Quantum Readiness & Post-Quantum Cryptography

    Know Where Your Encryption Breaks — Before Someone Else Does

    Cryptographic discovery, risk assessment, and a phased migration roadmap to NIST post-quantum standards. Fixed-fee, senior-led, delivered by a cloud architect who has worked in regulated healthcare, finance, and government environments.

    Why now

    The migration has moved from theory to planning

    I focus on what is known today: approved standards, published transition requirements, and the cryptography already inside your estate.

    The standards are ready

    NIST released the first three finalized post-quantum cryptography standards in August 2024: FIPS 203, 204, and 205. Organisations now have concrete algorithms to migrate to.

    Source: NIST

    Federal requirements are accelerating

    Executive Order 14412, issued in June 2026, mandates accelerated government-wide PQC migration for US federal systems with binding deadlines and directs federal acquisition rules to require it. Vendors, service providers, and partners will be pulled into scope.

    Source: The White House

    Transition timelines are firm

    The NSA's CNSA 2.0 suite sets transition timelines for quantum-resistant algorithms in national security systems.

    Source: NSA

    Long-lived data is exposed now

    Harvest now, decrypt later means encrypted data captured today can be stored and decrypted once cryptographically relevant quantum computers exist. Data with a long confidentiality lifetime is already exposed to that risk.

    Source: CISA

    Inventory comes first

    Published migration guidance from NIST, CISA, and NSA starts with an inventory of cryptographic assets. Most organisations cannot yet answer where RSA and ECC are used across their systems.

    Source: NIST NCCoE

    What I deliver

    A practical path from discovery to migration

    Cryptographic Discovery & Inventory

    A structured audit of where public-key cryptography is used across your applications, infrastructure, APIs, certificates, and third-party integrations. You get a documented cryptographic asset inventory — the prerequisite for any migration plan and for answering auditor and regulator questions.

    • Cryptographic asset inventory across cloud and on-prem
    • Certificate and key management review
    • Third-party and vendor dependency mapping
    • Documented findings for audit and compliance

    Quantum Risk Assessment

    Not all data carries the same risk. I assess which systems and datasets have a long enough confidentiality lifetime to be genuinely exposed to harvest-now-decrypt-later, and prioritise accordingly — so you spend effort where it matters instead of everywhere at once.

    • Data confidentiality lifetime analysis
    • Exposure prioritisation by system
    • Regulatory and contractual obligation mapping
    • Risk register your board can read

    Migration Roadmap & Crypto-Agility

    A phased, costed roadmap to NIST-approved algorithms, designed around crypto-agility — separating application logic from the cryptographic provider so future algorithm changes don't require rewriting your software.

    • Phased migration plan aligned to NIST standards
    • Crypto-agility architecture design
    • Hybrid transition approach
    • Sequencing that fits your existing cloud roadmap

    Why me

    Architecture and compliance, grounded in delivery

    This is cryptographic architecture and compliance work, not quantum research. It needs someone who can read your infrastructure end to end, find the cryptography buried in it, and produce a plan your engineers and auditors both accept. I've spent 18+ years doing exactly that kind of work across AWS, Azure, and GCP — including Singapore government cloud (GCC) and regulated healthcare and finance environments where compliance evidence mattered as much as the architecture.

    My credentials include AWS Certified Solutions Architect – Professional, AWS Certified DevOps Engineer – Professional, Microsoft Certified: Azure Solutions Architect Expert, and PMP.

    The organisations facing this first are the ones holding data that must stay confidential for years — financial services, healthcare, and government. That is where I have spent most of my career.

    Start with a fixed-fee cryptographic discovery audit

    Known scope, known cost, written findings. No retainer to get started.