped by whether you need to learn, audit, migrate, or certify.

Training & education

Train your team

Harvest now, decrypt later: the threat that makes PQC urgent today

Why a quantum computer that does not yet exist is already a problem for data you send today — and how to reason about which of your secrets are actually at risk. The threat model, the maths of the exposure window, and where to start.

8 min

Crypto-agility: designing systems that can swap algorithms

Crypto-agility is the property that lets you replace a cryptographic algorithm without re-architecting the system around it. What it means concretely, the anti-patterns that block it, and why it is the real deliverable of a post-quantum migration.

8 min

A post-quantum cryptography primer: the 10-minute orientation

The whole picture in one read: what a quantum computer actually breaks, what it leaves alone, the NIST standards that replace the broken parts, the deadlines that make it a program and not a project, and where to start. The on-ramp to everything else.

7 min

Hybrid key exchange, explained: pairing classical and post-quantum

Why post-quantum deployments run a classical curve and a PQ KEM together and derive the session key from both — so the connection survives a quantum break of the curve or an undiscovered flaw in the young algorithm. How the combiner works, where hybrids are used, and when pure PQC is preferred instead.

6 min

RSA vs ML-KEM: what actually changes when you replace classical key exchange

A side-by-side of RSA and ECDH against ML-KEM — the hardness assumptions Shor's algorithm breaks, the encapsulate/decapsulate message pattern, key and ciphertext sizes, and performance — so you know exactly what changes in your systems, and what ML-KEM does not replace.

7 min

Mosca's theorem explained: is your data already at risk?

The X + Y > Z inequality that decides whether a given secret is exposed to harvest-now-decrypt-later — what each term means, how to estimate them honestly, and how to turn the result into a per-system migration priority.

7 min

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.