HomeServices
Corporate Training Security Compliance Guide VAPT as a Service
AboutRecent Trends Get Started
Training Track

Quantum-proof InfoSec
& Compliance Training.

Connect your information-security program and regulatory obligations to the post-quantum transition. This track shows compliance, GRC and security teams how ISO, SOC 2, FedRAMP and friends are evolving to expect crypto-agility.

Quantum-proof InfoSec & Compliance training illustration
2035
NSA CNSA 2.0 Transition Deadline
6
Frameworks Mapped to PQC
2024
Year NIST PQC Standards Published
5
Course Modules

Compliance Is Becoming a Post-Quantum Requirement

Auditors and the frameworks they assess against are starting to expect crypto-agility and a documented cryptographic inventory rather than treating encryption as a black box. Under a "harvest now, decrypt later" threat, any regulated data with a long retention obligation faces retroactive exposure — and the liability that comes with it — the moment it leaves your perimeter. Guidance from NIST and the NSA's CNSA 2.0, with its 2035 transition deadline, is already signalling the timeline your compliance program will be measured against.

What You'll Learn

Inside the Quantum-proof InfoSec & Compliance Track

Framework-aware content that turns post-quantum readiness into auditable control evidence — every highlight below maps to a module in the detailed course syllabus.

How the PQC transition intersects ISO/IEC 27001, SOC 2 and the NIST Cybersecurity Framework

Building a cryptographic inventory (CBOM) in a form your auditors will accept as evidence

Mapping crypto-agility to existing controls so readiness lives inside your current program

Data-retention and harvest-now-decrypt-later liability for long-lived regulated records

Evidencing quantum-readiness to assessors, customers and the board with confidence

Explore the full module-by-module syllabus
Duration Options

Choose the Format That Fits

Three delivery depths — from a leadership briefing to a full hands-on lab — all tailored to your frameworks and audit cycle.

1 day

Executive Briefing

A leadership session that frames the regulatory exposure and builds the case for funding a readiness program — no technical prerequisites.

Regulatory awareness & risk framing Executives, GRC leaders & risk owners Workshop format, slides & Q&A
Most Popular
2 days

Technical Deep-Dive

For compliance and security teams: how PQC maps to your frameworks, building a CBOM and drafting a control-aligned readiness plan.

Framework mapping & control evidence GRC managers, auditors & security leads Worked examples + readiness workshop
5 days

Hands-On Lab

Full immersion: populate a CBOM, map controls across multiple frameworks and ship a capstone compliance roadmap to 2035.

Hands-on inventory & mapping work GRC, audit & security program teams Capstone roadmap + assessment
Prerequisites

What You Need to Start

Recommended Background

General security or GRC awareness — this is a compliance track, not a cryptography course

Familiarity with at least one framework such as ISO 27001, SOC 2 or the NIST CSF

No cryptography or coding expertise required — the technical depth is provided in plain language

What We Provide

A cryptographic-inventory (CBOM) template ready to populate against your environment

Control-mapping worksheets that align PQC readiness to ISO 27001, SOC 2 and the NIST CSF

A quantum-readiness checklist so every attendee leaves with a concrete next-step list

Who Should Attend

Built for Every Role in the Compliance Program

Content is pitched to each audience so program owners, leaders and assurance functions all leave with what they need.

GRC & Compliance Managers

Own the frameworks, control libraries and the evidence that satisfies certification audits.

Leave able to fold crypto-agility into existing controls and produce audit-ready PQC evidence.

CISOs & Security Leaders

Set the strategy, secure budget and answer to regulators, customers and the board.

Leave with a defensible, framework-aligned readiness roadmap mapped to the 2035 deadline.

Internal Auditors & Risk Officers

Test controls, assess exposure and report on the organisation's readiness posture.

Leave able to evaluate cryptographic risk and quantum-readiness as part of the audit plan.

Outcomes & Deliverables

What Your Team Walks Away With

Capabilities and tangible artifacts that translate directly into your compliance and audit program.

Capabilities Gained

A shared, accurate view of how the PQC transition touches each framework you maintain

The control language and evidence patterns that satisfy assessors on crypto-agility

A repeatable method for folding quantum-readiness into existing risk and policy cycles

Confidence to answer auditor and customer questions on your post-quantum plans

Tangible Deliverables

A cryptographic inventory (CBOM) mapped to the controls in your chosen frameworks

A quantum-readiness gap assessment that pinpoints where your program falls short today

A prioritised compliance roadmap sequenced toward the 2035 transition deadline

An auditor-ready evidence pack you can drop straight into your next assessment

A QSECS certificate of completion for every participant

Detailed Course Syllabus

A Module-by-Module Curriculum

Five modules scaling from the regulatory landscape to a hands-on compliance roadmap. Select a module to expand it.

1.1

The Quantum Threat for Compliance

Why quantum-relevant computing and harvest-now-decrypt-later turn cryptography into a compliance concern.

1.2

NIST & NSA Guidance

The finalised NIST PQC standards and the NSA CNSA 2.0 timeline that sets the 2035 transition deadline.

1.3

Crypto-Agility as a Control Objective

What crypto-agility means in practice and why frameworks are starting to expect it as evidence.

1.4

The Regulatory Direction of Travel

How sector regulators and assurance standards are signalling post-quantum expectations.

2.1

Why Auditors Want an Inventory

The case for a cryptographic bill of materials as the foundation of any readiness claim.

2.2

Cryptographic Discovery

Finding where crypto lives — applications, TLS endpoints, certificates, vendors and data stores.

2.3

Building a CBOM

Producing a Cryptographic Bill of Materials structured so an assessor will accept it as evidence.

2.4

Keeping the Inventory Current

Operationalising the CBOM so it stays accurate between audit cycles rather than going stale.

3.1

PQC in ISO/IEC 27001

Where crypto-agility lands in Annex A controls, the risk register and the statement of applicability.

3.2

PQC in SOC 2

How post-quantum readiness intersects the Trust Services Criteria and your control narratives.

3.3

PQC in the NIST CSF

Aligning readiness work to the Identify, Protect and Govern functions of the framework.

3.4

Writing the Evidence

Turning inventory and roadmap artifacts into control language and evidence assessors can test.

4.1

FedRAMP & NIST SP 800-53

Cryptographic-control expectations for cloud services and how PQC readiness fits the baseline.

4.2

PCI DSS & Payment Data

Where strong-cryptography requirements meet the post-quantum question for cardholder data.

4.3

Data-Retention & HNDL Risk

Triaging long-retention regulated data by the secrecy lifetime it must survive.

4.4

Liability & Disclosure

Understanding the retroactive-exposure liability that long-lived data carries today.

5.1

Gap Assessment

Scoring current readiness against frameworks to surface where the program falls short.

5.2

Prioritisation to 2035

Risk-ranking systems and sequencing the work against the transition deadline.

5.3

Building the Roadmap

Drafting a compliance roadmap with owners, milestones and control checkpoints.

5.4

Capstone

Assemble and present an auditor-ready readiness package for a realistic regulated scenario.

Certificate of Completion

Quantum-proof InfoSec & Compliance

Awarded by QSECS · Quantum Security Solutions

Issued to
Your Team Member
Credential
QSECS-QIC
Certification

Recognised Proof of Quantum-Readiness

Every participant who completes the track receives a verifiable QSECS Certificate of Completion — a credible signal to leadership, auditors and customers that your compliance program is preparing for the post-quantum era.

Individually issued with a unique, verifiable credential ID

Hands-on and lab tracks include a graded capstone assessment

Maps to continuing-education (CPE) hours for common security and audit certifications

Shareable to LinkedIn and your internal skills matrix

Sample Agenda

A Day in the Technical Deep-Dive

An illustrative Day 1 from the 2-day format — every agenda is tailored to your frameworks before delivery.

09:00

Welcome & the Regulatory Landscape

Framing the post-quantum exposure, the 2035 timeline and what it means for your compliance obligations.

10:30

Building a CBOM Auditors Accept

Cryptographic discovery and structuring an inventory that stands up as audit evidence.

13:30

Mapping PQC to Your Frameworks

Where crypto-agility lands in ISO 27001, SOC 2 and the NIST CSF — with worked control language.

15:30

Data-Retention & HNDL Liability

Triaging long-retention regulated data and the retroactive-exposure risk it carries.

16:45

Workshop: Your Readiness Gap

Score a sample program against a framework and identify the highest-priority gaps to close.

Day 2 covers FedRAMP and PCI DSS expectations, evidence writing and a roadmap-planning workshop to 2035.

FAQ

Frequently Asked Questions

Everything teams usually ask before booking the quantum-proof InfoSec & compliance track.

No. This is a compliance and GRC track, not a cryptography course. We expect general security awareness and familiarity with at least one framework such as ISO 27001 or SOC 2; the technical depth is delivered in plain language, and we send a readiness checklist beforehand.

We map post-quantum readiness to ISO/IEC 27001, SOC 2, the NIST Cybersecurity Framework, FedRAMP with NIST SP 800-53, and PCI DSS — alongside the NIST PQC standards and NSA CNSA 2.0 guidance that set the direction.

All three. We run sessions in-person at your site, fully remote, or hybrid — across time zones for distributed teams. The hands-on inventory and mapping work runs in a hosted environment so delivery mode never changes the experience.

Directly. The control-mapping worksheets and CBOM template are built to slot into your current ISO, SOC 2 or NIST CSF evidence, so quantum-readiness becomes part of your normal audit cycle rather than a separate exercise.

Yes. We tailor the examples, framework focus and data-retention scenarios to your sector and obligations, and can anchor the roadmap workshop to your real control set under NDA. Tailoring is scoped during the requirement-analysis call.

Yes — every participant receives a verifiable QSECS Certificate of Completion, and hands-on tracks include a graded capstone. The credential maps to CPE hours for common security and audit certifications.