Supply Chain & Resilience
Post-quantum readiness
What this is
Post-quantum readiness prepares an organisation's cryptography for algorithms resistant to quantum attack. The first and largest task is a cryptographic inventory: establishing where public-key cryptography is used, what data it protects and for how long that data must stay confidential. Migration cannot be planned for algorithms that have not been located.
The problem
Harvest now, decrypt later means the clock already started for long-lived data.
The quantum threat is unusual because it is a future capability that attacks the past. Encrypted traffic captured today - VPN sessions, TLS connections, encrypted archives - can be stored now and decrypted later, once a cryptographically relevant quantum computer exists. Nobody needs to break the encryption today to benefit from capturing it today.
That inverts the usual planning logic. For data that stops mattering in two years, this is not a current problem. For data that must stay confidential into the 2030s and beyond, the exposure is already live, because the capture is happening now regardless of when the decryption becomes possible.
The honest first step is not migration, it is inventory. Most organisations cannot answer where public-key cryptography is used across their estate, which algorithms and key lengths are in play, which are embedded in appliances and third-party products they cannot change, and which protect data with a long confidentiality requirement. Without that, any migration plan is guesswork.
Who this is for
- Organisations holding data that must remain confidential for a decade or more - health, financial, legal, defence.
- Firms whose regulators or major customers have begun asking about quantum readiness.
- Companies with long-lived embedded systems or appliances where cryptography cannot easily be changed.
- Teams who cannot currently produce a cryptographic inventory for any purpose, quantum or otherwise.
- Organisations planning a multi-year infrastructure programme where crypto-agility should be designed in now.
Delivery
How the engagement actually runs
Sprints inside your engineering cycle, with findings arriving continuously rather than a report arriving at the end. Durations are elapsed time for a typical scope, and get re-scoped against your estate before anything is committed.
- 011 week
Scope and approach
Which parts of the estate are in scope and how cryptography will be discovered - configuration analysis, traffic inspection, code and vendor documentation.
- 023-4 weeks
Build the inventory
The largest task by far, and the one with lasting value regardless of quantum timelines - a cryptographic inventory is useful for several other purposes.
- 031-2 weeks
Map data lifetimes
How long each data class must stay confidential, done with the business and with legal rather than assumed.
- 041-2 weeks
Prioritise and sequence
The intersection of long-lived data and vulnerable algorithms, sequenced into a migration plan with crypto-agility work first.
Deliverables
What you actually receive
Artefacts your team owns and can maintain after the engagement, not a report that ages the moment it lands.
| Deliverable | What it contains | When |
|---|---|---|
| Cryptographic inventory | Where public-key cryptography is used across the estate, which algorithms and key lengths, and in what protocols. Includes what is embedded in third-party products. | Week 3-5 |
| Data lifetime mapping | How long each protected data class must remain confidential, which is what determines urgency. Most estates have a small subset with genuinely long horizons. | Week 4 |
| Exposure prioritisation | Where long confidentiality requirements meet vulnerable algorithms on capturable channels - the intersection is the actual priority list, and it is usually short. | Week 5 |
| Crypto-agility assessment | Where algorithms are hardcoded versus configurable, because agility determines whether migration is a change or a rebuild. | Week 6 |
| Supplier position | Where your critical suppliers stand on post-quantum roadmaps, since much of your cryptography is in products you do not control. | Week 6 |
| Sequenced migration plan | A realistic multi-year sequence starting with the highest-exposure systems, aligned to standards and vendor availability rather than to a wish. | Week 7-8 |
Frameworks this touches
FAQ
Questions people actually ask
What is harvest now, decrypt later?
Which cryptography is affected?
Should we start migrating now or wait?
What is crypto-agility and why does it matter more than the algorithm choice?
More in Supply Chain & Resilience
Start
Three ways in, depending on how close the deadline is.
- Book it
Book a discovery call
Thirty minutes, no deck. We work out whether there is a real engagement here, and say so if there is not.
- Go
Check the EU AI Act applies
Six questions, a dated list of the obligations that reach you, and a calendar file so the deadlines land somewhere you will see them again.
- Go
Request a roadmap
You know the obligation and the deadline. We scope the sprints, the deliverables and the dates.
Or just email a human: hello@cloudgap.ai
We reply within24 hours