Cryptographic Posture Management — discover, grade & remediate your whole cryptographic estate
Sovereign Certificate Authority for enterprise-grade certificate issuance & management
Certificate Lifecycle Management, discovery, governance & automation
DNS-agnostic Domain Control Validation, ready for 47-day TLS certificates
A quarter-by-quarter method to inventory, prioritise and migrate your cryptography before the 2030 deadlines, with the four readiness metrics a board can read without a cryptographer in the room.
The PDF lands in your inbox within a minute, in the language of your choice.
The algorithms are standardised. The deadlines are published. What is not settled, in most organisations, is far more basic: nobody knows where the vulnerable cryptography is, what depends on it, or who owns it.
ANSSI, BSI and NIST converge on 2030 for the start of mandatory migration. NIS2 and DORA already make management bodies accountable for cryptographic risk.
Anything encrypted today and worth keeping for ten years is already exposed to harvest-now, decrypt-later. The lifetime of the data sets the deadline, not the hardware.
You cannot migrate what you do not know you run. The whitepaper spends its first year on this one problem, because every later phase depends on it.
Written for an enterprise starting in Q1 2027. Shift it if you start earlier or later, but keep the order.
Declare scope, read what runs, merge every source into one governed record per asset with a named owner. Blind spots listed, not hidden.
Not everything needs to move first. Weight each asset by data lifetime, exposure and dependencies, then grade it against your own policy.
Hybrid first, verified in production, one critical system at a time. A fix counts when it is re-observed live, not when the ticket closes.
Four metrics on one page, for the board and the supervisor alike: coverage, quantum exposure, agility, trajectory. Archived every quarter.
Boards do not need lattices. They need one page: how exposed are we, is it improving, how fast, what residual risk are we accepting. The same page goes to the regulator.
A plan with a quarter on every line, and one page of metrics to take to the board and the budget committee.
The sequencing: what to inventory first, how to weight exposure, when hybrid is enough and when it is not.
How NIS2 Article 20 and DORA Article 5 turn the migration into a governance obligation, and what evidence satisfies the supervisor.
Download the whitepaper in English or French, then put the first deliverable on next quarter's agenda.