Matrix CR Studio

NIST IR 8547 · 72-Hour Deliverable

Quantum Threat

Assessment

72-hour assessment that maps your cryptographic assets to NIST migration categories, overlays sector-specific data lifetime models, and produces store-now-break-later risk windows grounded in hardware-verified results.

Every assessment runs only against infrastructure you authorize in writing, from public and client-provided inputs. We scope to systems, never to individuals, and no probing begins before the engagement is signed.

BOOK A QTASEE THE 72-HOUR TIMELINE

The Mosca Theorem

X + Y > Z

Michele Mosca's inequality is the organizing principle of every quantum threat assessment worth paying for. It tells you (with arithmetic, not hand-waving) whether you are already too late to migrate.

X

Data shelf life

How long must this data remain confidential

Y

Migration time

How long to deploy PQC across this surface

Z

Q-Day horizon

Years until cryptographically-relevant quantum computer

Our Q-Day horizon estimate (Z) is anchored to the published cryptanalysis literature and to hands-on work running full Shor-ECDLP circuits on real IBM quantum hardware. Our runs did not yield a quantum break. We say so. The horizon shortens every year. Your data shelf life doesn't.

NIST IR 8547 Classification

Four categories. Four answers.

Every asset you own gets tagged with exactly one NIST IR 8547 category. The category determines the action.

Cat 1CRITICAL

Must transition: Shor-vulnerable

RSA · ECDSA · ECDH · DH · DSA

All public-key primitives that Shor's algorithm breaks in principle. We executed Shor-ECDLP circuits on real IBM quantum hardware (ibm_fez); key recovery was classical. No quantum break is claimed.

Cat 2HIGH

Must transition: Grover-weakened

AES-128 · SHA-256 (collision) · SHA-1 · MD5

Symmetric primitives whose effective strength halves under Grover. SHA-1 and MD5 are already classically broken.

Cat 3SAFE

No transition required

AES-256 · SHA-384 · SHA-512 · SHA3-family

Grover halves to 128-bit effective strength, still safely beyond brute force. Keep using these.

Cat 4MONITOR

Under study

Hash-then-sign · Lattice-based PAKE · Isogeny

Primitives where the NIST classification is still evolving. QTA flags these for monitoring rather than urgent action.

What This Means For Your Business

CRITICAL doesn't mean theoretical.

CRITICAL

Your current encryption is structurally broken by a cryptographically-relevant quantum computer. Not "weakened," broken. Any data encrypted with RSA, ECDSA, or ECDH that an adversary is storing today becomes readable on Q-Day. The only question is whether you migrate before they decrypt.

HIGH

Effective key strength is cut in half under Grover's algorithm. AES-128 drops to 64-bit effective security, insufficient for long-lived data. SHA-256 collision resistance is weakened. SHA-1 and MD5 are already classically broken and should have been replaced years ago.

MONITOR

AES-256 and SHA-3 are quantum-resistant at current key sizes. Grover halves effective strength to 128-bit, which remains beyond brute force. No immediate action required. Keep these in your stack and document them in your Crypto-SBOM as verified-safe.

UNDER STUDY

NIST is still evaluating these primitives. Some lattice-based and hash-then-sign constructions are likely safe; others are not. QTA flags these for monitoring so you are not caught off-guard when the classification resolves. Do not build new systems on unclassified primitives.

Sector Data Lifetime Model

Your sector dictates your X.

Defense classified programs have 35-year confidentiality windows. Banking records are bound by Basel III + AML lookback to 25 years. Tech product roadmaps expire in 10. QTA overlays your sector's data lifetime on every asset.

SECTORYEARSDRIVER
Defense35Classified programs · COMSEC
Insurance30Long-tail claims · reserves
Healthcare30HIPAA minimum + medical records lifetime
Banking25Basel III records + AML lookback
Pharma25Drug compound IP · clinical data
Government25FOIA · classification holds
Energy20SCADA · grid topology · safety systems
Legal20Attorney-client privilege · litigation
Telecom15Subscriber data · signaling
Manufacturing15Trade secrets · IP
Tech10Product roadmaps · source code

Store Now, Break Later

Four risk windows. Every asset gets one.

ACTIVE

Adversaries are recording your encrypted traffic today. Data lifetime exceeds the quantum-break horizon. By the time decryption is viable, your data is still confidential. You are already exposed.

IMMINENT

Narrow window. Data lifetime sits 3-7 years from quantum capability. Migration must begin this fiscal year to stay ahead of the decrypt window.

FUTURE

Exposure is real but deferrable. Data lifetime extends beyond current monitoring window but below the quantum-break horizon. Schedule for next planning cycle.

SAFE

Quantum-resistant primitives or short-lifetime data. No migration required. Focus resources elsewhere.

72-Hour Deliverable

From kick-off to signed report.

H+0

Kick-off

NDA executed. Asset inventory ingested via free-text, spreadsheet, or architecture document.

H+12

Surface enumeration

Cryptographic primitives extracted and tagged. NIST IR 8547 categories assigned to every asset.

H+24

Exposure scoring

MOSCA theorem applied: X + Y > Z. Sector-specific data lifetime overlaid. Store-now-break-later risk windows computed per asset.

H+48

Advisory cross-ref

Live KB cross-reference against CISA CNSA 2.0, NSA M-23-02, DORA Art. 6, SWIFT CSP, ETSI GR-QSC-004 (10 advisories total).

H+72

Deliverable

Executive brief (150w) + technical roadmap (400w) + evidence file. Cryptographically signed. Telegram digest optional.

Live Advisory Cross-Reference

Ten frameworks. One report.

Every QTA finding is tagged to the specific regulatory advisory it maps to. When the board asks "which framework requires this?" the answer is already in the deliverable.

NSA · US

CNSA 2.0

CISA · US

Quantum-Readiness

OMB · US

M-23-02

NIST · US

IR 8547

NIST · US

SP 800-227

ENISA · EU

PQC Guidance

DORA · EU

Article 6 · ICT Risk

ETSI · EU

Quantum-Safe Crypto

SWIFT · Global

CSP / CSCF

BSI · DE

Migration to PQC

Engagement Status

Quantum Threat Assessments are available as pilot engagements: fixed-scope, NDA-protected, with a signed deliverable and live advisory cross-reference. We have executed 512 hardware-validated quantum runs and published three self-retractions when our own re-analysis overturned prior claims. We are actively seeking our first production QTA deployment partners. Pilot pricing available for LATAM operators and defense-adjacent organizations.

Get Started

Know your exposure.
In 72 hours.

Three-day turnaround. Executive brief + technical roadmap + live advisory cross-reference.

Every finding cryptographically signed. Every claim anchored to empirical hardware results. Acceptable to federal auditors and board risk committees.

BOOK A QTATRY THE NIST SELECTORSEE THE HARDWARE PROOF