Security & Compliance / Post-Quantum Cryptography Consultant UK
Post-Quantum Cryptography Readiness — Discovery, Crypto-Agility & Migration Planning
The NCSC has set a national timeline: discovery of cryptographic dependencies and a drafted migration plan by 2028, highest-priority migration by 2031, and completion by 2035. Most organisations cannot yet answer the first question — where cryptography actually lives in the estate. That is an architecture problem before it is a cryptography problem.
You cannot migrate what you have never inventoried.
We help public-sector bodies, critical national infrastructure operators, and regulated enterprises build a defensible cryptographic inventory and a migration plan that survives a board review and an assurance review. The work starts with discovery across cloud, on-premises, network, and application estates, then risk-ranks by data longevity and exposure, and ends with a costed roadmap and a PKI capable of changing algorithms without being rebuilt.
Cryptographic discovery
Find the certificates, keys, algorithms, protocols, hardware roots of trust, and third-party dependencies that the estate actually relies on, including the ones nobody documented.
Migration planning
Risk-rank systems by how long their data must stay confidential, sequence the work against the 2028, 2031, and 2035 milestones, and produce the evidence trail assurance reviewers expect.
Crypto-agility by design
Rebuild PKI, issuance, and application trust so that changing an algorithm is a controlled change rather than a re-architecture, with automation that keeps pace with shrinking certificate lifetimes.
Anonymised delivery evidence.
- For an NHS body, expedited the build of a Windows Server 2022 two-node certificate authority ahead of imminent root authority expiry, making algorithm, key length, and lifetime decisions under a compressed timeline.
- Within a NATO-classified environment, resolved blocking ADCS and certificate-services issues preventing completion of a major messaging platform upgrade, working through cryptographic dependencies in a classified estate.
- For a regulated water-sector organisation, assessed and safely decommissioned an ADCS implementation incorrectly deployed on a domain controller, proving dependency status with Certutil and PKIview before any change was made.
Best fit.
This service is for critical national infrastructure and essential-service operators, NHS trusts, central government departments and arm’s-length bodies, regulated enterprises, and MSPs that need to answer this question on behalf of their own customers. It connects directly with PKI and certificate services, certificate lifecycle management, and security and compliance architecture.
