Navigation

Get in touch
Logo
News

PQC roadmap

Your cryptography needs a plan.

Not every system needs to be migrated at the same time. We assess protection duration, attack surface, technical dependencies and migration effort. This results in a sequence of well-founded measures, responsibilities and decision points.

person holding paper near pen and calculator — illustrative image
Well-founded prioritization · Planning and implementation by OTOKO®

Your brief for OTOKO®

What we take care of for you.

Certain information must remain confidential for many years. Recorded encrypted traffic can therefore already be relevant to long-term risk assessment today. At the same time, procurement, software adjustments and changes at counterparts take time. We connect these factors with your protection needs, without treating a speculative date for a powerful quantum computer as a reliable planning basis. Signatures are considered separately, because their long-term verifiability can require different measures than the confidentiality of a connection.

The possible scope of services

  • Assess protection needs for data and signatures together
  • Classify cryptographic dependencies and migration effort
  • Record vendor dependencies and procurement cycles
  • Plan pilot projects and migration waves
  • Document residual risks and open decisions

We define the specific scope, your involvement and the acceptance criteria before the start.

Technology explained clearly

How we carry out the task.

01

Dependencies determine the sequence

A central library or certificate platform can affect many applications. Conversely, a single legacy device can limit the migration of an entire communication path. We map these dependencies, review vendor information and separate measures that can be implemented in the short term from preparatory work. Pilots receive clear questions to answer, for example the compatibility of a gateway chain or support for a key type. The roadmap contains decision points where measurement results and new information can change further planning.

02

From a roadmap to stages you can order

Each stage names the systems, expected results, required contributions and approval criteria. Exceptions receive an owner and a review date. Acceptance looks not only at a list of dates, but at whether effort, dependencies and risks are clearly justified. To get started, we need an initial inventory, information on protection needs and upcoming renewals of your infrastructure.

Meeting room at the OTOKO® Cologne office

A verifiable result

What you keep working with.

  1. Well-founded prioritization
  2. Migration plan with dependencies
  3. Decision paper for business units and IT

The handover brings together implementation and documentation. Together, we review the agreed cases and record any remaining tasks.

Your project in detail

Set the sequence by protection duration and migration feasibility.

We translate a crypto inventory into a realistic PQC roadmap. Not all systems need the same timing and the same measure; priority follows from data value, protection duration and technical dependencies.

Consider confidentiality and long-term provability separately

For confidential data, what matters is how long it must remain protected and whether encrypted communication could be recorded today. For signatures and archives, long-term verifiability and the renewal of evidence also come into play. We capture these requirements together with the business owners, rather than sorting purely by server age.

Risk here does not mean predicting a specific date for powerful quantum computers. The planning considers well-founded scenarios and the time your organization needs for procurement, integration and approval. Particularly long lead times can justify an early start.

From priorities to actionable work packages

A roadmap contains prerequisites, owners, dependencies and decision points. Some tasks start with clarification from the vendor, others with a lab trial or a modernization of outdated libraries. We distinguish preparatory measures from production changeovers and flag decisions that still depend on concrete product support.

Effort and dates are maintained as a reasoned plan with open assumptions. The sequence is reviewed after pilots. A blanket, complete migration is rarely the first sensible measure; often, simply removing hard-coded algorithm bindings already creates the basis for later changes.

Illustrative project scenario

How the service helps in everyday use.

Example: Short-lived public content and development data that must stay confidential for many years use different systems. We do not prioritize all internet-facing services first as a matter of course; instead, we consider protection duration and migration lead time. For an archive that is difficult to replace, preparation starts earlier.

This example explains a possible process and is not a customer reference.

Before the first step

Your questions about PQC roadmap.

Do we have to wait for a binding deadline?

No. The inventory, dependency analysis and compatibility tests can start regardless. Specific migrations are based on risk and technical maturity.

Does the plan replace our security strategy?

No. It complements the strategy by addressing cryptographic change and is linked to existing risk, procurement and operations processes.

Your project

Which task would you like to solve?

Describe your situation and the desired result. The selected service will be included in the contact request.

Request this service

Our Partners

  • Microsoft
  • Microsoft Azure
  • Amazon AWS
  • Google Cloud
  • Thales Group
  • Arrow ECS
  • Vodafone
  • IBM
  • Veeam
  • Atlassian
  • JetBrains
  • NinjaOne
  • OPSWAT
  • Utimaco
  • Eviden

Accessibility

Adjust the display to suit your needs.

A simple version is not available for this page yet.

Settings currently apply to this visit. Allow saving in Cookie settings to remember them.