PQC Ready · by SDTC Solutions

We are PQC Ready. Your quantum-safe transition team.

Our team helps your organisation assess cryptographic exposure, plan the migration, and move toward quantum-safe infrastructure with structure and confidence.

Try Quick Scan

01 / Why it matters

Almost everything you trust online is kept private by encryption.

Quantum computers will one day be powerful enough to break it.

Data captured today could be unlocked the moment that day arrives.

The time to prepare is before it happens — not after.

Read more about this →

02 / The quantum risk

What the quantum age puts at risk.

Tap any card for the detail →

01

Harvest now, decrypt later

Encrypted data stolen today can be stored and unlocked the moment a quantum computer is ready.

Explore

Harvest now, decrypt later

  • Adversaries are recording traffic today
  • Anything that must stay secret for years is already exposed
  • The clock started well before "Q-Day"
Full explanation → Close
02

Public-key encryption broken

A large quantum computer running Shor's algorithm can break RSA and elliptic-curve cryptography.

Explore

Public-key encryption broken

  • RSA, ECC, ECDH and ECDSA all fall
  • The maths protecting today's keys unravels
  • Most of the internet's trust depends on it
Full explanation → Close
03

Forged digital signatures

If signatures can be forged, software updates, certificates and identities can be impersonated.

Explore

Forged digital signatures

  • Code-signing and updates become spoofable
  • Certificate chains lose their authority
  • Trust in "who really sent this" collapses
Full explanation → Close
04

Long-lived secrets exposed

Data that must stay private for decades — health, legal, state, intellectual property — is the first to fall.

Explore

Long-lived secrets exposed

  • 10–30 year confidentiality is at risk now
  • Retroactive decryption, not just future data
  • The longer the secret, the bigger the loss
Full explanation → Close
05

Everyday encryption weakened

Grover's algorithm chips away at the symmetric encryption that protects data at rest.

Explore

Everyday encryption weakened

  • Effective AES-128 strength roughly halves
  • Key sizes and hashing need rethinking
  • Larger keys buy back the safety margin
Full explanation → Close
06

Crypto-stranded systems

Embedded, OT and IoT devices with decade-long lifespans can't simply be patched.

Explore

Crypto-stranded systems

  • Cryptography is baked into the hardware
  • Long deployment, no easy upgrade path
  • Replacement has to be planned before it's urgent
Full explanation → Close

03 / A shared map

From unaware to quantum ready.

Enterprises and organisations are at different stages of PQC awareness and readiness. We use the PQC Enterprise Maturity Model (PQCEMM) to evaluate how prepared an organisation is to manage its transition. The stage-gated result runs from Level 1 to Level 5, with progress and evidence confidence shown separately.

Understand the PQCEMM model →
  1. 1.0Quantum Unaware
  2. 2.0Quantum Aware
  3. 3.0Quantum Preparing
  4. 4.0Quantum Advancing
  5. 5.0Quantum Ready

04 / How it works

We offer a structured path from discovery to assurance.

Getting quantum-ready is a coordinated programme across people, suppliers and technology - from first exposure awareness through continuous assurance.

  1. 01
    Phase 1

    Quantum Exposure Awareness

    • Establish a self-reported exposure and readiness baseline and identify the next evidence decision.
    • anonymous seven-question Quick Scan
    • adaptive registered assessment with Quinn
    • Named outputs: quantum exposure snapshot; structured evidence and maturity profile; advisory report and next-step recommendation.
    • Decision unlocked: Whether the organisation needs deeper cryptographic discovery and which scope should enter CRAS.
    Explore Phase 1 →
  2. 02
    Phase 2

    Cryptographic Assessment (CRAS)

    • Turn the Phase 1 baseline into verified cryptographic, service, trust, HNDL and supplier evidence.
    • facilitated scope definition
    • protected evidence-route design
    • Named outputs: CRAS scope statement; secure evidence intake plan; scope exclusions and unknown-state register.
    • Decision unlocked: Which continuity and migration-planning work should start next.
    Explore Phase 2 →
  3. 03
    Phase 3

    Business Continuity Optimisation

    • Connect cryptographic disruption to critical activities, long-lived confidentiality and exercised crisis decisions.
    • PQC-focused business impact analysis
    • critical-activity and recovery dependency mapping
    • Named outputs: PQC-focused business impact analysis; critical-activity and recovery requirements; Harvest Shield HNDL treatment register.
    • Decision unlocked: Which readiness gaps must close before the next exercise or migration gate.
    Explore Phase 3 →
  4. 04
    Phase 4

    PQC Transition & Migration Planning

    • Convert validated evidence into system routes, dependency-aware waves, tests, rollback and approval gates.
    • evidence-bound transition strategy
    • principle and decision-gate design
    • Named outputs: PQC migration strategy; transition principles and decision gates; system transition-route register.
    • Decision unlocked: Whether a pilot or migration wave may begin.
    Explore Phase 4 →
  5. 05
    Phase 5

    Execution of Migration Plan

    • Provisional scope: implementation begins only after Phase 5 entry approval and delivery-model selection.
    • Carry out only approved, bounded pilots and migration waves under a selected delivery and acceptance model.
    • delivery-boundary design
    • responsibility and assurance allocation
    • Named outputs: delivery-model decision; responsibility and assurance matrix; pilot execution record.
    • Decision unlocked: What is closed, what remains and how it will be assured.
    Explore Phase 5 →
  6. 06
    Phase 6

    Continuous Assurance

    • Keep standards, inventory, suppliers, exceptions and decision evidence current after initial migration.
    • primary-source signal monitoring
    • applicability and re-entry assessment
    • Named outputs: external signal register; impact and re-entry recommendations; inventory and supplier drift report.
    • Decision unlocked: Which earlier-phase work must be repeated and what remains valid.
    Explore Phase 6 →

05 / Standards & guidance

International PQC standards and regulatory developments.

We help you interpret the standards, national roadmaps and regulatory expectations shaping the transition, then turn them into practical priorities for your organisation.

  • NIST PQCPost-quantum standards

    The US standards body that finalised the first post-quantum algorithms — ML-KEM, ML-DSA and SLH-DSA — now the global baseline for migration. Read the full guide →

    + Details
  • NCSCPQC migration guidance

    The UK National Cyber Security Centre, whose guidance sets out how organisations should plan and stage their move to post-quantum cryptography. Read the full guide →

    + Details
  • DORAOperational resilience

    The EU Digital Operational Resilience Act — financial entities must manage and evidence their ICT and cryptographic risk. Read the full guide →

    + Details
  • NIS 2Network & information security

    The EU directive raising cyber-security and risk-management duties across essential and important sectors. Read the full guide →

    + Details
  • ISO 27001Information security management

    The international standard for an information-security management system — the framework many organisations already certify against. Read the full guide →

    + Details
  • CNSA 2.0Where relevant

    The NSA's Commercial National Security Algorithm Suite 2.0, setting quantum-resistant requirements for US national-security systems. Read the full guide →

    + Details

06 / Who we help

Built for organisations where trust has to last for years.

These are examples, not an exhaustive target market. Quantum exposure follows long-lived data, products, infrastructure and supply chains across every sector.

  • 01

    Financial services

    Payments, identity and customer data that must stay trustworthy for years — under heavy regulation, and long after Q-Day.

    PQC readiness focus
    • Map long-lived customer data, payment trust, identities and cryptographic dependencies.
    • Prioritise migrations against regulatory duties, operational resilience and supplier timelines.
    Sector guidance →
  • 02

    Telecommunications

    Subscriber data and network infrastructure with decade-long service lifespans to protect.

    PQC readiness focus
    • Trace cryptography across core networks, subscriber identity, roaming and lawful-intercept systems.
    • Sequence change around long-lived equipment, standards adoption and vendor release cycles.
    Sector guidance →
  • 03

    Critical infrastructure

    Operational technology, supply chains and continuity of services a whole nation depends on.

    PQC readiness focus
    • Identify quantum-vulnerable trust across operational technology and safety-critical communications.
    • Plan phased change without compromising availability, recovery or public-service continuity.
    Sector guidance →
  • 04

    Cloud & data centres

    Tenant confidentiality, platform trust and key management at massive scale.

    PQC readiness focus
    • Assess certificates, key management, APIs, control planes and tenant boundaries at scale.
    • Coordinate platform upgrades with cloud providers, managed services and customer dependencies.
    Sector guidance →
  • 05

    Government & public sector

    Citizen data and sensitive archives that must stay sealed for decades.

    PQC readiness focus
    • Prioritise citizen records, national archives and systems with long confidentiality lifetimes.
    • Connect national guidance, procurement, supplier assurance and service continuity into one roadmap.
    Sector guidance →
  • 06

    Healthcare & life sciences

    Patient records and research data with lifetime confidentiality requirements.

    PQC readiness focus
    • Protect patient records, genomic data, clinical research and connected medical systems.
    • Plan migration around safety, interoperability, research partnerships and legacy technology.
    Sector guidance →
  • 07

    Legal & professional services

    Privileged archives and client confidentiality that must hold, indefinitely.

    PQC readiness focus
    • Locate long-lived client files, privileged advice, transaction data and signing dependencies.
    • Turn confidentiality obligations into evidence-backed priorities for systems and suppliers.
    Sector guidance →
  • 08

    Manufacturing & automotive

    Connected products, industrial control, embedded cryptography and supplier networks with long replacement cycles.

    PQC readiness focus
    • Inventory embedded keys, secure updates, product identities and factory control dependencies.
    • Align product lifecycles with supplier capability, serviceability and crypto-agility requirements.
    Sector guidance →

07 / Leadership

Risk, technology and policy experience for a high-stakes transition.

See the roles a PQC programme needs →
Martin Denz

Martin Denz

Chief Executive Officer

Helps organisations of all sizes navigate the move to post-quantum cryptography before quantum-capable threats become operational.

Full bio

Martin began his career at Intel, where he led the operational growth of their largest European R&D site and later directed Intel's global Risk and Controls function — building enterprise-wide frameworks for business continuity and asset protection.

In 2020 he founded SDTC Solutions, a consultancy focused on strategic transformation and risk-controlled delivery. He has a background in Computer Science with post-graduate study at Imperial College Business School, and serves as an elected councillor and a magistrate.

Mikhail Oreshkin

Mikhail Oreshkin

Director, Sales & Business Development

Helps organisations in financial services, defence, energy and healthcare turn complex technology shifts into risk-managed plans.

Full bio

A graduate of Royal Holloway with a Master's in International Security, Mikhail builds partnerships across the UK, Europe, Central Asia and the Gulf region.

He began his career at the intersection of government procurement and international health diplomacy, and today advises leadership teams on emerging cyber and resilience risks, including post-quantum readiness.

Alexey Odinokov

Alexey Odinokov

Chief Technology Officer

Leads the technical strategy for assessing and addressing exposure to post-quantum cryptography risk.

Full bio

Alexey built his foundational expertise at Intel, helping establish their largest European R&D site across platform performance, wireless transmission and processor architecture.

He completed an MSc at Stanford Graduate School of Business, co-founded an ASIC services business, and studied Quantum Computing at MIT — sharpening his focus on the intersection of quantum theory and real-world cryptographic risk.

Anastasiia Vasylenko

Anastasiia Vasylenko

PR, Policy & Advocacy Executive

Leads the firm's marketing and media programmes, brand development and cyber-policy advocacy.

Full bio

Anastasiia began her career in Ukraine in public affairs and strategic communications, including overseeing PR for the Ukrainian Pavilion at the Venice Architecture Biennale.

She holds a Master's in International Law from Taras Shevchenko National University of Kyiv and is reading for an MPA at the London School of Economics.

Roeland Van Gestel

Roeland Van Gestel

Chief Operating Officer

Oversees PQC Ready's operational foundations while working directly with clients on complex transformation and risk engagements.

Full bio

A founding member who joined in 2025, Roeland brings three decades of international experience in general management, operations and large-scale transformation across consultancy and manufacturing.

His career spans Managing Director, CFO and Director of Transformation roles across automotive, optical cable, agri-food and oil — including World Bank and EBRD-funded projects. He is fluent in English, German, Dutch and Russian.

Danil van Gestel

Digital Solutions Lead

Profile and photo coming soon.

08 / Responsible use

Responsible AI, clear boundaries and careful handling of your information.

PQC Ready uses AI to make complex readiness work easier to navigate, while keeping people accountable for the method, the decisions and the relationship with you. We explain when AI is involved, minimise the information required and use an NDA when a confidential engagement needs sensitive evidence.

How Quinn helps

Quinn is an AI-assisted guide. It explains questions, helps you structure answers and can prepare clearly labelled advisory material. The assessment method and service boundaries remain defined by PQC Ready.

How Quinn uses AI →
Data minimisation

The free Quick Scan asks only for the information needed to create an indicative snapshot. We keep the purpose visible, separate a Quick Scan from a formal maturity assessment and avoid hidden reuse.

Read the data boundary →
Confidential engagements

Registered workspaces separate account data and assessment history. When detailed evidence or confidential architecture is needed, we first agree the scope, access and handling expectations under an NDA.

Public versus protected tools →

09 / Get started

Start planning your quantum-safe transition before it becomes urgent.

Bring a board question, a regulatory pressure point or a technical uncertainty. The first step is making the exposure visible.

Not sure where to start? Use the guide →
  • Vendor-neutral and confidential
  • No-obligation first conversation
  • Clear next steps within two weeks
Quantum signal check

Drag the signal into the highlighted safe band.

loading challenge Loading

Not sure where you actually stand? Try the Quick Scan with Quinn — a free, no-pressure first read on your quantum readiness, with a clear next move.

Try Quick Scan
Website activity & privacy ·