R2PQ

STATE_VULNERABLE

Harvest
now.
Decrypt
later.

Post-quantum exposure assessment

R2PQ.dev

Encrypted traffic is being collected today against the arrival of a machine that can read it. R2PQ finds what is exposed, and produces evidence of the assessment that anyone can check.

How harvested traffic becomes readable, and what R2PQ measures

01 / Harvest

You are falling through your own traffic.

Nation-state collectors do not need to break anything today. They record the ciphertext and wait. Everything you are moving through this lattice was readable to nobody, at the moment it was taken.

02 / The break

This is not order. This is the day it resolves.

A cryptographically relevant quantum computer does not scramble your data. It does the opposite. The noise snaps flat and becomes structure. What you are watching lock into place is the adversary's view, not yours.

03 / The instrument

You cannot argue with the arithmetic. You can measure against it.

The lattice becomes a grid you hold. R2PQ inventories the exposure, scores it against the published deadlines, and commits the finding to a receipt that a third party can verify without trusting us.

02 / Published deadlines

The clock is
not ours

None of this is speculative. The dates below are published by standards bodies and procurement authorities. They arrive whether or not an organisation is ready for them.

2024

NIST finalises the first PQC standards

ML-KEM and ML-DSA become the designated replacements for RSA and elliptic-curve key exchange.

Standardised
2027

CNSA 2.0 reaches new acquisitions

Requirements flow down from national-security buyers through prime contractors to their suppliers.

Procurement
2030

Early movers complete migration

Large technology estates target finished rotations. Late adopters begin absorbing compliance cost.

Market
2035

Classical public-key cryptography is phased out

Federal deadline. Systems still presenting RSA or ECC are out of compliance.

Mandate

We do not ask you
to take our word

Most assessments end in a PDF and an assurance. Ours ends in an evidence receipt: a cryptographic commitment to exactly what was examined, anchored to an independent RFC 3161 timestamp, checkable in a browser that never uploads it.

Verify a receipt now

What the receipt establishes

Integrity

Every recorded leaf hash rebuilds the stated Merkle root. The commitment is internally consistent.

Timestamp

An independent authority signed a token whose imprint derives from that exact root.

Signature

The token's CMS signature and its signed message digest are both intact.

Not established

Certificate-chain trust, revocation status, operator identity. The verifier says so plainly rather than implying otherwise.

Next

Find out what
is already
exposed.

A cryptographic exposure scan of your codebase and infrastructure. Where the keys are, which algorithms are quantum-vulnerable, and what a rotation actually costs. Delivered with a verifiable receipt.

Request an assessment