CABIER Global Assurance · Post-quantum

    Post-quantum readiness

    A cryptographic inventory, a staged migration and evidence at every step, linked to the same TrustGraph objects and Trust Gates as every other control.

    ARCHITECTURE. This page describes the design of the capability; it is not a live scan of any estate.

    Five stages

    1. Inventory

    Every use of public-key cryptography is recorded against the TrustGraph object it protects: certificates, key stores, signing services, custody keys, VPNs and third-party links.

    2. Prioritise

    Assets are ranked by how long their data must stay confidential and how exposed they are to capture-now, decrypt-later collection.

    3. Crypto-agility

    Systems are assessed for whether an algorithm can be swapped by configuration rather than by rebuild. Hard-coded cryptography is a finding in its own right.

    4. Migrate

    Migration to the NIST post-quantum standards (ML-KEM, ML-DSA, SLH-DSA), usually in hybrid mode first, with the owner and date recorded.

    5. Evidence

    Each migrated asset carries evidence of the algorithm in use, the test that proved it and the date it was verified.

    Reference points

    NIST FIPS 203, 204 and 205

    Post-quantum standards published August 2024.

    EU coordinated roadmap

    Member states to begin the transition by the end of 2026 and move high-risk uses by 2030. Pending primary-source verification.

    UK NCSC migration timeline

    Discovery by 2028, priority migration by 2031, completion by 2035. Pending primary-source verification.

    Digital assets and agentic payments

    Custody keys and payment signing used by agents need the longest protection and the least tolerance for failure, so they sit at the top of the priority list.

    Cryptographic assets attach to the objects they protect.

    See the relationship graph