PQC SUITE
Find it. Assess it. Migrate it.
One path through the post-quantum transition. Three live tools that take you from the cryptography you cannot yet see, to systems safely migrated.
Live now · Built on filed UK patents · Member of NVIDIA Inception
Why now
The deadline is no longer theoretical.
2030 and 2031
US Executive Order 14412 requires federal systems to migrate to post-quantum key establishment by the end of 2030, and digital signatures by the end of 2031. Regulated industries follow.
End of 2026
The EU roadmap asks organisations to hold a complete cryptographic inventory by the end of this year. CISA and NIST are defining the minimum elements of a cryptographic bill of materials.
Already happening
Harvest now, decrypt later. Encrypted data stolen today can be unlocked the moment quantum hardware matures. A 2030 deadline does nothing for data taken in 2026.
Most organisations cannot answer three questions.
What cryptography are we actually running? How exposed does that leave us? And what do we fix first?
You cannot prioritise what you have never measured. Discovery tools hand you a list and leave the hard part to you. The suite was built to close that gap.
One path, three steps
Each tool is sold standalone or as a suite. Discovery is the entry point.
Step 01 · Discover
CETI-VCC
Discover every piece of cryptography you run, and turn it into a verified inventory you can trust.
Cryptography hides in different places in every estate: in certificates, in configuration, in live connections, in dependencies you inherited years ago. One discovery pass covers all of it.
What comes back is not a raw scan. Every finding carries a stated confidence level, so you can see immediately which parts of your inventory are solid and which need a closer look before you act on them.
- Verified Cryptographic Inventory, exported as a CycloneDX CBOM
- Discovery confidence and coverage, stated explicitly
- Quantum-exposure map
- Deprecated-primitive findings
- Branded PDF report for audit and board use
- Machine-readable handoff into USMC and CADRE
Step 02 · Assess
USMC
Quantify how much cryptographic security margin you actually hold, and what to migrate first.
Almost every tool in this market assesses by severity: flag the weak algorithm, rank by asset criticality, produce a list. That tells you what looks bad. It cannot tell you how much margin you hold, so it cannot tell you when you are done.
USMC reports two complementary outputs. The QRESB Assurance Index is a composite decision-support metric that summarises overall posture for boards, auditors and assurance stakeholders. Where the assessment mode and available evidence support it, the report also states an estimated security margin in bits: a conservative lower bound on attacker work-factor relative to the 128-bit post-quantum threshold, always identified as an estimate and accompanied by its assumptions and evidence confidence.
Where evidence coverage is too low to assess, USMC returns Insufficient Evidence rather than a verdict.
That matters. Security teams have been handed too many confident-looking scores built on incomplete input. Refusing to score is what makes the scores we do produce worth something to an auditor.
Assess your marginStep 03 · Migrate
CADRE
Move systems to quantum-safe cryptography in controlled, reversible waves.
A migration plan is not a migration. CADRE takes your verified inventory and your assurance result and turns them into sequenced work, ordered by risk, dependency and readiness.
Nothing changes on an assumption. Every change can be undone. And after each wave, your assurance position is measured again, so progress is expressed as real movement rather than a count of closed tickets.
- Migration roadmap, sequenced into waves by risk, dependency and readiness
- Dependency verification, tested rather than assumed
- Transactional remediation, with no half-migrated states
- Assurance-margin tracking after each wave
- Migration priority ranking, largest gain per unit effort first
- Enterprise delivery controls: safety gates, canary rollout, dual approval for critical infrastructure
Why this suite
What makes the suite different
We measure, we do not just score
A composite assurance index for the board, and an estimated security margin in bits against the 128-bit post-quantum threshold. That comes from our own work on bounding cryptographic security, protected by filed UK patents.
We say when we do not know
Insufficient Evidence is a supported result. Every estimate ships with its assumptions and its evidence confidence.
Migration is reversible
Dependencies are verified before anything changes, and every change can be rolled back. That is what makes a cryptographic change authorisable in a regulated production environment.
Built on physics, not policy libraries
The methods behind the suite come from original theoretical work, filed as UK patents, rather than from a compliance mapping.
Built for the people who own the migration.
CISOs, heads of cryptography, named post-quantum migration leads, and the cybersecurity consultants and managers who advise them.
In banks, insurers and payment providers; critical national infrastructure; government and defence; and healthcare. Across the UK, EU and USA.
If your organisation holds sensitive data with a confidentiality life of ten years or more, harvest now, decrypt later already applies to you.
Pricing
Start with one engine, or take the whole path.
Single engine
Professional
£3,500
per month
or £35,000 per year — save 17%
One engine of your choice. Discovery is the usual starting point.
Buy nowAll three engines
The PQC Suite
£8,500
per month
or £85,000 per year
CETI-VCC, USMC and CADRE as one path with handoff between each step. Around 20% below buying separately.
Buy the suiteScaled coverage
Enterprise
Contact us
Annual contract
Scaled coverage across the estate, onboarding and support.
Contact salesBespoke deployment
Defence & Critical Infrastructure
Contact us
Enhanced delivery controls
Bespoke deployment, enhanced delivery controls, dual approval workflows.
Contact salesStart with discovery.
See your cryptography, then your exposure, then your path. Discovery is the entry point, and it is the slowest part of the job, so it is the part worth starting now.
Start with discoveryCETI-VCC is covered by UK patent application GB2616659.5. CADRE is covered by UK patent application GB2616169.5. USMC is built on QRESB, UK patent application GB2610441.4. Patent applications are filed and pending.
Physivitis Ltd · Deep-Tech IP and Software · physivitis.tech