Your encryption has an expiration date. Do you know when?
Harvest-now-decrypt-later means traffic recorded today can be decrypted tomorrow. Regulators already require you to track the cryptography you run and to plan its migration. We put both on paper: an inventory, a regulatory mapping, and a roadmap, in the language your auditor works in.
The free scan reads only what your servers already show the public internet: TLS versions, key-exchange groups, cipher suites, and certificates. Findings arrive by email as a short gap snapshot, or read a sample first.
By requesting a scan you confirm you are authorised to have that domain assessed. We use your email for one purpose: delivering this snapshot and following up on it. No lists, no resale. Write to contact@kybermark.com to have your data deleted.
A compliance deadline, not a science-fiction risk
The dates that matter are not "when a large quantum computer exists". They are already on the regulatory calendar:
| PCI DSS 4.0.1 · req 12.3.3 | inventory of cipher suites and protocols, viability actively tracked | since 31 Mar 2025 |
|---|---|---|
| DORA · Art. 9(4)(d) + RTS | documented encryption policy, certificate register, and updating cryptography as cryptanalysis advances (RTS 2024/1774, Arts. 6–7) | since 17 Jan 2025 |
| FIPS 140-2 → Historical | every active FIPS 140-2 validation moves to Historical status | 21 Sep 2026 |
| NIST IR 8547 (draft) | RSA-2048 and ECC P-256 deprecated, then disallowed | 2030 / 2035 |
| G7 Cyber Expert Group | financial-sector PQC migration roadmap; your regulator has read it | Jan 2026 |
In a 2026 Entrust–Ponemon survey of 4,000 security leaders, 68% called cryptographic-asset management extremely difficult, and only 41% are actually preparing for migration. That gap between knowing and doing is the job we do.
What you get
-
A cryptographic inventory (CBOM)
Where you use encryption, which of it is quantum-vulnerable, and which of that protects long-lived data. Built on the open CycloneDX standard, so it stays useful after we leave.
-
Regulatory mapping
Every finding that requires action is tied to the clause that requires it (PCI DSS 12.3.3, DORA Art. 9(4)(d), NIST IR 8547), so your auditor sees exactly which requirement each gap answers to. Purely informational findings are labelled as such: we don't invent mandates.
-
A 36-month migration roadmap
Prioritised by harvest-now-decrypt-later exposure and regulatory deadline. What to fix first and what it takes, in board-ready language.
The honest middle
The big consultancies start at six figures. The overlay tools hand you a score and a false sense of safety. We sit between:
Against Big4, SandboxAQ, IBM Quantum Safe: built for enterprise, priced for enterprise. If you are a credit union or a fintech, you are not their customer. You are ours.
Against free scanners and readiness scores: a surface number is not an audit-ready deliverable. We go inside (a real inventory of your code and infrastructure) and hand you a signed report you can put in front of your regulator.
We do not sell you cryptography. NIST already standardised it (FIPS 203/204/205); it is free and open-source. We sell the judgment, the mapping, and the plan: the three things that don't commoditise.
How it works
-
1.0
Free external scan
We look at your public endpoints from the outside; you get a gap snapshot by email.
-
2.0
Scoped assessment
You run our read-only scanner inside your perimeter. Offline mode is available. Nothing leaves your network but the report.
-
3.0
Report and roadmap
Cryptographic inventory, regulatory mapping, prioritised 36-month plan, board deck.
-
4.0
Annual re-scan
We track regulatory changes and re-issue the assessment as deadlines move.
Engagements
-
free
External scan
Public TLS perimeter, gap snapshot by email.
-
fixed scope
Fintech assessment
Network-layer inventory, regulatory mapping, roadmap skeleton, one working session.
-
fixed scope
Bank · Insurer · Credit union
Full cryptographic inventory across code and infrastructure, mapping, prioritised roadmap, materials for your next exam.
-
recurring
Annual retainer
Yearly re-scan plus regulatory updates as mandates evolve.
Every engagement is a fixed-scope project with a deliverable, sized to sit beside your existing compliance line items, closer to your annual pentest than to a consultancy retainer. What the deliverable looks like: a sample Tier 1 report. Tell us what kind of institution you are and we will scope it: write to contact@kybermark.com →
This assessment helps you demonstrate readiness and address inventory and crypto-agility expectations. It is not a substitute for a formal audit, and the "Quantum Readiness Assessed" mark is an attestation by us, not an accredited certification.
Questions we actually get
- Is the quantum threat even real yet?
- The relevant date is not "when a large quantum computer exists". It is today, because recorded traffic can be decrypted later. That is why the deadlines that matter are regulatory: DORA since January 2025, PCI DSS 12.3.3 since March 2025, NIST deprecation by 2030.
- Do you see our data?
- No. For the scoped assessment, the scanner runs inside your perimeter with an offline mode; only the report leaves. Think flashlight, not vacuum cleaner. The free scan never touches your infrastructure at all. It reads what your public endpoints already serve.
- We already have SOC 2. Isn't crypto covered?
- SOC 2 does not assess the quantum-readiness of your cryptographic inventory. It answers a different question.
- What is a CBOM?
- A Cryptographic Bill of Materials: an inventory of cryptographic assets in the open CycloneDX standard, maintained under the Linux Foundation.
- Is this an accredited certification?
- No. Our mark is an attestation: our expert assessment, not an accredited certification. No accredited PQC-readiness certification scheme currently exists anywhere; we align with the frameworks as they form (X9, NIST/CISA CBOM guidance).