Post-quantum guides, by what you need to do
Practical, sourced explainers on the concepts and decisions behind a post-quantum migration — the threat model, crypto-agility, inventory, roadmaps, and conformance. Grouped by whether you need to learn, audit, migrate, or certify.
PQC readiness audit
Book an audit →Building a cryptographic inventory: you can't migrate what you can't see
A cryptographic inventory is a complete, current map of every algorithm, key, certificate, protocol, and library in your estate — plus where each is used and what data it protects. Why it is the mandatory first step of any PQC migration, how to build one, and how CBOM keeps it alive instead of stale.
7 min
The PQC readiness assessment: measuring how prepared you are to migrate
A post-quantum readiness assessment is a breadth-first evaluation of how prepared your organization is to migrate — turning a vague sense of quantum risk into a scored, prioritized baseline. What it evaluates, how it differs from a full technical audit, and what you get out of it.
8 min
Finding quantum-vulnerable cryptography in code and on the network
The practical hunt for RSA, Diffie–Hellman, and elliptic-curve schemes across source, dependencies, certificates, and live traffic — what actually counts as vulnerable, the detection methods, their blind spots, and how findings converge into one machine-readable inventory.
7 min
Migration engineering
Plan a migration →A post-quantum migration roadmap: sequencing the move to PQC
How to turn a cryptographic inventory into a prioritized, deadline-aware migration plan — the five phases, how to sequence by data shelf life rather than by ease, and how to roll out hybrids without breaking production.
8 min
Migrating TLS to hybrid post-quantum key exchange
A practical walkthrough of moving TLS 1.3 to X25519MLKEM768 hybrid key exchange — what changes on the wire, where support already exists, the handshake-size cost, and how to roll it out without breaking classical clients.
9 min
Migrating RSA and ECDH key exchange to ML-KEM
Replacing classical key establishment with ML-KEM is more than a TLS change: key exchange lives in SSH, VPNs, email, messaging, and data at rest. What actually changes, hybrid vs pure, and how to stage the migration without stranding half your estate on classical crypto.
9 min
Implementing crypto-agility: patterns for swappable cryptography
The concrete patterns that make an algorithm a replaceable component: runtime negotiation, a provider abstraction, config-driven selection, self-describing versioned formats, size-agnostic storage, and automated rotation. The engineering behind agility, not the argument for it.
8 min
Conformance certification
Get certified →Conformance testing for post-quantum crypto: why passing the KATs is not enough
Passing NIST's ACVP known-answer vectors, conforming to FIPS 203/204/205, and passing a security audit are three different things. What the KATs miss, how conformance testing actually works, and why an audited, popular library is not evidence of conformance.
7 min
A FIPS 203 conformance checklist for ML-KEM implementations
The concrete checks a conformant ML-KEM implementation must pass — §7.2/§7.3 input validation, implicit rejection, exact sizes and encoding, versioning and adversarial vectors — as a checklist you can run against any library.
7 min
ACVP vs conformance vs FIPS 140-3: what each one actually proves
"ACVP-tested," "conformant," and "FIPS 140-3 validated" are three different claims that answer three different questions. What each one covers, what it silently leaves out, and how to ask which axis a vendor's assurance really lives on.
8 min
Training & education
Train your team →Harvest now, decrypt later: the threat that makes PQC urgent today
Why a quantum computer that does not yet exist is already a problem for data you send today — and how to reason about which of your secrets are actually at risk. The threat model, the maths of the exposure window, and where to start.
8 min
Crypto-agility: designing systems that can swap algorithms
Crypto-agility is the property that lets you replace a cryptographic algorithm without re-architecting the system around it. What it means concretely, the anti-patterns that block it, and why it is the real deliverable of a post-quantum migration.
8 min
A post-quantum cryptography primer: the 10-minute orientation
The whole picture in one read: what a quantum computer actually breaks, what it leaves alone, the NIST standards that replace the broken parts, the deadlines that make it a program and not a project, and where to start. The on-ramp to everything else.
7 min
Hybrid key exchange, explained: pairing classical and post-quantum
Why post-quantum deployments run a classical curve and a PQ KEM together and derive the session key from both — so the connection survives a quantum break of the curve or an undiscovered flaw in the young algorithm. How the combiner works, where hybrids are used, and when pure PQC is preferred instead.
6 min
RSA vs ML-KEM: what actually changes when you replace classical key exchange
A side-by-side of RSA and ECDH against ML-KEM — the hardness assumptions Shor's algorithm breaks, the encapsulate/decapsulate message pattern, key and ciphertext sizes, and performance — so you know exactly what changes in your systems, and what ML-KEM does not replace.
7 min
Mosca's theorem explained: is your data already at risk?
The X + Y > Z inequality that decides whether a given secret is exposed to harvest-now-decrypt-later — what each term means, how to estimate them honestly, and how to turn the result into a per-system migration priority.
7 min
Turn quantum risk into a credential.
Book a discovery call and get an indicative scope and pricing for your organisation.