<NESway/>
Skipping the slide deck0%

Every PQC deadline that applies to you, on one calendar.

Mapping of NIST, NSA CNSA 2.0, EU and sector-specific quantum-readiness requirements to your systems and dates.

Let's Build Together

One call with a senior engineer. A straight answer on what it would take.

Illustration: Compliance mapping to emerging PQC mandates

Where you are. Where you’ll be.

You need this if

  • You supply government, defense or critical infrastructure
  • You operate in financial services
  • Customers have added quantum readiness to security questionnaires

What changes for your business

  • No surprise compliance deadlines
  • Evidence ready for auditors and customers
  • Migration priorities aligned with regulatory exposure

What we hand over

  1. Applicable mandate and deadline register
  2. Requirement-to-system mapping
  3. Compliance roadmap aligned to migration plan
  4. Audit evidence and reporting templates

What it is

Post-quantum compliance mapping identifies which quantum-readiness requirements apply to an organization, from NIST's timeline for retiring RSA and ECC to CNSA 2.0 and sector regulators, and turns them into dated system requirements and evidence. The rules come from several directions at once, so mapping is what prevents duplicated work.

Post-quantum requirements are arriving from many directions: NIST's deprecation timeline, CNSA 2.0 for national security suppliers from 2027, EU coordinated roadmaps, and financial regulators asking pointed questions. We map which apply to you, translate each into concrete system requirements and dates, and build the evidence trail auditors and customers will request.

Why now
2030 NIST begins deprecating RSA and ECC; both are disallowed by 2035. NIST IR 8547 (opens in a new tab)
Last reviewed

How it runs

  1. 01

    Diagnose

    Typically 2–4 weeks

    We map the problem, your data and your systems, and agree the one number that defines success.

  2. 02

    Prove

    Typically 4–8 weeks

    A working pilot on your real data, measured against that number. Not a slide demo.

  3. 03

    Ship

    Scoped to the outcome

    Production build with security, monitoring, cost controls and documentation included, not upsold.

  4. 04

    Run

    Ongoing, optional

    We operate what we built against clear service levels, or train your team to. Your call. No lock-in.

Questions you’ll ask

Which post-quantum rules might apply to us?
Commonly NIST's timeline to deprecate RSA and ECC from 2030, CNSA 2.0 for suppliers to US national security systems, EU coordinated roadmaps for member states and critical sectors, and supervisory expectations in financial services. Which apply depends on your sector, customers and markets.
What evidence will auditors expect?
An inventory of cryptography, a risk assessment, a dated migration plan with owners, and proof of progress against it. We build these as living records rather than a one-off report.
Customers are asking about quantum readiness in questionnaires. What do we say?
The honest answer is your inventory status and your dated plan. Having both turns an awkward question into evidence of good governance.

Sound familiar? Let’s fix it.

One call with a senior engineer. You’ll leave with a straight answer on what it would take.

Let's Build Together