A foundational-to-hands-on track on how quantum computing reshapes the threat landscape and how to defend against it. Teams leave fluent in the NIST PQC standards — ML-KEM, ML-DSA and SLH-DSA — and ready to plan a real-world migration.
The Data You Encrypt Today Is Already Exposed
Public-key cryptography — RSA, ECC and Diffie-Hellman — secures virtually every TLS session, digital signature and VPN in use today, and a cryptographically-relevant quantum computer breaks all of it at once. Worse, ciphertext captured now can be stored and decrypted later, so any data whose secrecy must outlast the early 2030s is effectively at risk the moment it leaves your network. The NSA's CNSA 2.0 guidance already fixes 2035 as the deadline for national-security systems to finish moving to post-quantum algorithms — and enterprise timelines are only shorter.
A blend of threat-model fundamentals and practical cryptography your engineers can apply immediately — every highlight below maps to a module in the detailed course syllabus.
How Shor's and Grover's algorithms break RSA & ECC and weaken symmetric cryptography
The NIST PQC standards — ML-KEM (Kyber), ML-DSA (Dilithium) and SLH-DSA (SPHINCS+)
Hybrid key-exchange and signature schemes for a safe, staged transition
Building a cryptographic inventory (CBOM) and a prioritised migration roadmap
Harvest-Now-Decrypt-Later risk and protecting long-lived sensitive data
Three delivery depths — from a leadership briefing to a full hands-on lab — all tailored to your stack and team.
A boardroom-level session that builds shared urgency and a funding case — no technical prerequisites.
For architects and engineers: the standards, hybrid protocols and a migration plan, with guided demos.
Full immersion: implement PQC, stand up hybrid TLS, build a CBOM and ship a capstone migration plan.
General security awareness — no cryptography expertise required for the executive briefing
Basic familiarity with TLS, PKI and certificates for the technical deep-dive
Comfort with one programming language (Python, Go, Java, Rust or C/C++) for the hands-on lab
A ready-to-use lab sandbox with OpenSSL, liboqs and sample codebases — no local setup needed
Slide decks, quick-reference cards and a CBOM inventory template to keep
A pre-session readiness checklist so every attendee arrives at the right level
Content is pitched to each audience so leaders, builders and risk owners all leave with what they need.
Own the cryptographic strategy and the migration design across the enterprise.
Leave able to design crypto-agile systems and lead a standards-based PQC rollout.
Implement and ship the cryptography that production systems depend on.
Leave able to integrate ML-KEM/ML-DSA and hybrid handshakes into code and CI pipelines.
Set priorities, secure budget and answer to regulators and the board.
Leave with a defensible business case, risk model and roadmap mapped to the NIST timeline.
Capabilities and tangible artifacts that translate directly into your post-quantum migration program.
A shared, accurate mental model of the quantum threat across technical and leadership roles
Hands-on familiarity with PQC algorithms and how to evaluate them for your stack
A repeatable method for discovering and prioritising cryptographic assets
Confidence to design hybrid deployments that fail safe during the transition
A cryptographic inventory (CBOM) template and the method to populate it
A prioritised PQC migration roadmap mapped to the NIST 2030-2035 deadline
Reference hybrid TLS / handshake configurations and working code samples
A decision matrix for selecting ML-KEM, ML-DSA and SLH-DSA per use case
A QSECS certificate of completion for every participant
Five modules scaling from threat fundamentals to a hands-on migration capstone. Select a module to expand it.
Qubits, superposition and entanglement — only the physics you need to reason about cryptographic risk.
Why RSA, Diffie-Hellman and ECC fall to a cryptographically relevant quantum computer.
The quadratic speed-up against symmetric ciphers and hashes — and why doubling key sizes is the answer.
The store-and-wait attack model and how to triage data by its required secrecy lifetime.
How the standards were selected, the FIPS 203/204/205 outcomes and what comes next.
Lattice-based key encapsulation — parameters, performance and where it replaces today's key exchange.
The default post-quantum signature scheme: sizes, speed and signing trade-offs.
Hash-based, conservative signatures for firmware and long-lived roots of trust.
Combining classical and PQC algorithms so a break in either still leaves you protected.
X25519+ML-KEM groups, handshake sizing and interoperability considerations.
Composite and hybrid certificates, CA readiness and chain-of-trust migration.
SSH, VPN/IPsec, code signing and messaging — sequencing the rollout across protocols.
Finding every place crypto lives — code, libraries, TLS endpoints, secrets and hardware.
Producing a Cryptographic Bill of Materials and keeping it current in CI.
Designing systems where algorithms are configuration, not hard-coded assumptions.
Risk-ranking assets and sequencing a migration mapped to the 2030-2035 window.
Generate keys, encapsulate and sign using liboqs and OpenSSL provider tooling.
Stand up a server negotiating a hybrid group and inspect the handshake on the wire.
Scan a sample application and emit a CBOM, then triage its findings.
Draft and present a prioritised PQC migration plan for a realistic enterprise scenario.
Awarded by QSECS · Quantum Security Solutions
Every participant who completes the track receives a verifiable QSECS Certificate of Completion — a credible signal to leadership, auditors and customers that your teams are preparing for the post-quantum era.
Individually issued with a unique, verifiable credential ID
Hands-on and lab tracks include a graded capstone assessment
Maps to continuing-education (CPE) hours for common security certifications
Shareable to LinkedIn and your internal skills matrix
An illustrative Day 1 from the 2-day format — every agenda is tailored to your goals before delivery.
Framing the risk, the timeline and what "quantum-safe" actually means for your organisation.
Shor's algorithm against RSA/ECC and Grover's against symmetric primitives — with worked intuition.
ML-KEM, ML-DSA and SLH-DSA — parameters, performance and selection trade-offs.
Why hybrid first, and how it lands in TLS 1.3 and your PKI.
Stand up a server negotiating a hybrid group and inspect it on the wire.
Day 2 covers cryptographic discovery, building a CBOM, crypto-agility patterns and a migration-planning workshop.
Everything teams usually ask before booking the post-quantum cryptography track.
No. The executive briefing assumes no cryptography knowledge. The technical deep-dive expects basic familiarity with TLS/PKI, and the hands-on lab assumes comfort with one programming language. We send a readiness checklist beforehand so everyone arrives at the right level.
The current NIST PQC standards — ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) — plus hybrid key-exchange and signature schemes, and how they apply to TLS, SSH, VPNs, PKI and code signing.
All three. We run sessions in-person at your site, fully remote, or hybrid — across time zones for distributed teams. The hands-on labs run in a hosted sandbox so delivery mode never changes the experience.
We provide a ready-to-use cloud sandbox pre-loaded with OpenSSL, liboqs and sample codebases. Participants only need a browser — there's no local setup, and nothing touches your production systems.
Yes. We tailor examples and labs to your languages, cloud providers and protocols, and can anchor the migration workshop to your real architecture under NDA. Tailoring is scoped during the requirement-analysis call.
Continuously. The material tracks the finalised FIPS standards and ongoing NIST guidance, including additional signature candidates as they progress, so your teams learn what's current — not what's deprecated.
Yes — every participant receives a verifiable QSECS Certificate of Completion, and hands-on tracks include a graded capstone. The credential maps to CPE hours for common security certifications.