Every PQC deadline that applies to you, on one calendar.
Mapping of NIST, NSA CNSA 2.0, EU and sector-specific quantum-readiness requirements to your systems and dates.
One call with a senior engineer. A straight answer on what it would take.

Where you are. Where you’ll be.
You need this if
- You supply government, defense or critical infrastructure
- You operate in financial services
- Customers have added quantum readiness to security questionnaires
What changes for your business
- No surprise compliance deadlines
- Evidence ready for auditors and customers
- Migration priorities aligned with regulatory exposure
What we hand over
- Applicable mandate and deadline register
- Requirement-to-system mapping
- Compliance roadmap aligned to migration plan
- Audit evidence and reporting templates
What it is
Post-quantum compliance mapping identifies which quantum-readiness requirements apply to an organization, from NIST's timeline for retiring RSA and ECC to CNSA 2.0 and sector regulators, and turns them into dated system requirements and evidence. The rules come from several directions at once, so mapping is what prevents duplicated work.
Post-quantum requirements are arriving from many directions: NIST's deprecation timeline, CNSA 2.0 for national security suppliers from 2027, EU coordinated roadmaps, and financial regulators asking pointed questions. We map which apply to you, translate each into concrete system requirements and dates, and build the evidence trail auditors and customers will request.
- Why now
- 2030 NIST begins deprecating RSA and ECC; both are disallowed by 2035. NIST IR 8547 (opens in a new tab)
- Last reviewed
How it runs
- 01
Diagnose
Typically 2–4 weeksWe map the problem, your data and your systems, and agree the one number that defines success.
- 02
Prove
Typically 4–8 weeksA working pilot on your real data, measured against that number. Not a slide demo.
- 03
Ship
Scoped to the outcomeProduction build with security, monitoring, cost controls and documentation included, not upsold.
- 04
Run
Ongoing, optionalWe operate what we built against clear service levels, or train your team to. Your call. No lock-in.
Questions you’ll ask
- Which post-quantum rules might apply to us?
- Commonly NIST's timeline to deprecate RSA and ECC from 2030, CNSA 2.0 for suppliers to US national security systems, EU coordinated roadmaps for member states and critical sectors, and supervisory expectations in financial services. Which apply depends on your sector, customers and markets.
- What evidence will auditors expect?
- An inventory of cryptography, a risk assessment, a dated migration plan with owners, and proof of progress against it. We build these as living records rather than a one-off report.
- Customers are asking about quantum readiness in questionnaires. What do we say?
- The honest answer is your inventory status and your dated plan. Having both turns an awkward question into evidence of good governance.
Sound familiar? Let’s fix it.
One call with a senior engineer. You’ll leave with a straight answer on what it would take.
Let's Build Together