Your encryption has an expiration date. Do you know when?
Harvest-now-decrypt-later means traffic recorded today can be decrypted tomorrow. Regulators already require you to track the cryptography you run and to plan its migration. We put both on paper — an inventory, a regulatory mapping, and a roadmap, in the language your auditor works in.
The free scan reads only what your servers already show the public internet — TLS versions, key-exchange groups, cipher suites, and certificates. Findings arrive by email as a short gap snapshot, or read a sample first.
A compliance deadline, not a science-fiction risk
The dates that matter are not "when a large quantum computer exists". They are already on the regulatory calendar:
| PCI DSS 4.0.1 · req 12.3.3 | inventory of cipher suites and protocols, viability actively tracked | since 31 Mar 2025 |
|---|---|---|
| DORA · Art. 9(4)(d) + RTS | documented encryption policy, certificate register, and updating cryptography as cryptanalysis advances (RTS 2024/1774, Arts. 6–7) | since 17 Jan 2025 |
| FIPS 140-2 → Historical | every active FIPS 140-2 validation moves to Historical status | 21 Sep 2026 |
| NIST IR 8547 | RSA-2048 and ECC P-256 deprecated, then disallowed | 2030 / 2035 |
| G7 Cyber Expert Group | financial-sector PQC migration roadmap — your regulator has read it | Jan 2026 |
In a 2026 Entrust–Ponemon survey of 4,000 security leaders, 68% called cryptographic-asset management extremely difficult — and only 41% are actually preparing for migration. That gap between knowing and doing is the job we do.
What you get
-
A cryptographic inventory (CBOM)
Where you use encryption, which of it is quantum-vulnerable, and which of that protects long-lived data — built on the open CycloneDX standard, so it stays useful after we leave.
-
Regulatory mapping
Every finding tied to the specific clause that requires action — PCI DSS 12.3.3, DORA Art. 9(4)(d), NIST IR 8547 — so your auditor sees exactly which requirement each finding answers to.
-
A 36-month migration roadmap
Prioritised by harvest-now-decrypt-later exposure and regulatory deadline. What to fix first, and what it takes — in board-ready language.
The honest middle
The big consultancies start at six figures. The overlay tools hand you a score and a false sense of safety. We sit between:
Against Big4, SandboxAQ, IBM Quantum Safe — built for enterprise, priced for enterprise. If you are a credit union or a fintech, you are not their customer. You are ours.
Against free scanners and readiness scores — a surface number is not an audit-ready deliverable. We go inside — a real inventory of your code and infrastructure — and hand you a signed report you can put in front of your regulator.
We do not sell you cryptography. NIST already standardised it (FIPS 203/204/205); it is free and open-source. We sell the judgment, the mapping, and the plan — the three things that don't commoditise.
How it works
-
1.0
Free external scan
We look at your public endpoints from the outside; you get a gap snapshot by email.
-
2.0
Scoped assessment
You run our read-only scanner inside your perimeter — offline mode available. Nothing leaves your network but the report.
-
3.0
Report and roadmap
Cryptographic inventory, regulatory mapping, prioritised 36-month plan, board deck.
-
4.0
Annual re-scan
We track regulatory changes and re-issue the assessment as deadlines move.
Engagements
-
free
External scan
Public TLS perimeter, gap snapshot by email.
-
fixed scope
Fintech assessment
Network-layer inventory, regulatory mapping, roadmap skeleton, one working session.
-
fixed scope
Bank · Insurer · Credit union
Full cryptographic inventory across code and infrastructure, mapping, prioritised roadmap, materials for your next exam.
-
recurring
Annual retainer
Yearly re-scan plus regulatory updates as mandates evolve.
Every engagement is a fixed-scope project with a deliverable — sized to sit beside your existing compliance line items, closer to your annual pentest than to a consultancy retainer. Tell us what kind of institution you are and we will scope it: write to hello@kybermark.com →
This assessment helps you demonstrate readiness and address inventory and crypto-agility expectations. It is not a substitute for a formal audit, and the "Quantum Readiness Assessed" mark is an attestation by us — not an accredited certification.
Questions we actually get
- Is the quantum threat even real yet?
- The relevant date is not "when a large quantum computer exists" — it is today, because recorded traffic can be decrypted later. That is why the deadlines that matter are regulatory: DORA since January 2025, PCI DSS 12.3.3 since March 2025, NIST deprecation by 2030.
- Do you see our data?
- No. For the scoped assessment, the scanner runs inside your perimeter with an offline mode; only the report leaves. Think flashlight, not vacuum cleaner. The free scan never touches your infrastructure at all — it reads what your public endpoints already serve.
- We already have SOC 2 — isn't crypto covered?
- SOC 2 does not assess the quantum-readiness of your cryptographic inventory. It answers a different question.
- What is a CBOM?
- A Cryptographic Bill of Materials — an inventory of cryptographic assets in the open CycloneDX standard, maintained under the Linux Foundation.
- Is this an accredited certification?
- No — our mark is an attestation: our expert assessment, not an accredited certification. No accredited PQC-readiness certification scheme currently exists anywhere; we align with the frameworks as they form (X9, NIST/CISA CBOM guidance).