The Decision Layer™ · 10-Day Quantum Decision Readiness Assessment

Turn post-quantum uncertainty into one board-ready decision.

A focused 10-day assessment for organisations that need to understand PQC exposure before committing to a wider migration programme. Not just what cryptography must change. What decision must be made, who owns it, what evidence supports it and what the board should see next.

The transformation
Before

Quantum risk is visible, but the decision is not.

Cyber sees old algorithms. Finance sees a large number. Legal sees regulatory duty. Procurement sees supplier promises. Risk sees long-horizon exposure. The board gets five reasonable views and no clean decision.

After

The issue is named, measured, owned and ready to govern.

You know what is exposed, what makes it quantum-relevant, which time horizon matters, which suppliers could delay you, who owns the next move and what evidence supports the recommendation.

What the service helps leaders avoid
Unclear labels

One event. Five names. No clean decision.

Quantum, Cyber, Finance, Legal and Vendor Risk often describe the same issue through different lenses. The assessment separates the primary event from its attributes.

You leave with: a shared classification that lets the board understand what actually happened.
Mixed time horizons

Today’s cost and tomorrow’s stress case stay apart.

Current remediation and long-horizon Q-Day exposure should not sit in the same number. The assessment separates the two clocks so leaders know which decision they are funding.

You leave with: a current-period view, a long-horizon view and a clearer funding conversation.
Weak supplier evidence

“We are monitoring the standards” stops being enough.

The assessment tests whether suppliers have affected products, migration duties, dates, evidence, contract commitments and exit options.

You leave with: a supplier action list that turns comfort into proof.
Inflated numbers

Big figures no longer behave like fog machines.

Finance needs numbers with manners. The assessment separates base-case cost, conditional stress scenarios and strategic exposure so the board can act without pretending uncertainty has disappeared.

You leave with: numbers that support decisions instead of overwhelming them.
Lost decision memory

The decision can still be reconstructed later.

Migration choices made now may be challenged years later. The assessment builds the decision trail, evidence map, owners, assumptions and review points.

You leave with: a proof pack that survives audit, scrutiny and staff turnover.
Board uncertainty

The board sees the decision, not just the activity.

The assessment turns technical work into a board-ready view of exposure, consequence, ownership, unresolved choices and next action.

You leave with: one decision roadmap instead of another status update.
What each executive is really trying to achieve
Audit Chair / ARC Chair

Know whether green means anything.

See whether management has evidence behind its PQC position, whether current and long-horizon exposures are separated and whether decisions can be reconstructed later.

You leave with: the questions that determine whether the programme is genuinely ready for oversight.
Chief Audit Executive

Audit the machinery, not the mood.

Test whether events are classified properly, supplier evidence supports claims, risk acceptance is owned and the board paper preserves the decision logic.

You leave with: assurance that challenges decision quality before the story hardens.
Chief Risk Officer

Turn five functional views into one enterprise decision.

Bring quantum, cyber, legal, finance, technology and supplier risk into one position with clear time horizons, consequences, owners and uncertainty.

You leave with: one enterprise view instead of competing labels.
Chief Information Security Officer

Show why funding is needed now.

Translate TLS, PKI, HSM, signing and cryptographic exposure into business consequence, supplier dependency and funding choices.

You leave with: a board-ready case for action, not another technical heatmap.
Chief Information Officer

Make cryptographic risk visible before renewal decisions.

Know whether platform, cloud and supplier decisions create hidden PQC exposure before contracts, architecture and budgets lock the organisation in.

You leave with: the conditions for a safer yes, no, not yet or only if.
Procurement / Supplier Risk

Turn supplier promises into decision-grade evidence.

Ask which products are affected, which commitments exist, which evidence supports the roadmap and what happens if the supplier cannot move.

You leave with: sharper renewal questions, contract gaps and supplier escalation points.
The 10-day sprint

Ten days to move from quantum fog to decision readiness.

Phase 1 stands alone. No obligation to proceed. The aim is not to solve the whole migration in ten days. The aim is to find the evidence, name the decision and show leaders what must happen next.

Days 1 to 2

Executive framing and evidence intake.

Confirm scope, critical services, risk appetite, supplier landscape, board concerns and available evidence across TLS, PKI, HSM, signing, suppliers and governance.

Days 3 to 4

Cryptographic exposure review.

Assess visible TLS, PKI, certificate, HSM, key management and digital signing exposure, with emphasis on what creates business consequence.

Days 5 to 6

Decision Layer analysis.

Separate primary event, quantum relevance, technical method, legal scope, supplier dependency, base-case exposure and long-horizon stress scenario.

Days 7 to 8

Supplier and evidence challenge.

Review supplier claims, contract gaps, migration duties, proof quality, exit options, data lifetime exposure and ownership gaps.

Day 9

Scoring and roadmap design.

Score exposure, classify decision gaps, map control families, define next actions and build the prioritised decision roadmap.

Day 10

Executive readout.

Deliver the board-ready risk profile, exposure score, evidence heatmap, supplier action list, open decisions and recommended next move.

What you receive
01

Executive risk profile.

A plain-English view of current PQC exposure, board concern, material dependencies and recommended decisions.

02

Exposure score.

A scored view across TLS, PKI, HSM, digital signing, supplier evidence, governance, assurance and decision infrastructure.

03

Two-clock view.

A clear separation between today’s cryptographic estate and long-horizon quantum exposure.

04

Supplier evidence map.

A view of supplier claims, missing evidence, contract gaps, migration duties, milestone risk and exit options.

05

Board question pack.

The questions that help directors challenge management without pretending to be cryptographers.

06

Prioritised decision roadmap.

The route from assessment into cryptographic inventory, quantum security analysis, architecture design, implementation and assurance.

The common future

What they are all trying to achieve is a better Monday morning.

The meeting is shorter because the decision is clearer. The number has manners. The time horizons are separated. Supplier evidence is visible. The action has one owner. The uncertainty is explicit. And if somebody asks later why the organisation made the call, the answer still exists.

Help me turn quantum risk into the right decision, by the right people, with enough evidence to defend it before the issue becomes more expensive.

The 10-day assessment promise

Know what is exposed. Know what decision is needed. Know who owns it. Know what evidence supports it.

Start with the 10-day Quantum Decision Readiness Assessment when your organisation needs a clear first answer before committing to a wider PQC migration programme.

10 days · no obligation to proceed

The Decision Layer™ · 10-Day Quantum Decision Readiness Assessment · Decision readiness before PQC migration.