Quantum-readiness assessment · for financial institutions

KYBERMARK

Your encryption has an expiration date. Do you know when?

Harvest-now-decrypt-later means traffic recorded today can be decrypted tomorrow. Regulators already require you to track the cryptography you run and to plan its migration. We put both on paper — an inventory, a regulatory mapping, and a roadmap, in the language your auditor works in.

The free scan reads only what your servers already show the public internet — TLS versions, key-exchange groups, cipher suites, and certificates. Findings arrive by email as a short gap snapshot, or read a sample first.

A compliance deadline, not a science-fiction risk

The dates that matter are not "when a large quantum computer exists". They are already on the regulatory calendar:

PCI DSS 4.0.1 · req 12.3.3 inventory of cipher suites and protocols, viability actively tracked since 31 Mar 2025
DORA · Art. 9(4)(d) + RTS documented encryption policy, certificate register, and updating cryptography as cryptanalysis advances (RTS 2024/1774, Arts. 6–7) since 17 Jan 2025
FIPS 140-2 → Historical every active FIPS 140-2 validation moves to Historical status 21 Sep 2026
NIST IR 8547 RSA-2048 and ECC P-256 deprecated, then disallowed 2030 / 2035
G7 Cyber Expert Group financial-sector PQC migration roadmap — your regulator has read it Jan 2026

In a 2026 Entrust–Ponemon survey of 4,000 security leaders, 68% called cryptographic-asset management extremely difficult — and only 41% are actually preparing for migration. That gap between knowing and doing is the job we do.

What you get

The honest middle

The big consultancies start at six figures. The overlay tools hand you a score and a false sense of safety. We sit between:

Against Big4, SandboxAQ, IBM Quantum Safe — built for enterprise, priced for enterprise. If you are a credit union or a fintech, you are not their customer. You are ours.

Against free scanners and readiness scores — a surface number is not an audit-ready deliverable. We go inside — a real inventory of your code and infrastructure — and hand you a signed report you can put in front of your regulator.

We do not sell you cryptography. NIST already standardised it (FIPS 203/204/205); it is free and open-source. We sell the judgment, the mapping, and the plan — the three things that don't commoditise.

How it works

  1. 1.0

    Free external scan

    We look at your public endpoints from the outside; you get a gap snapshot by email.

  2. 2.0

    Scoped assessment

    You run our read-only scanner inside your perimeter — offline mode available. Nothing leaves your network but the report.

  3. 3.0

    Report and roadmap

    Cryptographic inventory, regulatory mapping, prioritised 36-month plan, board deck.

  4. 4.0

    Annual re-scan

    We track regulatory changes and re-issue the assessment as deadlines move.

Engagements

Every engagement is a fixed-scope project with a deliverable — sized to sit beside your existing compliance line items, closer to your annual pentest than to a consultancy retainer. Tell us what kind of institution you are and we will scope it: write to hello@kybermark.com →

This assessment helps you demonstrate readiness and address inventory and crypto-agility expectations. It is not a substitute for a formal audit, and the "Quantum Readiness Assessed" mark is an attestation by us — not an accredited certification.

Questions we actually get

Is the quantum threat even real yet?
The relevant date is not "when a large quantum computer exists" — it is today, because recorded traffic can be decrypted later. That is why the deadlines that matter are regulatory: DORA since January 2025, PCI DSS 12.3.3 since March 2025, NIST deprecation by 2030.
Do you see our data?
No. For the scoped assessment, the scanner runs inside your perimeter with an offline mode; only the report leaves. Think flashlight, not vacuum cleaner. The free scan never touches your infrastructure at all — it reads what your public endpoints already serve.
We already have SOC 2 — isn't crypto covered?
SOC 2 does not assess the quantum-readiness of your cryptographic inventory. It answers a different question.
What is a CBOM?
A Cryptographic Bill of Materials — an inventory of cryptographic assets in the open CycloneDX standard, maintained under the Linux Foundation.
Is this an accredited certification?
No — our mark is an attestation: our expert assessment, not an accredited certification. No accredited PQC-readiness certification scheme currently exists anywhere; we align with the frameworks as they form (X9, NIST/CISA CBOM guidance).