Insights
Quantum-readiness, in plain language
Short, citable pieces on the standards, deadlines and decisions every security and engineering leader should know before the post-quantum migration lands on their desk.
- ·PQC Migration
Harvest Now, Decrypt Later: The CISO's 2026 Guide to Beating the Quantum Deadline
Why HNDL attacks make PQC migration urgent in 2026: Mosca's Theorem, NIST FIPS 203/204/205, NCSC milestones, and a 90-day starter plan.
harvest now decrypt laterpost-quantum cryptographyMosca's theorem - ·Post-Quantum Readiness
Certifications That Cover CRYSTALS-Kyber and Dilithium (NIST FIPS 203/204)
Which certification actually teaches you to implement CRYSTALS-Kyber and Dilithium? A guide to the NIST FIPS 203/204 standards and the hands-on training that covers them.
CRYSTALS-KyberCRYSTALS-DilithiumML-KEM - ·Post-Quantum Readiness
How to Build a CBOM (Cryptographic Bill of Materials): A Step-by-Step Guide
A CBOM is the inventory that makes post-quantum migration possible. Here's how to build one — the sources, the tooling, the four categories to capture, and the pitfalls that stall most programs.
CBOMcryptographic bill of materialspost-quantum migration - ·Post-Quantum Readiness
How Should an Enterprise Start Its PQC Migration? A Phased Playbook
Post-quantum migration is a multi-year program, not a library swap. Here's how an enterprise starts one - governance, cryptographic inventory, risk-based prioritization, and a phased Assess to Implement roadmap.
PQC migrationpost-quantum cryptographycrypto-agility - ·Post-Quantum Readiness
What Training Do CISOs Actually Need for the Quantum Threat?
The quantum threat is a governance problem before it is a math problem. Here's the specific training a CISO and their team need to be quantum-ready — and how to sequence it.
CISO quantum threatpost-quantum cryptography trainingPQC migration - ·Post-Quantum Readiness
Mosca's Theorem Explained: How to Calculate Your Organization's Quantum Risk Deadline (X + Y > Z)
Mosca's Theorem (X + Y > Z) is the simplest test of whether your organization is late to post-quantum migration. Calculate it, with worked examples.
Mosca's theoremquantum risk deadlinepost-quantum cryptography