The Four Capabilities a PQC Program Needs
Most organizations don't need four post-quantum hires. They need four capabilities: discovery, architecture, implementation, and delivery. How those map to headcount depends on the…
Archive
Most organizations don't need four post-quantum hires. They need four capabilities: discovery, architecture, implementation, and delivery. How those map to headcount depends on the…
More than a dozen national authorities have published post-quantum deadlines. They agree on 2035 and disagree on almost everything before it. A field guide…
Most post-quantum programs stall on organizational arguments, not technical ones. The recurring objections come in three shapes, and each one can be answered without…
Germany expects hybrid key exchange. Australia expects pure ML-KEM. The US sets a date for dropping the classical half. What to build when the…
No quantum computer can break blockchain signatures today. The published migration deadlines still bind. Here is what to do without waiting for anyone.
A new output type, a signature algorithm choice, a fee-market renegotiation, and a multi-year UTXO sunset. The engineering pieces of Bitcoin's PQC migration, and…
One network, three cryptographic primitives, five layers, five different sets of owners. Ethereum as a worked example in reading a cryptographic inventory.
Export controls, investment screening, and diverging PQC standards have turned quantum sovereignty into a procurement question. The short version, for architects and buyers.
Most sovereignty tabletops end with the finding that the organisation would cope, because nobody defined coping first. A design guide for an exercise that…
Approved algorithm lists are the first of four axes on which national post-quantum requirements diverge. The other three are harder to abstract away.