Connect your information-security program and regulatory obligations to the post-quantum transition. This track shows compliance, GRC and security teams how ISO, SOC 2, FedRAMP and friends are evolving to expect crypto-agility.
Compliance Is Becoming a Post-Quantum Requirement
Auditors and the frameworks they assess against are starting to expect crypto-agility and a documented cryptographic inventory rather than treating encryption as a black box. Under a "harvest now, decrypt later" threat, any regulated data with a long retention obligation faces retroactive exposure — and the liability that comes with it — the moment it leaves your perimeter. Guidance from NIST and the NSA's CNSA 2.0, with its 2035 transition deadline, is already signalling the timeline your compliance program will be measured against.
Framework-aware content that turns post-quantum readiness into auditable control evidence — every highlight below maps to a module in the detailed course syllabus.
How the PQC transition intersects ISO/IEC 27001, SOC 2 and the NIST Cybersecurity Framework
Building a cryptographic inventory (CBOM) in a form your auditors will accept as evidence
Mapping crypto-agility to existing controls so readiness lives inside your current program
Data-retention and harvest-now-decrypt-later liability for long-lived regulated records
Evidencing quantum-readiness to assessors, customers and the board with confidence
Three delivery depths — from a leadership briefing to a full hands-on lab — all tailored to your frameworks and audit cycle.
A leadership session that frames the regulatory exposure and builds the case for funding a readiness program — no technical prerequisites.
For compliance and security teams: how PQC maps to your frameworks, building a CBOM and drafting a control-aligned readiness plan.
Full immersion: populate a CBOM, map controls across multiple frameworks and ship a capstone compliance roadmap to 2035.
General security or GRC awareness — this is a compliance track, not a cryptography course
Familiarity with at least one framework such as ISO 27001, SOC 2 or the NIST CSF
No cryptography or coding expertise required — the technical depth is provided in plain language
A cryptographic-inventory (CBOM) template ready to populate against your environment
Control-mapping worksheets that align PQC readiness to ISO 27001, SOC 2 and the NIST CSF
A quantum-readiness checklist so every attendee leaves with a concrete next-step list
Content is pitched to each audience so program owners, leaders and assurance functions all leave with what they need.
Own the frameworks, control libraries and the evidence that satisfies certification audits.
Leave able to fold crypto-agility into existing controls and produce audit-ready PQC evidence.
Set the strategy, secure budget and answer to regulators, customers and the board.
Leave with a defensible, framework-aligned readiness roadmap mapped to the 2035 deadline.
Test controls, assess exposure and report on the organisation's readiness posture.
Leave able to evaluate cryptographic risk and quantum-readiness as part of the audit plan.
Capabilities and tangible artifacts that translate directly into your compliance and audit program.
A shared, accurate view of how the PQC transition touches each framework you maintain
The control language and evidence patterns that satisfy assessors on crypto-agility
A repeatable method for folding quantum-readiness into existing risk and policy cycles
Confidence to answer auditor and customer questions on your post-quantum plans
A cryptographic inventory (CBOM) mapped to the controls in your chosen frameworks
A quantum-readiness gap assessment that pinpoints where your program falls short today
A prioritised compliance roadmap sequenced toward the 2035 transition deadline
An auditor-ready evidence pack you can drop straight into your next assessment
A QSECS certificate of completion for every participant
Five modules scaling from the regulatory landscape to a hands-on compliance roadmap. Select a module to expand it.
Why quantum-relevant computing and harvest-now-decrypt-later turn cryptography into a compliance concern.
The finalised NIST PQC standards and the NSA CNSA 2.0 timeline that sets the 2035 transition deadline.
What crypto-agility means in practice and why frameworks are starting to expect it as evidence.
How sector regulators and assurance standards are signalling post-quantum expectations.
The case for a cryptographic bill of materials as the foundation of any readiness claim.
Finding where crypto lives — applications, TLS endpoints, certificates, vendors and data stores.
Producing a Cryptographic Bill of Materials structured so an assessor will accept it as evidence.
Operationalising the CBOM so it stays accurate between audit cycles rather than going stale.
Where crypto-agility lands in Annex A controls, the risk register and the statement of applicability.
How post-quantum readiness intersects the Trust Services Criteria and your control narratives.
Aligning readiness work to the Identify, Protect and Govern functions of the framework.
Turning inventory and roadmap artifacts into control language and evidence assessors can test.
Cryptographic-control expectations for cloud services and how PQC readiness fits the baseline.
Where strong-cryptography requirements meet the post-quantum question for cardholder data.
Triaging long-retention regulated data by the secrecy lifetime it must survive.
Understanding the retroactive-exposure liability that long-lived data carries today.
Scoring current readiness against frameworks to surface where the program falls short.
Risk-ranking systems and sequencing the work against the transition deadline.
Drafting a compliance roadmap with owners, milestones and control checkpoints.
Assemble and present an auditor-ready readiness package for a realistic regulated scenario.
Awarded by QSECS · Quantum Security Solutions
Every participant who completes the track receives a verifiable QSECS Certificate of Completion — a credible signal to leadership, auditors and customers that your compliance program is preparing for the post-quantum era.
Individually issued with a unique, verifiable credential ID
Hands-on and lab tracks include a graded capstone assessment
Maps to continuing-education (CPE) hours for common security and audit certifications
Shareable to LinkedIn and your internal skills matrix
An illustrative Day 1 from the 2-day format — every agenda is tailored to your frameworks before delivery.
Framing the post-quantum exposure, the 2035 timeline and what it means for your compliance obligations.
Cryptographic discovery and structuring an inventory that stands up as audit evidence.
Where crypto-agility lands in ISO 27001, SOC 2 and the NIST CSF — with worked control language.
Triaging long-retention regulated data and the retroactive-exposure risk it carries.
Score a sample program against a framework and identify the highest-priority gaps to close.
Day 2 covers FedRAMP and PCI DSS expectations, evidence writing and a roadmap-planning workshop to 2035.
Everything teams usually ask before booking the quantum-proof InfoSec & compliance track.
No. This is a compliance and GRC track, not a cryptography course. We expect general security awareness and familiarity with at least one framework such as ISO 27001 or SOC 2; the technical depth is delivered in plain language, and we send a readiness checklist beforehand.
We map post-quantum readiness to ISO/IEC 27001, SOC 2, the NIST Cybersecurity Framework, FedRAMP with NIST SP 800-53, and PCI DSS — alongside the NIST PQC standards and NSA CNSA 2.0 guidance that set the direction.
All three. We run sessions in-person at your site, fully remote, or hybrid — across time zones for distributed teams. The hands-on inventory and mapping work runs in a hosted environment so delivery mode never changes the experience.
Directly. The control-mapping worksheets and CBOM template are built to slot into your current ISO, SOC 2 or NIST CSF evidence, so quantum-readiness becomes part of your normal audit cycle rather than a separate exercise.
Yes. We tailor the examples, framework focus and data-retention scenarios to your sector and obligations, and can anchor the roadmap workshop to your real control set under NDA. Tailoring is scoped during the requirement-analysis call.
Yes — every participant receives a verifiable QSECS Certificate of Completion, and hands-on tracks include a graded capstone. The credential maps to CPE hours for common security and audit certifications.