Rosetta Q-Ready · post-quantum cryptographic exposure

How ready is your cryptography for the quantum clock?

Automated map of your post-quantum cryptographic exposure. Public-surface evidence, a Q-Ready score, and a board-ready report — no network access required at the External tier.

33/ 100
Conscientesee the sample report →
The problem · a calendar that is already policy

The cryptographic clock is already running.

The public-key cryptography protecting almost all enterprise traffic (RSA, ECC) will be vulnerable to a cryptographically relevant quantum computer via Shor’s algorithm. The replacements are already standards. Migration takes years. The defense timeline is fixed by public policy; the attack timeline is a probability distribution.

2024
FIPS 203/204/205 finalized (ML-KEM · ML-DSA · SLH-DSA)
2027
CNSA 2.0: PQC mandatory in new US national-security systems
2030
NIST IR 8547: RSA-2048 and ECC P-256 deprecated
2033–37
expert central window for a CRQC (GRI)
2035
quantum-vulnerable algorithms disallowed from NIST standards
Harvest Now, Decrypt Later

The risk starts today, not when the machine arrives.

A long-horizon adversary can collect encrypted traffic today and decrypt it once a CRQC exists. Data whose confidentiality must outlive ~10 years should be treated as potentially exposed under classical cryptography.

01

Capture today

The adversary records TLS traffic encrypted in transit.

02

Archive

Stores it — cheaply — waiting for capability.

03

CRQC

A quantum computer runs Shor against RSA/ECC.

04

Plaintext

Years-old traffic becomes readable, retroactively.

We do not claim “your data was already stolen.” We claim measurable exposure under a public timeline.

Mosca’s inequality

Add the years. If the sum lands late, you are late.

If the time your data must stay secret (X) plus the time it takes to migrate (Y) exceeds the time until a CRQC (Z), the organization is late. A typical banking example:

X + Y > Z
X · confidentiality
8 yr
Y · migration
9 yr
Z · until CRQC
9 yr
X + Y = 17 years > Z = 9 years → 8 years late. The decision window is now, not 2033.
What we deliver

A report a board can read, with the evidence behind it.

  • Q-Ready score 0–100 with band and traffic-light
  • Top 5 findings and the cost of inaction (Mosca)
  • Observed inventory: hosts, algorithms, hybrid, CDN
  • HNDL index by industry + CRQC scenarios
  • Actionable roadmap 30 / 90 / 365 days
  • Rosetta seal: JSON hash + ledger (evidence)
33/ 100
Consciente
Three tiers

From an external look to a partner-run program.

Tier 1 · External
Q-Ready External
USD 4,900
1 root domain · up to 50 hosts — Domain + industry only. 100% Rosetta, no network access.
  • Public-surface evidence
  • TLS PQC probe + Certificate Transparency
  • Score + PDF report + portal
  • Delivery in 24–72 h
Early-adopter pilot: ~USD 2,500Map my domain
Tier 2 · Assisted
Q-Ready Assisted
USD 24,900
up to 5 domains · 500 hosts · 1 cloud — External + questionnaire + uploads + read-only OAuth.
  • Everything in External
  • Crypto inventory + CycloneDX CBOM
  • Cloudflare / AWS / Azure integrations
  • Detailed roadmap · 5–10 days
Choose Assisted
Tier 3 · Enterprise
Q-Ready Enterprise
From USD 180k
8–16 week program — Rosetta evidence + partner execution (Big 4 / boutique).
  • Everything in Assisted
  • Evidence Pack for the partner
  • Workshops and internal discovery
  • Remediation program
Talk to a partner
How the External tier works

Four steps, without touching your network.

1

Your domain

Enter legal name, root domain(s), and industry.

2

Public probes

We probe public endpoints only: TLS, certificates, CT.

3

Score

The engine computes your Q-Ready 0–100 and HNDL posture.

4

Report

You receive the sealable report and portal, in 24–72 h.

Standards we cite

None of this depends on marketing.

Honesty

What Q-Ready is not.

Q-Ready is not a certification (not ISO/PCI/NIST) and does not replace a formal internal review.

The External tier does not see inside: it does not inventory HSM/KMS, apps, VPN, encrypted DBs or internal mTLS. Those visibility gaps are covered in Assisted and Enterprise.

We do not sell panic. The cryptographic threat (Shor/CRQC) is a theorem + policy calendar; quantum advantage in optimization is a measured verdict on the Evidence Ledger. Separate claims.

Frequently asked
Do you need access to my network?

Not at the External tier. We probe only public endpoints of the domains you authorize. Assisted adds uploads and read-only integrations you control.

Is this a certification?

No. It is a measurement with evidence and an actionable verdict. It complements, not replaces, formal compliance reviews.

Is it urgent if the quantum computer does not exist yet?

Yes, because of “harvest now, decrypt later” and because migration takes years. The 2030/2035 milestones are policy, not hardware.

How is this different from your Evidence Ledger?

A theorem (Shor on RSA/ECC) versus a measured verdict (Ledger: did quantum beat the classical baseline on this instance?). Q-Ready measures cryptographic exposure; the Ledger measures optimization advantage. Keeping them separate is part of our discipline.

How often should we re-scan?

Your surface changes. The Monitor add-on re-scans quarterly (USD 990/yr) to track your migration progress.

See where your cryptography stands against the clock.

Start with the External tier: public evidence, no access required.