NIST finalises the first PQC standards
ML-KEM and ML-DSA become the designated replacements for RSA and elliptic-curve key exchange.
STATE_VULNERABLE
Nation-state collectors do not need to break anything today. They record the ciphertext and wait. Everything you are moving through this lattice was readable to nobody, at the moment it was taken.
A cryptographically relevant quantum computer does not scramble your data. It does the opposite. The noise snaps flat and becomes structure. What you are watching lock into place is the adversary's view, not yours.
The lattice becomes a grid you hold. R2PQ inventories the exposure, scores it against the published deadlines, and commits the finding to a receipt that a third party can verify without trusting us.
02 / Published deadlines
None of this is speculative. The dates below are published by standards bodies and procurement authorities. They arrive whether or not an organisation is ready for them.
ML-KEM and ML-DSA become the designated replacements for RSA and elliptic-curve key exchange.
Requirements flow down from national-security buyers through prime contractors to their suppliers.
Large technology estates target finished rotations. Late adopters begin absorbing compliance cost.
Federal deadline. Systems still presenting RSA or ECC are out of compliance.
Most assessments end in a PDF and an assurance. Ours ends in an evidence receipt: a cryptographic commitment to exactly what was examined, anchored to an independent RFC 3161 timestamp, checkable in a browser that never uploads it.
What the receipt establishes
Every recorded leaf hash rebuilds the stated Merkle root. The commitment is internally consistent.
An independent authority signed a token whose imprint derives from that exact root.
The token's CMS signature and its signed message digest are both intact.
Certificate-chain trust, revocation status, operator identity. The verifier says so plainly rather than implying otherwise.
Next
A cryptographic exposure scan of your codebase and infrastructure. Where the keys are, which algorithms are quantum-vulnerable, and what a rotation actually costs. Delivered with a verifiable receipt.
Request an assessment