New Content & Platform Update
Preparing for Post-Quantum Cryptography
Release date: August, 3rd, 2026
We’ve launched Preparing for Post-Quantum Cryptography – a new theory collection designed to give security leaders a structured framework for post-quantum cryptography (PQC) migration.
Rather than focusing on theoretical algorithm design, this collection delivers actionable guidance to help you audit existing cryptographic assets, evaluate finalized National Institute of Standards and Technology (NIST) replacement standards, and build a resilient migration strategy.
Key topics covered in this collection include:
Assessing cryptographic footprints: Learn how to discover and catalog vulnerable asymmetric algorithms (such as RSA and ECC) across your infrastructure.
Evaluating finalized NIST standards: Understand the practical applications of Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM), Module-Lattice-Based Digital Signature Algorithm (ML-DSA), and Stateless Hash-Based Digital Signature Algorithm (SLH-DSA).
Building an enterprise migration roadmap: Formulate a step-by-step transition plan that addresses technical debt, vendor readiness, and cryptographic agility.
Who Are We Doing It For
This collection is built specifically for security leadership and governance teams, including:
Chief Information Security Officers (CISOs)
Risk managers
Compliance leads and auditors
Why Are We Doing It Now
The regulatory grace period for quantum readiness has officially ended. Threat actors are actively executing "Harvest Now, Decrypt Later" (HNDL) attacks – exfiltrating encrypted data today to decrypt it once quantum capability matures.
Additionally, regulators and standard-setting bodies now treat post-quantum readiness as an immediate audit requirement. Organizations must demonstrate actionable progress to auditors, procurement teams, and boards today to comply with:
NIST's published PQC standards: Finalized specifications for ML-KEM, ML-DSA, and SLH-DSA are live, establishing the baseline for modern encryption.
Digital Operational Resilience Act (DORA): Regulatory enforcement is now in effect, mandating strict ICT risk management and cryptographic oversight.
Payment Card Industry Data Security Standard (PCI DSS) v4.0.1: Requirement 12.3.3 is now mandatory, forcing organizations to document and manage targeted cryptographic inventories.
National Cyber Security Centre (NCSC) guidance: The NCSC has set a 2028 deadline for complete cryptographic discovery and initial migration planning.
Next Steps and Related Content
This theory collection serves as the strategic foundation for your PQC journey. To defend against the immediate data exfiltration phase of HNDL attacks, pair these concepts with our tactical incident response (IR) and threat hunting labs:
Orchid Corp: Akira: Identify credentials being exfiltrated to OneDrive via PowerShell.
Orchid Emporium: Lazarus Group: Investigate cloud-native Amazon Simple Storage Service (S3) to Command and Control (C2) exfiltration.
Note: While these threat hunting labs train defenders to stop active data exfiltration, they focus on general adversary tactics rather than PQC-specific algorithms.
For a broader conceptual foundation, explore our existing Quantum Computing Fundamentals collection. In the coming weeks, we’ll also expand this track with dedicated PQC crisis simulation scenarios to test executive decision-making under pressure.
Customer Availability: Live today and accessible to all customers across all tiers.