Security & Compliance / Post-Quantum Cryptography Consultant UK

Post-Quantum Cryptography Readiness — Discovery, Crypto-Agility & Migration Planning

The NCSC has set a national timeline: discovery of cryptographic dependencies and a drafted migration plan by 2028, highest-priority migration by 2031, and completion by 2035. Most organisations cannot yet answer the first question — where cryptography actually lives in the estate. That is an architecture problem before it is a cryptography problem.

You cannot migrate what you have never inventoried.

We help public-sector bodies, critical national infrastructure operators, and regulated enterprises build a defensible cryptographic inventory and a migration plan that survives a board review and an assurance review. The work starts with discovery across cloud, on-premises, network, and application estates, then risk-ranks by data longevity and exposure, and ends with a costed roadmap and a PKI capable of changing algorithms without being rebuilt.

Cryptographic discovery

Find the certificates, keys, algorithms, protocols, hardware roots of trust, and third-party dependencies that the estate actually relies on, including the ones nobody documented.

  • Certificate discovery
  • Algorithm inventory
  • HSM & key stores
  • Supplier dependencies

Migration planning

Risk-rank systems by how long their data must stay confidential, sequence the work against the 2028, 2031, and 2035 milestones, and produce the evidence trail assurance reviewers expect.

  • 2028 discovery
  • Risk prioritisation
  • Roadmap & costing
  • Board reporting

Crypto-agility by design

Rebuild PKI, issuance, and application trust so that changing an algorithm is a controlled change rather than a re-architecture, with automation that keeps pace with shrinking certificate lifetimes.

  • ADCS & PKI design
  • Certificate automation
  • Protocol agility
  • Hybrid certificates

Anonymised delivery evidence.

  • For an NHS body, expedited the build of a Windows Server 2022 two-node certificate authority ahead of imminent root authority expiry, making algorithm, key length, and lifetime decisions under a compressed timeline.
  • Within a NATO-classified environment, resolved blocking ADCS and certificate-services issues preventing completion of a major messaging platform upgrade, working through cryptographic dependencies in a classified estate.
  • For a regulated water-sector organisation, assessed and safely decommissioned an ADCS implementation incorrectly deployed on a domain controller, proving dependency status with Certutil and PKIview before any change was made.

Best fit.

This service is for critical national infrastructure and essential-service operators, NHS trusts, central government departments and arm’s-length bodies, regulated enterprises, and MSPs that need to answer this question on behalf of their own customers. It connects directly with PKI and certificate services, certificate lifecycle management, and security and compliance architecture.