HNDL / TNFL Risk Assessment
Rank migration by the data that is already being collected against you.
What the engagement covers.
Harvest-now-decrypt-later exposure depends on how long data stays sensitive and how long migration takes. This assessment turns that into a defensible priority order rather than an alphabetical asset list.
Included capabilities
- Data confidentiality lifetime analysis per data class
- Harvest-now-decrypt-later exposure scoring across channels at rest and in transit
- Trust-now-forge-later exposure for signatures, code signing and long-lived credentials
- Migration effort estimation per system and dependency cluster
- Prioritized migration sequence with justification for each tier
Outputs and deliverables
- Data lifetime and exposure analysis
- HNDL and TNFL risk scoring model and results
- Migration priority tiers with justification
- Risk committee briefing pack
How it is delivered, step by step.
Each step has an owner, an entry condition and an artefact that has to exist before the next step begins.
Where this is typically applied.
Code signing and firmware signatures with decade-long validity
Justifying migration budget to a sceptical finance function
The operating pattern for PQC & Quantum Migration.
The same delivery discipline applies across every capability in this line, so combined engagements stay coherent.
Integration
- Certificate lifecycle management and PKI platforms already in place.
- HSM estate, key management services and cloud KMS.
- CI/CD pipelines, so crypto inventory stays current as code ships.
- Asset and configuration management for device and endpoint coverage.
Engagement approach
Most clients begin with discovery and risk mapping as a contained first phase, because nothing else can be planned credibly without an inventory. Migration then runs in waves aligned to certificate renewal and platform refresh cycles rather than as a separate programme.
Other capabilities in PQC & Quantum Migration.
Cryptographic Discovery
You cannot migrate cryptography you cannot find.
PQ-02CBOM / SBOM Enrichment
Extend the software bill of materials until it answers cryptographic questions.
PQ-04Crypto-Agility Architecture
Design so the next algorithm change is a configuration decision, not a rebuild.
PQ-05Hybrid PQC Migration
Run classical and post-quantum together until the ecosystem is ready to drop one.
PQ-06PKI Modernization
Rebuild the certificate authority estate so it can issue what comes next.
PQ-07Digital Signature Migration
Protect signatures that must remain verifiable for decades.
PQ-08Secure Communication Migration
Make the channels quantum-safe without breaking the people who use them.
PQ-09IoT / OT PQC Migration
The hardest estate: constrained devices with long lives and no easy update path.
PQ-10PQC Test Lab & Validation
A place to break things before production does it for you.
PQ-11Governance & Reporting
Keep a multi-year cryptographic programme honest between milestones.
PQ-12Training & Capability Transfer
Leave the client able to run the programme without the consultant.