Blogs
Blogs
Practical insights, industry perspectives and technical guidance on cryptographic exposure and quantum readiness.
All Articles
Practical insights, industry perspectives and technical guidance on cryptographic exposure and quantum readiness.
- All Posts
- ECEM
- Governance & Compliance
- Industry Perspectives
- Post-Quantum Risks
- PQC Discovery, Inventory & CBOM
- Standards

Five jurisdictions have now set post-quantum deadlines. Almost none of the first ones ask you to migrate anything - they...

Qatar's NIA Standard v2.1 removed its algorithm table and pointed to a separate national cryptographic standard instead. Good crypto-agility design...

OpenSSH 10.1 added a warning when your SSH session isn't using post-quantum key exchange. Here's what triggers it, what it...

PCI DSS 4.0's cryptographic inventory requirement became mandatory in March 2025. It isn't post-quantum guidance - but the inventory and...

NIST, FINMA and NCSC regulate different things, in different countries, with different levers - but strip away the enforcement mechanism...

The Cloud Security Alliance has named AI infrastructure a primary harvest-now-decrypt-later target. Model weights, training data and inter-agent traffic aren't...

CARAF and CAMM are two of the named frameworks organisations cite when discussing crypto-agility. Neither does what the other does,...

A CBOM isn't a separate standard invented for post-quantum readiness - it's a formal part of CycloneDX, the same SBOM...

Harvest now, decrypt later isn't a future scenario - it's a present one. Here's what the risk actually is, why...
Want Early Access to Our Research?
Get notified when new articles are published.