Crypto-debt command center that turns weak-cipher and PQC findings into owned fixes across hybrid application portfolios.
Large hybrid enterprises can now discover outdated protocols, weak cipher suites, and encryption gaps, but they still cannot turn that output into an owned remediation plan across hundreds of applications and teams. Security leaders know which business services are exposed, yet compliance teams, application owners, and platform teams still trade spreadsheets, tickets, and exception memos to decide what gets fixed first and when a safe change window exists.
Why now
- A $17 million seed round around quantum readiness shows enterprises are turning cryptographic modernization into a funded operating program, not a distant research project.
- Because discovery now spans on-premises, cloud, and hybrid environments, large enterprises can finally see the backlog; the urgent gap is converting that exposure map into fixes.
- The source explicitly centers CISOs, compliance teams, and application owners, which means the pain has become a cross-functional workflow that can support a new software layer.
- Policy alignment, continuous discovery, inventory, remediation, and governance point to a recurring operating-system opportunity rather than a one-time migration consulting project.
Catalyst. QIZ's financing and the explicit framing of quantum-safe migration as an urgent, long-lead remediation program show that discovery has matured and execution is now the blocking layer.
The idea
The product connects to cryptographic discovery tools, load balancers, API gateways, code repositories, certificate authorities, CMDBs, ServiceNow or Jira, and compliance systems to build a live graph of every finding, business service, owner, and dependency. Instead of a flat inventory, it groups outdated protocols, weak cipher suites, and encryption gaps into remediation waves based on business impact, shared infrastructure, and approved change windows. Each application owner gets an opinionated fix packet with affected endpoints, likely libraries or configs, rollback notes, and the evidence needed to request an exception or prove closure. Security leaders get one board-ready view of portfolio exposure, progress, blocked dependencies, and forecasted completion dates rather than weekly spreadsheet rollups. Over time, the platform learns which stacks, vendors, and teams remediate fastest, turning that workflow data into better sequencing, benchmarking, and eventually automated policy enforcement.
What's different. Incumbent PKI suites discover assets or automate issuance, while GRC systems track exceptions after someone else has translated technical debt into business work. This company owns the handoff between finding and fixing: it ties each cryptographic gap to a service owner, change window, remediation packet, and evidence trail. That creates a defensible dataset of dependency patterns, fix latency by stack, vendor responsiveness, and proven remediation playbooks that adjacent tools do not naturally collect.
| Beachhead | Fortune 500 industrial manufacturers with 200+ external partner, field-service, and customer applications across on-prem/cloud/hybrid estates, starting with TLS and cipher remediation on shared gateways, Java/.NET services, and vendor appliances. |
|---|---|
| Wedge | A cryptographic remediation OS that ingests findings from discovery tools, maps each weak protocol or cipher gap to the right business service and owner, sequences fixes by change window, and auto-builds audit and exception evidence. |
| Non-obvious insight | The immediate budget is not for a perfect future post-quantum stack; it is for the program layer that can translate discovered crypto debt into accountable, sequenced work across application owners, compliance, and infrastructure teams. Enterprises already have scanners and PKI tools, but they still lack a remediation operating system that answers who owns each fix, what it breaks, and how progress gets proven to leadership. |
| Venture-scale path | Start as the command center for one hybrid application portfolio, then expand into enterprise-wide cryptographic policy, vendor remediation, machine-identity lifecycle, release gating, and board reporting for every algorithm or certificate change. |
| Primary user | Director of cryptography modernization or deputy CISO at a Fortune 500 industrial manufacturer with 200+ customer, supplier, and field-service applications across on-prem, cloud, and private data-center environments. |
|---|---|
| Secondary user | Application security PMO lead or platform owner responsible for TLS, cipher-suite, and protocol remediation across shared gateways and internal services. |
| Economic buyer | CISO or CIO. |
| First customer | A publicly traded U.S. industrial manufacturer that just completed a cryptographic posture assessment, found weak cipher suites across its F5, Nginx, Java, and VPN estate, and promised the audit committee a quarterly remediation scorecard. |
|---|---|
| Buying trigger | A board or audit-committee request for a quantum-readiness plan after an assessment surfaces hundreds of outdated protocols, unknown owners, and shared infrastructure dependencies. |
| Current alternative | Scanner exports, Excel or ServiceNow backlogs, CMDB tagging, consulting-led program spreadsheets, and generic PKI or GRC dashboards. |
| Switching reason | The first customer switches because the product turns a scary but static inventory into an owner-assigned, sequence-aware remediation program that fits real change windows and produces evidence automatically. |
| Pricing hypothesis | Annual subscription priced by governed applications or business services, with premium tiers for automated owner mapping, vendor-remediation tracking, and board reporting. |
Jobs to be done
| Job | Current alternative | Success metric |
|---|---|---|
| When our audit committee asks for a quantum-readiness plan, help our cryptography program office assign and sequence fixes across hybrid applications, so they can reduce exposure without freezing releases. | Spreadsheet PMO, ServiceNow tickets, and manual owner-chasing. | Percentage of critical findings assigned to named owners and closed by the committed quarter. |
| When shared gateways or vendor appliances carry weak ciphers, help our application-security and platform teams prove which services are affected and what exceptions remain, so they can remediate before audit or outage risk compounds. | Flat scanner reports plus ad hoc engineering review. | Time to produce owner, business impact, and exception evidence for every critical finding. |
flowchart LR Buyer[Cryptography program lead] --> Pain[Known crypto debt has no clear owners or sequence] Pain --> Product[Crypto-debt command center] Product --> Outcome[Faster remediation with board-ready evidence]
- Signal · 5/5The category has fresh financing, explicit urgency, and a concrete workflow spanning discovery, remediation, and governance.
- Pain · 4/5The pain is severe for security leadership, but some enterprises may still try to muscle through with consultants and spreadsheets until deadlines tighten.
- Wedge · 5/5One hybrid application portfolio with known weak ciphers and owner ambiguity is a precise first workflow with obvious ROI.
- Defense · 4/5Ownership graphs, fix-latency data, and proven remediation playbooks create sticky workflow intelligence, though large security vendors can respond.
- Scale · 5/5The beachhead expands naturally into enterprise-wide cryptographic policy, vendor remediation, machine identity, and change control.
- Cryptographic discovery and certificate-management vendors
- Cyber advisory firms running quantum-readiness assessments
- Enterprise ticketing, CMDB, and observability platforms
- Normalizing cryptographic findings and mapping ownership
- Sequencing remediation waves and tracking closure
- Producing audit, exception, and leadership reporting
- Cross-system graph of findings, owners, business services, and dependencies
- Remediation sequencing engine and exception-evidence workflow
- Connectors into discovery tools, ticketing systems, CMDBs, repos, and PKI infrastructure
- Turn cryptographic findings into owner-assigned remediation waves instead of static inventories
- Prioritize weak protocols and cipher gaps by business impact and change-window reality
- Generate board, audit, and exception evidence automatically as fixes progress
- High-touch first portfolio rollout with weekly remediation-program reviews
- Quarterly exposure and progress reporting for security leadership and auditors
- Expansion from one application portfolio into more business units and vendor estates
- Direct enterprise sales to CISO, CIO, and infrastructure-transformation leaders
- Design-partner launches tied to one completed cryptographic posture assessment
- Partnerships with discovery vendors, cyber consultancies, and systems integrators
- Fortune 500 industrial manufacturers with hybrid application estates
- Central cryptography or application-security PMOs running quantum-readiness programs
- Infrastructure and platform teams responsible for shared gateways, VPNs, and service frameworks
- Integration and graph-model engineering
- Enterprise implementation and customer success
- Direct sales and partner enablement
- Annual platform subscription
- Usage tiers based on governed applications or business services
- Premium modules for automated owner mapping, vendor tracking, and board reporting
Market
| TAM | $0.9B Estimate: roughly 2,500 global large enterprises and critical-infrastructure operators with complex hybrid estates x about $350k annual remediation-program ACV = about $875M, cross-checked against broader machine-identity, managed-encryption, and PQC market forecasts. |
|---|---|
| SAM | $90.0M Estimate: roughly 180 Fortune-500-scale industrial, energy, telecom, and critical-infrastructure logos in the initial US/EU beachhead x about $500k first-program ACV = about $90M. |
| SOM | $4.8M Estimate: 12 year-3 logos x about $400k blended ACV after landing one hybrid application portfolio and expanding to adjacent gateways and services in the same account. |
Executive takeaways
- The wedge is real, but only if the startup sells remediation execution and audit evidence rather than another discovery dashboard.
- QIZ is the closest direct competitor, so differentiation must center on owner resolution, change-window sequencing, and exception packetization for one application portfolio.
- Regulatory timelines and certificate-lifecycle pressure make the problem immediate; a vague Q-Day story alone is not enough to win budget.
- The technical building blocks already exist across cloud providers and legacy TLS stacks, but the implementation burden is fragmented enough to justify a dedicated orchestration layer.
Market definition
The relevant market is cryptographic remediation program software: a control layer that turns crypto inventory, weak protocol findings, and PQC readiness gaps into owner-assigned, sequence-aware change plans across hybrid enterprise applications.
Customer and buyer
The day-to-day champion is a cryptography modernization leader or application-security PMO inside a Fortune 500-style industrial manufacturer with many shared gateways, Java/.NET services, and vendor appliances. The economic buyer is usually the CISO or CIO, with an audit committee or board request creating urgency.
Buying triggers
- A posture assessment or audit surfaces weak ciphers, outdated protocols, and unclear ownership, forcing the security team to turn inventory into an owned remediation plan. [88][89][90][95]
- Government and standards guidance now expects inventory, prioritization, vendor engagement, and migration roadmaps rather than one-time awareness exercises. [15][16][17][99][98]
- Shorter certificate lifetimes and machine identity sprawl make manual spreadsheet and ticket-based programs too brittle to defend in front of auditors or business owners. [19][34][91][10]
- Cloud and runtime vendors are shipping PQC and TLS building blocks now, which pushes application and platform teams to coordinate real stack-level change windows instead of treating PQC as distant research. [100][101][102][103][104][105][106]
Willingness to pay
Willingness to pay is credible because spend can attach to existing trust-infrastructure, certificate lifecycle, and quantum-readiness budgets. QIZ's seed, Keyfactor's $1B+ raise, CyberArk's Venafi acquisition, DigiCert's PQC-capable lifecycle tooling, and AppViewX's explicit PQC and 47-day packaging all show buyers are already funding adjacent control layers. [1][5][7][9][10][88]
Category dynamics
Tailwinds
- Standards and official migration guidance have moved from theory into concrete inventory and roadmap work.
- Funding and consolidation validate that trust-infrastructure and crypto-agility budgets are already forming around this problem.
- Cloud providers and runtime stacks now expose enough PQC and TLS controls to make stack-by-stack remediation a current engineering task.
Headwinds
- Well-funded incumbents already market adjacent discovery, lifecycle, and governance capabilities.
- Legacy stack diversity across F5, NGINX, Java, .NET, and OpenSSL increases integration burden and slows first value if onboarding is not opinionated.
Validation signals
- QIZ's $17M seed round validates that cryptographic posture and remediation have become a fundable operating program, not just a consulting narrative.
- Keyfactor's $1B+ investment and CyberArk's Venafi acquisition show adjacent trust-infrastructure categories are already strategic at scale.
- Sectigo reports that 92% of organizations expect to increase PQC investment within 2-3 years while only 14% have fully assessed quantum-vulnerable systems.
- NIST, CISA, OMB, and the NCSC now describe migration as a discovery, planning, and execution program with specific milestones and inventories.
Regulatory & technical constraints
- A credible migration program must inventory algorithms, protocols, certificates, libraries, and long-lived dependencies before prioritizing remediation.
- Provider support differs across hybrid TLS, KMS, CA, and signature layers, so migration waves must be staged by stack compatibility rather than declared globally.
- Legacy gateways, proxies, runtimes, and libraries expose TLS and cipher controls in different places, which raises the blast radius of any shared-infrastructure change.
Competition
Competition is dense across CLM, machine identity, cryptographic posture management, and emerging PQC programs. QIZ is the nearest direct fit, while Keyfactor, CyberArk/Venafi, AppViewX, DigiCert, and SandboxAQ all cover adjacent discovery, lifecycle, or analytics layers. The defensible gap is a portfolio-level remediation OS that translates findings into named owners, change windows, exceptions, and board-ready evidence.
| Competitor | Stage | Wedge | Pricing | Strength | Weakness vs. us |
|---|---|---|---|---|---|
| QIZ Security | seed | Cryptographic posture and PQC management across hybrid enterprise environments with API-based discovery and prioritization. | Custom / enterprise | Closest direct fit to the problem statement, with explicit positioning around hybrid discovery, prioritization, and cross-team collaboration. | More naturally framed as a posture-management platform; the startup can be narrower and more opinionated on service-owner assignment, change windows, and exception evidence. |
| Keyfactor | scale-up | Trust control plane spanning discovery, issuance, lifecycle automation, and quantum-safe cryptography across enterprise trust infrastructure. | Custom / enterprise | Large installed base and strong trust-infrastructure narrative, backed by major capital and a broad machine-identity footprint. | Broad platform scope makes it less opinionated around one portfolio’s remediation waves, blocked dependencies, and board-ready closure packets. |
| SandboxAQ | scale-up | Cryptographic risk AI platform that discovers assets, maps blast radius, and pushes machine-speed remediation for cryptographic exposure. | Custom / enterprise | Strong cryptographic analytics and risk-mapping story, especially for hidden assets and blast-radius analysis. | Closer to exposure analysis than to application-PMO style sequencing, exception handling, and cross-functional execution. |
| AppViewX | scale-up | Certificate lifecycle and PQC readiness platform with explicit packaging for crypto-agility, scorecards, and 47-day certificate operations. | Custom / enterprise | Strong CLM roots, explicit PQC messaging, and credible automation story around shrinking certificate lifetimes. | Still centered on CLM and PKI administration rather than business-service-level remediation ownership and sequencing across mixed stacks. |
| CyberArk / Venafi | incumbent | Machine identity security spanning secrets, certificates, workload identities, and zero-touch PKI. | Custom / enterprise | Massive incumbent footprint and broad coverage across machine identity primitives, acquisition-backed scale, and buyer familiarity. | Buyer mental model is still platform-wide identity control, not a remediation OS for one crypto backlog with owner-specific fix packets and change windows. |
Why incumbents do not win by default
- Machine identity and CLM suites. Keyfactor, CyberArk/Venafi, DigiCert, and AppViewX already own discovery, issuance, and lifecycle automation, but their center of gravity is broad trust administration rather than application-portfolio sequencing and exception evidence.
- Cryptographic posture and PQC platforms. QIZ, SandboxAQ, and adjacent quantum-safe vendors can discover assets and score risk, but they are not obviously positioned as the operator-facing system for change-window planning, owner assignment, and audit packetization across one portfolio.
- Cloud and runtime platforms. AWS, Google Cloud, Cloudflare, and core runtime stacks expose the primitives for PQC and TLS modernization, but they do not solve cross-estate owner mapping across gateways, Java, .NET, NGINX, and appliances.
- In-house PMO and ticketing. Enterprises can continue with spreadsheets, backlog queues, and change boards, but inventory gaps, certificate sprawl, and audit pressure make those manual workflows increasingly hard to defend or scale.
Business plan
Crypto Debt Command Center should start as the remediation operating system for Fortune 500 industrial manufacturers that already know they have weak protocols and cipher debt but cannot turn scanner output into owned fixes across hybrid application portfolios. The immediate buyer pain is not abstract quantum risk; it is the audit-committee promise to show quarterly progress after a posture assessment reveals hundreds of findings across F5, NGINX, Java, .NET, and vendor appliances. The product should sit on top of existing discovery, CLM, ticketing, and CMDB tools, then map each finding to a service owner, change window, and evidence packet rather than trying to replace incumbent PKI or posture platforms. That wedge is attractive because shared-gateway and legacy-stack remediation produces visible backlog, cross-functional coordination pain, and board-facing reporting requirements before broader machine-identity or policy-enforcement expansion. Research-backed sizing supports an estimated $0.9B TAM, $90.0M beachhead SAM, and $4.8M year-3 SOM if the company stays disciplined on large industrial and critical-infrastructure accounts instead of selling horizontally too early. The strongest reason to engage is that regulation, vendor guidance, and recent financing around cryptographic posture management all suggest enterprises are already budgeting for the program layer around quantum readiness. The biggest reason for caution is that QIZ, Keyfactor, Venafi, AppViewX, and consulting-led PMOs already sit adjacent to the workflow, so the startup must prove faster owner resolution, change-window sequencing, and audit evidence than those alternatives. One material evidence gap remains: the inputs do not establish standalone pricing benchmarks or how often triggered buyers will fund software instead of extending incumbent suites, so the first year must prove paid pilot conversion into durable annual contracts.
Problem
- Large hybrid enterprises can now discover weak protocols, outdated cipher suites, and encryption gaps, but they still cannot assign accountable owners and sequence fixes across hundreds of applications, shared gateways, and vendor appliances.
- Board, audit, and regulatory pressure now requires quarterly remediation progress, exception evidence, and vendor engagement, yet most programs still run through spreadsheets, ServiceNow queues, and consulting PMOs that do not prove closure.
Solution
- Ingest findings from discovery, CLM, gateway, certificate, CMDB, repo, and ticketing systems into one graph that maps each cryptographic issue to the affected business service, likely owner, dependency chain, and approved change window.
- Turn that graph into remediation waves, owner-specific fix packets, exception packets, and board-ready scorecards for TLS and cipher backlog first, then expand into broader crypto-agility governance after one portfolio is working.
Why we win
- Incumbent CLM, PKI, and posture products mostly stop at discovery, issuance, or high-level reporting; the startup is narrower and more opinionated on owner resolution, change-window sequencing, and proof of closure for one application portfolio.
- Each deployment compounds a proprietary dataset of ownership links, stack-specific remediation playbooks, vendor response patterns, and closure benchmarks that make onboarding faster and the reporting layer harder to replace.
| Beachhead | Publicly traded U.S. industrial manufacturers with 200+ hybrid customer, supplier, and field-service applications that just completed a cryptographic posture assessment and now owe the board a quarterly remediation scorecard. |
|---|---|
| Wedge rationale | This slice creates faster proof than a broad PQC platform because the backlog already exists, shared gateways create visible blast radius, and the buyer has a dated reporting obligation. Selling horizontally into generic cyber teams would produce weaker triggers, fuzzier budgets, and more direct overlap with incumbent CLM or posture suites. |
| Sequencing | Start as an orchestration layer behind existing discovery and CLM tools so deployment can begin with imported findings instead of a rip-and-replace. Build owner mapping, remediation waves, and exception evidence before automated policy enforcement; keep founder-led sales and a solutions-heavy deployment motion until two or three portfolios prove repeatable conversion, then add partner channels and broader governance modules. |
| Not yet | Replacing certificate authorities, CLM suites, or cryptographic discovery infrastructure · Selling to smaller enterprises or single-cloud software teams without hybrid legacy estates · Managing every post-quantum algorithm migration workflow before the TLS and cipher backlog wedge converts reliably · Inline release blocking or autonomous policy enforcement before customers trust the ownership graph and remediation packets |
| Wedge | Sell a 90-day remediation-program deployment to a manufacturer that already has assessment findings and a board-mandated quarterly scorecard, then use existing scanner output to assign owners and sequence TLS and cipher fixes on one governed portfolio. |
|---|---|
| Channels | Founder-led direct sales to deputy CISOs, cryptography modernization leads, and application-security PMOs immediately after posture assessments · Design-partner deals tied to one completed cryptographic assessment and one board or audit remediation commitment · Referral and co-sell partnerships with discovery or CLM vendors and advisory firms that create the backlog but do not own the remediation workflow |
| Funnel targets | Target account→qualified discovery 15-25%, qualified discovery→paid pilot 25-35%, paid pilot→annual production 50%+, production→second portfolio or business unit 40%+ within 12 months. |
| Pricing | Lead with an 8-12 week paid pilot at roughly $75k-$150k for one governed portfolio, creditable toward a $250k-$500k annual subscription priced by governed applications or business services, with premium modules for automated owner mapping, vendor tracking, and board reporting. This fits the buyer's budget logic because they are purchasing closure velocity and audit evidence for a known backlog, not seats or raw scan data. |
| MVP | The MVP should ingest one discovery feed plus gateway, CMDB, repo, and ticketing data; infer likely service owners; group critical findings into remediation waves; and generate fix packets, exception packets, and a quarterly scorecard for one governed application portfolio. It should use lightweight human confirmation for first-wave owner mapping rather than promise fully automated enforcement. |
|---|---|
| 6 months | Deploy 2-3 design-partner pilots on one portfolio each, covering data ingestion, owner confirmation, remediation-wave planning, exception workflow, and first board-ready reporting. |
| 12 months | Convert at least 2 pilots into annual subscriptions, add production connectors for major CLM and ticketing systems, and ship stack-specific playbooks for F5, NGINX, Java, and .NET remediation. |
| 24 months | Expand from one portfolio into enterprise-wide cryptographic policy, vendor-remediation tracking, change-window forecasting, and release-gating workflows across multiple business units. |
| Key bets | CMDB, repo, certificate, and ticket data are sufficient to reach usable owner-mapping accuracy with lightweight human confirmation. · Board-ready scorecards and exception packets are budget-worthy outcomes, not just reporting polish. · Starting with TLS and cipher backlog on shared gateways and common runtimes produces faster proof than leading with a broad PQC migration platform. · Discovery vendors, CLM suites, and advisory firms will integrate and refer opportunities instead of blocking the startup outright. |
| Revenue streams | Annual platform subscription for remediation workflow across governed applications or business services · Premium modules for automated owner mapping, vendor-remediation tracking, and board reporting · Limited onboarding and integration services for first-portfolio deployment |
|---|---|
| Unit of value | Governed applications or business services under active cryptographic remediation management |
| Target gross margin | 70% |
| Expansion levers | Expand from one hybrid application portfolio to additional business units inside the same enterprise · Add vendor-appliance remediation, exception management, and change-window forecasting once the core workflow is trusted · Extend from TLS and cipher backlog into broader crypto-agility, machine-identity, and release-gating programs |
| North-star metric | Percent of critical cryptographic findings in governed portfolios that are assigned to named owners and closed or formally excepted by the committed quarter. |
|---|---|
| Input metrics | Time from imported finding to named owner assignment · Percent of critical findings grouped into an approved remediation wave within 30 days · Owner-assignment accuracy after first-wave human confirmation · Paid pilot to annual production conversion rate · Quarterly scorecards delivered without manual spreadsheet consolidation · Percent of customers expanding from one portfolio to a second portfolio or business unit |
| Moats to build | Cross-system graph of findings, services, owners, gateways, certificates, and dependencies · Fix-latency and change-window benchmarks by stack, vendor, and team · Exception packets and audit history tied to regulatory milestones and board commitments |
| Kill criteria | If fewer than 3 of the first 10 qualified, triggered ICP accounts agree to a paid pilot, the beachhead trigger is too weak. · If first-wave owner assignment accuracy stays below 70% before human review and below 85% after confirmation, the product is too services-heavy. · If the first 3 pilots cannot cut quarterly reporting and exception-preparation labor by at least 50% or fail to convert 1 account to annual production, revisit the wedge. |
Milestones
- Land 2-3 design partners in industrial manufacturing with completed cryptographic posture assessments.
- Ship MVP ingestion, owner confirmation, remediation-wave planning, and quarterly scorecard workflow for one governed portfolio.
- Prove at least 85% owner-assignment accuracy after first-wave confirmation and a measurable reduction in manual reporting effort.
- Convert at least 1 pilot into an annual subscription and capture a referenceable before-and-after operating case study.
- Expand first customers from one portfolio to additional gateways, business units, or vendor estates.
- Ship stack-specific playbooks, vendor-remediation tracking, and change-window forecasting.
- Establish repeat referral motion with at least one discovery or CLM vendor and one advisory partner.
- Reach 8-12 paying logos while keeping deployments product-led rather than services-led.
- Extend from TLS and cipher backlog into machine-identity, release-gating, and broader crypto-agility governance workflows.
- Become the system of record for cryptographic exceptions and board reporting across multi-business-unit enterprise accounts.
- Use remediation telemetry to benchmark closure rates by stack, vendor, and team and support higher-value enterprise tiers.
flowchart LR Wedge[Industrial remediation wedge] --> MVP[Owner mapping and remediation waves] MVP --> Proof[Board-ready closure proof] Proof --> Expansion[Enterprise crypto governance expansion]
Founding team
| Role | Start timing | Rationale |
|---|---|---|
| Founder/CEO | Month 0 | Founder-led sales and partner development are required early because the buyer is senior, the trigger is situational, and the wedge must be positioned against incumbents precisely. |
| Founding eng | Month 0 | The first technical moat is the graph linking findings, owners, dependencies, and change windows across heterogeneous systems. |
| Platform/integration engineer | Month 3 | Connector depth across gateways, CLM, CMDB, and ticketing determines time-to-value and whether deployments stay product-led. |
| Solutions engineer | Month 3 | Enterprise pilots need someone who can instrument data sources, validate owner mapping, and capture measurable before-and-after workflow metrics. |
| Product/security PM | Month 6 | The roadmap must codify remediation packets, exception workflow, and regulatory reporting patterns into repeatable product templates. |
| Enterprise seller | Month 12 | Only hire a dedicated seller after at least one pilot converts, so the motion scales on a proven ICP and packaging rather than expensive experimentation. |
Experiment roadmap
| Horizon | Experiment | Hypothesis | Success metric | Owner |
|---|---|---|---|---|
| 0–90 days | Interview 12-15 deputy CISOs, cryptography leaders, and application-security PMO owners at manufacturers that recently completed a posture assessment. | The immediate budget trigger is a board or audit remediation commitment, not generic curiosity about PQC. | At least 8 interviews reference a dated reporting obligation and at least 3 agree to scope a paid pilot. | Founder/CEO |
| 0–90 days | Build a concierge owner-mapping report using sample gateway, CMDB, repo, certificate, and ticket data from one design partner. | Multi-source enrichment can infer enough ownership to make software-led remediation waves credible. | At least 70% of critical findings receive a probable owner before human review and at least 85% after confirmation. | Founding eng |
| 0–90 days | Prototype a quarterly scorecard and exception packet workflow for one board-facing remediation program. | Reporting and evidence automation is a budget-worthy outcome alongside owner assignment. | One design partner uses the output in a real steering committee or audit-prep meeting. | Product/security PM |
| 90–180 days | Run 2 paid pilots covering one governed portfolio each with remediation waves, owner confirmation, and exception management. | A one-portfolio deployment can show enough closure and reporting value to justify annual production. | At least 2 pilots go live and at least 1 converts to an annual subscription or signed expansion commitment. | Solutions engineer |
| 90–180 days | Launch one referral motion with a discovery or CLM vendor and one advisory firm that performs quantum-readiness assessments. | Upstream ecosystem partners can source warmer leads than broad outbound selling. | At least 3 qualified opportunities originate through partner introductions. | Founder/CEO |
| 180–360 days | Ship stack-specific remediation playbooks and vendor-tracking workflow for F5, NGINX, Java, and .NET-heavy accounts. | Opinionated templates improve time-to-value enough to support account expansion and healthier gross margins. | Pilot customers using templates close critical findings at least 25% faster or expand to a second portfolio. | Platform/integration engineer |
Risk assessment
- R1QIZ or large CLM and machine-identity incumbents bundle enough remediation workflow to erase differentiation. — Win on faster portfolio onboarding, neutral integrations, owner-specific fix packets, and audit evidence that incumbents do not package cleanly today.
- R2Stale or incomplete ownership data makes automatic assignment too inaccurate for software-first deployment. — Blend CMDB data with repo, certificate, gateway, and ticket signals, require lightweight human confirmation on wave one, and use pilot history to improve future mapping.
- R3Buyers frame the need as temporary consulting or compliance PMO work instead of a recurring software category. — Sell against dated quarterly scorecards, measure reporting labor reduction and closure velocity, and use paid pilots to prove repeatable software outcomes.
- R4Legacy heterogeneity across F5, NGINX, Java, .NET, and vendor appliances turns onboarding into a custom integration project. — Constrain the first wedge to common stacks, ship opinionated playbooks, and hire solutions and integration talent before broadening connector breadth.
| Risk | Likelihood | Impact | Mitigation |
|---|---|---|---|
| QIZ or large CLM and machine-identity incumbents bundle enough remediation workflow to erase differentiation. | Medium | High | Win on faster portfolio onboarding, neutral integrations, owner-specific fix packets, and audit evidence that incumbents do not package cleanly today. |
| Stale or incomplete ownership data makes automatic assignment too inaccurate for software-first deployment. | High | High | Blend CMDB data with repo, certificate, gateway, and ticket signals, require lightweight human confirmation on wave one, and use pilot history to improve future mapping. |
| Buyers frame the need as temporary consulting or compliance PMO work instead of a recurring software category. | Medium | High | Sell against dated quarterly scorecards, measure reporting labor reduction and closure velocity, and use paid pilots to prove repeatable software outcomes. |
| Legacy heterogeneity across F5, NGINX, Java, .NET, and vendor appliances turns onboarding into a custom integration project. | High | Medium | Constrain the first wedge to common stacks, ship opinionated playbooks, and hire solutions and integration talent before broadening connector breadth. |
| Title | Deputy CISO for cryptography modernization at a Fortune 500 industrial manufacturer |
|---|---|
| Profile | A publicly traded U.S. industrial manufacturer with 200+ hybrid customer, supplier, and field-service applications, recent assessment findings across F5, NGINX, Java, .NET, and vendor appliances, and an audit-committee remediation commitment. |
| Trigger | A posture assessment or audit committee review exposes hundreds of weak-cipher or outdated-protocol findings with unclear owners and a promised quarterly scorecard. |
| Buyer | CISO or CIO |
| Initial contract | An 8-12 week paid pilot for one governed application portfolio at roughly $75k-$150k, creditable toward a $250k-$500k annual subscription if the team can assign owners, build remediation waves, and deliver the first board-ready scorecard. |
What must be true
- At least 3 of the first 10 qualified triggered ICP accounts will pay for a portfolio deployment instead of defaulting to consultants plus spreadsheets.
- The product can map at least 70% of critical findings to a probable service owner before human review and exceed 85% after first-wave confirmation.
- One pilot can cut quarterly status-reporting and exception-preparation labor by at least 50% within 90 days.
- At least half of paid pilots convert from one-portfolio deployment to a $250k+ annual subscription anchored on governed applications or business services.
- Incumbent CLM or posture vendors will not win most early deals once the workflow is framed as remediation execution rather than raw inventory.
Open diligence questions
- How often does the buyer already own Keyfactor, Venafi, AppViewX, or QIZ, and why is that stack still insufficient?
- What data sources are actually available in the first 30 days for owner mapping: CMDB, certificate, gateway, repo, ticketing, or all of the above?
- Who owns the first budget line in practice: the CISO, CIO, application-security PMO, or a transformation office?
- What proof actually unlocks annual conversion: closure velocity, audit evidence, vendor tracking, or board reporting?
- How much solutions-engineering effort is required per portfolio before gross margins fall below software economics?
| Call | Meet / investigate further |
|---|---|
| Conviction | Promising cybersecurity workflow wedge with real timing, but conviction depends on proving that owner resolution and change-window sequencing create a distinct budget before incumbents bundle it. |
| Why believe | Assessments, regulatory guidance, and board scorecard commitments create a concrete remediation program that existing discovery and CLM tools do not clearly own end to end. |
| Why doubt | QIZ and large trust-infrastructure vendors already sit close to this workflow, so weak differentiation or services-heavy deployment could compress the company into a feature or consulting layer. |
| Next diligence | Confirm that 2-3 triggered industrial logos will pay for a one-portfolio deployment and that at least 1 converts into a $250k+ annual subscription after measurable reporting and closure gains. |
Financial model
| Year 1 revenue | $443K EBITDA $-991K · Cash EOP $2.01M |
|---|---|
| Year 2 revenue | $2.54M EBITDA $-644K · Cash EOP $1.36M |
| Year 3 revenue | $4.72M EBITDA $21K · Cash EOP $1.39M |
| ARPU (annual) | $400K |
|---|---|
| Gross margin | 70% |
| CAC | $141K Payback 6.0 months |
| LTV / CAC | 11.0x LTV $1.56M |
| Round | seed · $3.0M |
|---|---|
| Runway | 18 months |
| Milestone | Reach 8 paying logos, prove at least 2 referenceable annual conversions, and establish a repeatable partner-assisted remediation workflow with six months of cash buffer. |
Model sanity
- Revenue engine. Base-case revenue comes from 12 paying logos by Q4Y3, with each moving from roughly $105K pilots into roughly $390K production ARR and then expansion modules inside the same account.
- Must go right. The company has to keep deployments product-led enough for gross margin to climb from pilot-heavy mid-50s in late Y1 to about 70% by late Y3.
- Model breaks if. If sales cycles slip toward 9-10 months and mature ACV stalls near $480K, downside cash falls below $0.2M before the business reaches scaled software economics.
- Next-round proof. The next financing is justified when Q4Y2 shows 8 paying logos, 2 referenceable annual conversions, and partner-sourced pipeline that supports Y3 growth without a services-heavy burn profile.
- Revenue (line, area)
- Cash EOP (dashed)
- EBITDA (bars, gray = loss)
- Founder / CEO
- Engineering
- Platform / Integrations
- Solutions / Customer Success
- Product / Security PM
- Sales
- G&A / Ops
| Y3 revenue | Y3 EBITDA | Cash low point | Description | |
|---|---|---|---|---|
| Downside | Enterprise procurement slips, mature ACV lands lower, and delivery stays more services-heavy, so the company reaches Y3 scale later and with weaker software economics. | |||
| Base | Base case follows the BP path of three paying logos by M12, eight by Q4Y2, and twelve by Q4Y3 while gross margin only reaches the BP target in late Y3. | |||
| Upside | Partner referrals and earlier reference wins pull starts forward, support firmer pricing, and let the company reach solidly positive EBITDA inside Y3. |
| Variable | Downside | Upside | Cash impact | Revenue impact |
|---|---|---|---|---|
| sales cycle | Median cycle extends toward 9-10 months. | Reference wins compress new cycles toward 5-6 months. | ||
| ARPU | Production ARR lands at $360K and mature expansion at $480K. | Production ARR $420K and mature expansion $540K. | ||
| gross margin | Exit gross margin reaches only 68%. | Exit gross margin reaches 73%. | ||
| CAC | CAC rises to about $180K because partner referrals do not materialize. | CAC falls toward $120K once reference logos and partners warm the pipeline. | ||
| hiring pace | A second seller and later engineering hires are pulled forward before partner proof. | One late-stage hire is deferred until after the tenth paying logo. | ||
| churn | Monthly churn drifts to 2.5% as pilots do not expand cleanly. | Monthly churn improves to 1.0% with deeper workflow embed. |
Scenarios
| Scenario | Y3 revenue | Y3 EBITDA | Cash low point | Description | Key changes |
|---|---|---|---|---|---|
| Downside | $3.89M | $-678K | $198K | Enterprise procurement slips, mature ACV lands lower, and delivery stays more services-heavy, so the company reaches Y3 scale later and with weaker software economics. |
|
| Base | $4.72M | $21K | $1.29M | Base case follows the BP path of three paying logos by M12, eight by Q4Y2, and twelve by Q4Y3 while gross margin only reaches the BP target in late Y3. |
|
| Upside | $5.33M | $540K | $1.81M | Partner referrals and earlier reference wins pull starts forward, support firmer pricing, and let the company reach solidly positive EBITDA inside Y3. |
|
Sensitivity
| Variable | Downside | Base | Upside |
|---|---|---|---|
| ARPU | Production ARR lands at $360K and mature expansion at $480K. | Production ARR $390K and mature expansion $510K. | Production ARR $420K and mature expansion $540K. |
| CAC | CAC rises to about $180K because partner referrals do not materialize. | CAC holds near $141K per logo. | CAC falls toward $120K once reference logos and partners warm the pipeline. |
| churn | Monthly churn drifts to 2.5% as pilots do not expand cleanly. | Monthly churn remains 1.5%. | Monthly churn improves to 1.0% with deeper workflow embed. |
| sales cycle | Median cycle extends toward 9-10 months. | Triggered sales cycles stay in the 6-9 month range. | Reference wins compress new cycles toward 5-6 months. |
| gross margin | Exit gross margin reaches only 68%. | Gross margin exits at 71% with a long-run 70% unit-economics target. | Exit gross margin reaches 73%. |
| hiring pace | A second seller and later engineering hires are pulled forward before partner proof. | Hiring stays milestone-gated until logo and margin proof appear. | One late-stage hire is deferred until after the tenth paying logo. |
Key assumptions (28)
| ID | Name | Value | Unit | Source |
|---|---|---|---|---|
| A1 | Model start month | 2026-08 | YYYY-MM | [BP date 2026-07-10] the model begins in the first full month after the dated business plan. |
| A2 | Opening cash / seed raise | $3.0M | USD | [BP fundingAsk targetFundingRangeUsd $3–5M + model cash curve] the base case uses the low end of the stated seed range because hiring is milestone-gated and the company nears EBITDA breakeven in Y3. |
| A3 | Starting paying logos | 0 | count | [BP executiveSummary + BP milestones 0–12 months] the company starts pre-revenue and must first land paid pilots. |
| A4 | Customer definition | One active paying enterprise logo in a pilot or annual production deployment | definition | [BP gtm.pricing + BP market.som] customersEop counts paying logos, while within-logo expansion raises ARPU over time. |
| A5 | Paid pilot economics | $105K over roughly 3 months (~$35K/mo) | USD/logo | [BP gtm.pricing $75k-$150k for 8-12 weeks] the model uses a near-midpoint pilot package. |
| A6 | Initial production contract | $390K ARR (~$32.5K/mo) | USD/logo/year | [BP gtm.pricing $250k-$500k annual subscription + Research market.sam roughly $500K first-program ACV] the base case lands below the research ACV anchor until proof and modules accumulate. |
| A7 | Expanded mature contract | $510K ARR (~$42.5K/mo) | USD/logo/year | [BP gtm.pricing + BP businessModel expansion levers + Research market.som roughly $400K blended ACV] mature logos expand above the base subscription through a second portfolio and premium modules, while the overall Y3 blend stays near the research anchor. |
| A8 | Customer start schedule | M6, M9, M11, M13, M15, M18, M20, M22, M26, M29, M32, M35 | month index | [BP product sixMonth/twelveMonth + BP milestones + Research market.som 12 reachable logos] the base case reaches 3 paying logos by M12, 8 by Q4Y2, and 12 by Q4Y3. |
| A9 | Gross margin ramp | 48% early pilots, 55% late Y1, 58-68% through Y2, and 69-71% through Y3 | gross margin percent | [BP businessModel.targetGrossMarginPct 70 + BP strategicChoices sequencingRationale + BP risks on services-heavy onboarding] margin improves as connectors and remediation playbooks reduce bespoke delivery work. |
| A10 | Enterprise sales-cycle anchor | 6-9 months with pilot-to-annual conversion at or above the BP 50% floor | months / conversion | [BP market.buyingProcess + BP gtm.funnelTargets] the logo-start schedule assumes triggered accounts with completed posture assessments and board pressure. |
| A11 | Hiring timeline | M1 founder and founding eng; M4 platform and solutions; M7 product/security PM; M13 seller; M16 platform 2; M18 solutions 2; M20 eng 2; M24 ops; M27 eng 3; M30 seller 2; M32 eng 4 | timeline | [BP team + BP strategicChoices.sequencingRationale + startup-finance heuristic] hiring stays behind revenue proof and partner-motion proof. |
| A12 | Founder loaded compensation | $180.0K | USD/year | [BP team Founder/CEO + startup-finance heuristic] lean founder cash compensation with taxes and benefits included. |
| A13 | Engineering loaded compensation | $210.0K per FTE | USD/year | [BP team Founding eng + startup-finance heuristic] reflects senior graph, workflow, and infrastructure engineering talent. |
| A14 | Platform / integrations loaded compensation | $195.0K per FTE | USD/year | [BP team Platform/integration engineer + startup-finance heuristic] the role must own F5, NGINX, CLM, CMDB, and ticketing connectors. |
| A15 | Solutions / customer success loaded compensation | $175.0K per FTE | USD/year | [BP team Solutions engineer + startup-finance heuristic] enterprise pilots need technical deployment ownership without assuming partner-level consulting rates. |
| A16 | Product / security PM loaded compensation | $190.0K | USD/year | [BP team Product/security PM + startup-finance heuristic] the role combines compliance workflow design with roadmap ownership. |
| A17 | Sales loaded compensation | $230.0K per FTE | USD/year | [BP team Enterprise seller + startup-finance heuristic] includes variable compensation and travel for long-cycle enterprise sales. |
| A18 | G&A / ops loaded compensation | $140.0K | USD/year | [BP fundingAsk.useOfFundsSummary + startup-finance heuristic] supports finance, legal, vendor, and compliance operations without building a full back office. |
| A19 | Payroll allocation to P&L lines | Founder 45% S&M / 20% R&D / 35% G&A; engineering 100% R&D; platform 15% S&M / 85% R&D; solutions 45% S&M / 55% R&D; PM 80% R&D / 20% G&A; sales 100% S&M; ops 100% G&A | allocation | [BP team rationales + BP operations] this maps salary into the functional lines without hiding solutions-heavy deployment work. |
| A20 | Non-payroll sales and marketing overhead | $10K-$42K per month | USD/month | [BP gtm.channels + BP investorMemo.diligenceQuestions + startup-finance heuristic] covers travel, events, partner enablement, and security-procurement support. |
| A21 | Non-payroll R&D overhead | $12K-$26K per month | USD/month | [BP operations + startup-finance heuristic] covers cloud, graph infrastructure, development tooling, and test environments. |
| A22 | Non-payroll G&A overhead | $10K-$18K per month | USD/month | [BP fundingAsk.useOfFundsSummary + startup-finance heuristic] covers legal, insurance, audit prep, and enterprise compliance costs. |
| A23 | Cash conversion convention | EBITDA approximates cash movement | formula | [startup-finance heuristic] the model assumes immaterial debt service, capex, taxes, and working-capital timing at seed scale. |
| A24 | Monthly churn | 1.5 | percent/month | [startup-finance heuristic for sticky enterprise infrastructure software] a successful workflow embed should churn slowly, but the model does not assume zero churn. |
| A25 | CAC convention | $141.1K per paying logo | USD/logo | [model calc using Y1-Y2 sales and marketing spend divided by 8 active logos at Q4Y2 + BP gtm.funnelTargets] this reflects the first proof cohort rather than long-run scale efficiency. |
| A26 | Unit-economics ARPU anchor | $400.0K annual | USD/logo/year | [Research market.som 12 reachable logos at about $400K blended ACV] the unit-economics section uses the research blend rather than the highest mature-logo price point. |
| A27 | Next-round milestone for funding sizing | 8 paying logos, 2 referenceable annual conversions, partner-sourced pipeline, and gross margin near 70% | milestone | [BP milestones 12–24 months + BP fundingAsk.useOfFundsSummary] this is the proof package the seed round must finance with buffer. |
| A28 | Quarterly salary convention | Y2-Y3 salary rows use actual monthly hires inside each quarter rather than only quarter-end snapshots | convention | [Headcount column convention + BP team.startTiming] this keeps the salary line consistent with the modeled hiring ramp. |
flowchart LR Leads[Triggered assessed accounts] --> Pilots[Paid pilots] Pilots --> Production[Annual production contracts] Production --> Expansion[Second portfolio or premium modules] Expansion --> Revenue[Recognized revenue] Revenue --> GrossProfit[Gross profit] GrossProfit --> Cash[Cash runway]
Flags: The model depends on mature logos expanding above the base subscription into premium modules or a second governed portfolio. · Reaching 8 paying logos by Q4Y2 is aggressive for a founder-led enterprise motion and leaves limited room for procurement slip. · Y3 EBITDA is only around breakeven, so any sustained services-heavy onboarding would likely force another raise sooner than the base case suggests.
Top risks
- Incumbent absorption. Large PKI, exposure-management, or GRC vendors could bundle basic remediation-program views into existing suites. Mitigation: Win on cross-tool sequencing, owner resolution, and evidence automation that sit between discovery, ticketing, and compliance systems rather than inside any one incumbent silo.
- Owner-data drift. CMDB and application ownership data are often stale, which can undermine the first promise of automatic assignment. Mitigation: Combine CMDB records with repo, ticket, gateway, and approval telemetry, then require lightweight human confirmation on the first remediation wave to improve mapping accuracy.
- Budget ambiguity. Some buyers may frame the problem as temporary program management work and default to consultants instead of a new platform. Mitigation: Sell into explicit board, audit, or quantum-readiness deadlines and package a 60-day first-portfolio deployment with measurable closure and reporting outcomes.
Evidence
Cited sources (40)
- Keyfactor. Keyfactor Announces $1B+ Strategic Growth Investment Led by Summit Partners to Expand Leadership in Securing the AI and Post-Quantum Enterprise · https://www.keyfactor.com/press-releases/keyfactor-announces-1b-strategic-growth-investment-led-by-summit-partners-to-expand-leadership-in-securing-the-ai-and-post-quantum-enterprise/
- Keyfactor. Keyfactor Launches Trust Control Plane to Unify Digital Trust Across the Enterprise · https://www.keyfactor.com/press-releases/keyfactor-launches-trust-control-plane-to-unify-digital-trust-across-the-enterprise/
- Keyfactor. The Vision Behind the Keyfactor Trust Control Plane · https://www.keyfactor.com/blog/the-vision-behind-the-keyfactor-trust-control-plane/
- CyberArk. Machine Identity Security | CyberArk · https://www.cyberark.com/products/machine-identity-security/
- CyberArk. CyberArk Completes Acquisition of Machine Identity Management Leader Venafi · https://www.cyberark.com/press/cyberark-completes-acquisition-of-machine-identity-management-leader-venafi/
- DigiCert. Trust Lifecycle Manager release notes · https://docs.digicert.com/en/whats-new/release-notes/trust-lifecycle-manager-release-notes.html
- DigiCert. Integration guides for Trust Lifecycle Manager - DigiCert · https://docs.digicert.com/en/trust-lifecycle-manager/integration-guides.html
- AppViewX. Crypto-Agility and Post Quantum Cryptography Readiness - AppViewX · https://www.appviewx.com/solutions/crypto-agility-and-post-quantum-cryptography-readiness/
- AppViewX. 47-Day Mandate Solution: AppViewX · https://www.appviewx.com/solutions/47-day-mandate/
- SandboxAQ. Cryptographic Security Platform | One Control Plane | AQtive Guard · https://www.aqtiveguard.com/platform
- NIST. Post-quantum cryptography | NIST · https://www.nist.gov/pqc
- NIST. NIST Releases First 3 Finalized Post-Quantum Encryption Standards · https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
- CISA. Quantum-Readiness: Migration to Post-Quantum Cryptography · https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography
- NCSC. Timelines for migration to post-quantum cryptography · https://www.ncsc.gov.uk/guidance/pqc-migration-timelines
- NCSC. Next steps in preparing for post-quantum cryptography · https://www.ncsc.gov.uk/paper/next-steps-in-preparing-for-post-quantum-cryptography
- Let’s Encrypt. Decreasing Certificate Lifetimes to 45 Days · https://letsencrypt.org/2025/12/02/from-90-to-45
- GII Research. Managed Encryption Services Market by Service Type, Deployment Model ... · https://www.giiresearch.com/report/ires2082020-managed-encryption-services-market-by-service-type.html
- Kubernetes. Certificates and Certificate Signing Requests | Kubernetes · https://kubernetes.io/docs/reference/access-authn-authz/certificate-signing-requests/
- cert-manager. Certificate resource - cert-manager Documentation · https://cert-manager.io/docs/usage/certificate/
- cert-manager. trust-manager · https://cert-manager.io/docs/trust/trust-manager/
- Linkerd. Automatic mTLS | Linkerd · https://linkerd.io/docs/features/automatic-mtls/
- Linkerd. Replacing expired certificates | Linkerd · https://linkerd.io/2.18/tasks/replacing_expired_certificates/
- AWS. Secure Kubernetes with AWS Private Certificate Authority · https://docs.aws.amazon.com/privateca/latest/userguide/PcaKubernetes.html
- CyberArk. The invisible threat: Machine identity sprawl and expired certificates · https://www.cyberark.com/resources/blog/the-invisible-threat-machine-identity-sprawl-and-expired-certificates
- QIZ Security. QIZ Security | From Cryptography Chaos to Quantum Resilience · https://qizsecurity.com/
- PR Newswire. QIZ Security Raises $17M Seed to Lead Cyber Readiness for the Post-Quantum Era · https://www.prnewswire.com/news-releases/qiz-security-raises-17m-seed-to-lead-cyber-readiness-for-the-post-quantum-era-302820074.html
- SC World. QIZ Security raises $17 million for cryptographic management platform · https://www.scworld.com/brief/qiz-security-raises-17-million-for-cryptographic-management-platform
- Microsoft. Building your cryptographic inventory: A customer strategy for cryptographic posture management · https://www.microsoft.com/en-us/security/blog/2026/04/16/building-your-cryptographic-inventory-a-customer-strategy-for-cryptographic-posture-management/
- Sectigo. 2025 State of Crypto Agility Report: Preparing for post-quantum · https://www.sectigo.com/blog/2025-state-of-crypto-agility-report-preparing-for-post-quantum
- NIST. IR 8547, Transition to Post-Quantum Cryptography Standards | CSRC · https://csrc.nist.gov/pubs/ir/8547/ipd
- European Commission. Recommendation on a coordinated implementation roadmap for the transition to Post-Quantum Cryptography · https://digital-strategy.ec.europa.eu/en/library/recommendation-coordinated-implementation-roadmap-transition-post-quantum-cryptography
- OMB. M-23-02: Migrating to Post-Quantum Cryptography · https://www.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf
- AWS. Migration to Post-Quantum Cryptography - Amazon Web Services · https://aws.amazon.com/security/post-quantum-cryptography/migrating-to-post-quantum-cryptography/
- Google Cloud. Announcing quantum-safe Key Encapsulation Mechanisms in Cloud KMS · https://cloud.google.com/blog/products/identity-security/announcing-quantum-safe-key-encapsulation-mechanisms-in-cloud-kms/
- Cloudflare. Post-quantum cryptography (PQC) · Cloudflare SSL/TLS docs · https://developers.cloudflare.com/ssl/post-quantum-cryptography/
- Microsoft Learn. Transport Layer Security (TLS) best practices with .NET Framework | Microsoft Learn · https://learn.microsoft.com/en-us/dotnet/framework/network-programming/tls
- Oracle. Java Secure Socket Extension (JSSE) Reference Guide · https://docs.oracle.com/javase/8/docs/technotes/guides/security/jsse/JSSERefGuide.html
- NGINX. Module ngx_http_ssl_module · https://nginx.org/en/docs/http/ngx_http_ssl_module.html
- F5. Additional SSL Profile Configuration Options · https://techdocs.f5.com/en-us/bigip-17-0-0/big-ip-system-ssl-administration/additional-ssl-profile-configuration-options.html
- MarketsandMarkets. Post-quantum Cryptography (PQC) Market worth $2.84 billion by 2030 · https://www.marketsandmarkets.com/PressReleases/post-quantum-cryptography.asp