QUANTUM RISK
& INTELLIGENCE
ADVISORY
Practitioner-grade intelligence at the intersection of quantum computing, post-quantum cryptography, and the decade-long migration decisions facing every board with long-lived secrets — scenario forecasting, sovereign capability analysis, crypto-agility doctrine, and the regulatory architecture forming around the quantum transition.
QRIA BRIEFINGS
I went looking for one number — the 20 million qubits everyone said it would take to break RSA-2048 — and found it no longer holds. Not because the hardware moved, but because the mathematics did: three papers in ten months (Gidney's under-a-million, Iceberg's contested sub-100,000, and a Caltech–Berkeley–Oratomic team's 'as few as 10,000') have compressed the requirement more than a thousandfold. Applied honestly to a decade-long harvest and multi-decade confidentiality periods, the Mosca inequality no longer rules out that the most sensitive data already collected is compromised in waiting. The full arithmetic — and what it means for AUKUS, the harvest, and a policy response that has not caught up.
National PKIs are the cryptographic substrate of every modern state — tax filing, healthcare records, qualified electronic signatures, eID cards, government TLS, and the diplomatic identity that authenticates inter-state messages. They were architected for an adversary who could not yet exist. The first post-quantum PKI migration is now under way, at scale, in the history of the discipline. NIST finalised FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA), and the stateful hash-based track in SP 800-208. The BSI’s TR-02102-1 update of 23 January 2026 names end-of-2031 and end-of-2035 as the migration floors. The German V-PKI assessment is the public canary. The deeper reality is that every national PKI on the planet faces the same trade — and every candidate signature scheme loses on something that matters. The algorithm is the visible decision. The portfolio is the operational decision. The systemic cascade across HSM firmware, X.509, TLS, OCSP, smart cards, eIDAS QSP regime, browser stores, mail clients, code signing, and eID issuance is the actual project. Ten jurisdictions mapped against the convergent 2031–2035 calendar, with three original diagrams and the practitioner frame for the migration the regulators have only begun to describe.
NIS2 Article 21 requires “state-of-the-art” cryptography. DORA Article 6 requires emerging-risk monitoring of quantum. CRA Article 11 names crypto-agility as a design property. CNSA 2.0 sets a January 2027 contractor floor. Each framework audits a procedural shell. The substantive obligation lives in the union — and the audit that maps across the four is the one that almost no organisation has yet run. Crypto-agility is a property of architecture, not a control. The state-of-the-art has moved. The audit has not yet caught up. The supervisory practice is on a calendar that will close the gap whether the organisation prepares or not. The practitioner playbook for the PQC migration the regulators are actually asking for, mapped to the regulators actually doing the asking.
Part III of the Governance Gap trilogy. The class of risks where post-activation governance cannot reverse the consequences. Three thresholds: the Kessler cascade in LEO that becomes self-sustaining once triggered, the HNDL harvest already in progress against the Mosca inequality (15-year confidentiality data generated from 2020 onwards is already in the risk window), and the inference permanence where Yeagley’s behavioural model meets Q-Day content decryption. The 1,400-fold qubit reduction in three months. Google’s 2029 internal deadline. CNSA 2.0 in January 2027. DORA quantum risk monitoring active since January 2025. The governance gap that cannot be closed after the risk activates — because the activation itself changes the conditions under which governance is possible. The time to close it is before the activation. The Chokepoint Doctrine series, complete.
The inaugural QRIA briefing. Written for boards, executives, and operations leaders — not just security teams. Most of the encrypted data your organisation creates today is being collected by state actors and stored against the future arrival of a Cryptographically Relevant Quantum Computer that can break today’s encryption. The threat is called Harvest Now Decrypt Later. The capability that defeats today’s encryption is on probability bands across the 2030–2040 window. The standards to defend against it — NIST’s ML-KEM, ML-DSA and SLH-DSA — were finalised in August 2024. The decision window for migration is now. The cost of doing nothing is not paid today; it is paid in the decade after decryption, when the files that were collected in 2024 become readable in 2034. This piece is the accessible explanation, the practical action sequence, and the regulatory context for the executive who reads it.
INITIATE ENGAGEMENT
SECURE CHANNELS
All inquiries are treated with discretion. For sensitive government or defense sector engagements, please indicate in your message and we will establish appropriate communication protocols.
Standard inquiries: 48 hours
Retainer & enterprise: 24 hours
Government & defense: Same day