01
Data platform and storage
Where your data lives, how it is held, and what it costs to keep. Storage architecture, resilience, and retention that matches how long the data is actually sensitive for.
01 / Discover
Most organisations cannot list the data they store.
In Systems. In AI. On Servers and Drives. We then have Cryptography Gaps.
02 / Protect
The encryption around it has an expiry date.
NIST deprecates RSA and ECC in 2030. They are disallowed in 2035.
03 / Monitor
And nothing is watching it change.
Shadow AI. Silent drift. Risk that nobody owns.
Qubi Advisory Service
Discover What you Store - Cut What it Costs - Trust What AI Integrates.
The deadlines
None of these are predictions. They are published dates, and two of them have already started.
2035
The year RSA and ECC stop being allowed. They are deprecated from 2030. A full cryptographic migration takes most organisations between five and fifteen years.
NIST IR 8547
7%
Of global annual turnover. That is the ceiling for EU AI Act penalties, and the core obligations became fully applicable on 2 August 2026.
Regulation (EU) 2024/1689
95%
Of enterprise generative AI pilots produced no measurable return. Where the reasons were examined, the blocker was ownership and process rather than the model.
MIT NANDA, The GenAI Divide, 2025
Every one of these has the same first move, and almost nobody has made it: a complete inventory. You cannot migrate cryptography you have not catalogued, and you cannot govern an AI system you do not know exists.
How we work
The same three moves, whether the subject is a storage estate, a certificate, or a model somebody in finance started using last March.
01
We build the inventory nobody has: what data you hold and where it lives, which systems hold it, what cryptography protects it, and which AI systems are running inside your business whether or not anyone signed them off.
This is the unglamorous part, and it is the part that decides whether everything after it is real.
02
Then the work is prioritised by what is actually at risk. Long-lived sensitive data goes first, because that is what is worth stealing today and decrypting later. We migrate to the current NIST standards, usually in hybrid mode so nothing breaks while the estate catches up.
Governance is written at the same time, not afterwards, so the evidence exists when somebody asks for it.
03
Estates drift. Certificates expire, teams add tools, models get swapped, and an inventory that is not maintained is a document rather than a control.
We run monitoring and observability as a managed service, so the picture stays current and somebody is accountable for it at three in the morning.
What we do
Taken on individually, or run together as a managed service.
01
Where your data lives, how it is held, and what it costs to keep. Storage architecture, resilience, and retention that matches how long the data is actually sensitive for.
02
Classification, lineage, retention and access. Knowing what you hold, why you hold it, who can reach it, and when it should be gone.
03
Cryptographic inventory, risk ranking by data lifetime, and migration to ML-KEM and ML-DSA. Hybrid deployment so the estate stays compatible while it moves.
04
Discovering the AI already in use, classifying it by risk, and putting real ownership and controls behind it. Built to the AI Act and the NIST AI Risk Management Framework.
05
Knowing what your systems are doing while they are doing it. Instrumentation, alerting that means something, and the evidence trail that audits ask for.
06
The above, run continuously by us. Round-the-clock cover without you funding a rota, a tooling stack, and the people to sit behind them.
07
Knowing which jurisdiction can reach each dataset, and being able to prove it. Residency mapping, key custody so location stops deciding control, and the evidence pack that procurement and auditors keep asking for.
Why this is different from residency →Post-quantum cryptography
It is being stored. The technique has a name, harvest now, decrypt later, and it does not need a quantum computer to exist yet. It only needs one to exist before your data stops being sensitive.
So the question is not whether quantum computing is ready. It is how long your data stays valuable. Medical records, financial history, legal files, contracts, anything with a long life is already exposed to a decision somebody made about it years from now.
NIST finalised the replacement standards in August 2024: ML-KEM (FIPS 203) for key exchange, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures. The standards are settled. The migration is not.
The uncomfortable arithmetic
The first two dates are NIST's. The three durations are the estimates most commonly cited for a full migration, and they assume the work is planned rather than rushed. Put the two lists beside each other and the conclusion is awkward: for a lot of organisations, the comfortable start date was already a few years ago.
The migration, step by step
Six phases, following the structure NIST's own migration project uses. Each one ends with something you can hold, and each one is validated before the next begins. The order is not negotiable, because every later step depends on the inventory being real.
Find every place cryptography is actually used. Not where the documentation says it is. Where it is.
What you get
A cryptographic bill of materials covering certificates, TLS endpoints, key stores, application code, hardware and third party services.
How it is validated
Automated discovery is reconciled against your asset and network inventories. Nothing is counted as covered until something evidences it.
Typical duration
4 to 8 weeks
Turn that scan into a register somebody owns and keeps current. Discovery is a standing programme, not a one off exercise.
What you get
A living inventory in an open format: algorithm, key length, what it protects, who owns it, and when it expires.
How it is validated
Sample re-scans checked against the register, plus named owner sign off for every system in scope.
Typical duration
4 to 6 weeks, then continuous
Work out how long each dataset has to stay confidential. This is the step that sets the order of everything after it.
What you get
Data classified by sensitivity lifetime and mapped to the cryptography currently protecting it.
How it is validated
Retention and sensitivity confirmed by the business owner who is accountable for the data, not assumed by the technical team.
Typical duration
3 to 6 weeks
Rank the work by real exposure. Long lived sensitive data goes first, because that is exactly what harvest now, decrypt later is aimed at.
What you get
A sequenced plan with costs, owners and dependencies, written so it survives a board review.
How it is validated
Checked back against the register so no system quietly drops out of scope between planning and delivery.
Typical duration
2 to 4 weeks
Prove the replacement algorithms work in your estate before anything touches production.
What you get
Tested hybrid configurations, a measured performance impact, and a rollback path that has actually been run rather than written down.
How it is validated
Interoperability testing in a controlled environment, performance baselines against current state, and deliberate failure testing.
Typical duration
6 to 12 weeks
Roll out in hybrid mode so nothing loses compatibility while the rest of the estate catches up. Then keep watching, because estates drift.
What you get
Migrated systems, an updated register, and monitoring that flags drift before an auditor finds it.
How it is validated
A re-scan proving no deprecated algorithms remain in scope, then continuous alerting on anything new that appears.
Typical duration
Ongoing
All six have to be finished before RSA and ECC are disallowed in 2035. The first two are where most organisations have not started, and they are the ones everything else rests on.
Where it usually starts
None of that appears in a policy document. All of it is in scope.
AI governance
The EU AI Act's core obligations became fully applicable on 2 August 2026. Penalties reach €35 million or 7% of global turnover for prohibited practices, and €15 million or 3% for most high-risk breaches. If you sell into the EU, it applies to you regardless of where you are registered.
Most organisations cannot produce a complete list of the AI systems they are running, which makes risk classification impossible in principle rather than just difficult in practice. IBM's Cost of a Data Breach Report 2025 put breaches involving high levels of unsanctioned AI at around $670,000 more than those with little or none.
We start where the regulation starts. Find every system, classify it honestly, give each one a named owner, then write the controls. Policy written before the inventory is a document that describes a company you do not have.
Data sovereignty
Residency is a map reference. It tells you which building the server is in. Sovereignty is a legal question: whose courts can reach the data, and who has to comply when they ask.
The gap between those two matters more than most procurement processes admit. If your provider is a US company, the US CLOUD Act can compel disclosure of data it holds, including data physically sitting in London or Frankfurt. Choosing a UK region does not, on its own, put your data beyond that reach.
That is not an argument for panic or for repatriating everything. It is an argument for knowing. Most organisations cannot currently produce a list of which datasets live under which jurisdiction, which means they cannot answer the question when a regulator, a public sector framework, or a large customer's procurement team asks it.
The pressure is real and rising. Around 52% of UK business leaders say they are looking at bringing data back onshore, and sovereignty requirements are now routine in public sector procurement through G-Cloud and GovAssure. The Cyber Security and Resilience Bill extends that direction of travel further.
The same rule as everywhere else on this page: you cannot assert sovereignty over data you have not located.
How we help
Working with us
Start here
A fixed-scope inventory of one domain: cryptography, data, or AI. You get the register, the risk ranking and a sequenced plan. It stands on its own even if you never call us again.
Then
Migration and remediation against the plan, with your team involved rather than watched. Handover documentation is a deliverable with a date on it, not a favour at the end.
Ongoing
Monitoring, observability and inventory maintenance run continuously. Priced per month, cancellable, with the register handed over in a format you can read without us.
The most common complaint about consultants is not price. It is that the work gets delivered, the knowledge leaves with them, and the client is dependent from then on.
Straight answers
There is no machine today that breaks RSA at scale. That is not the point of the exercise. Encrypted traffic is being collected now by people who intend to read it later, so the risk lands on any data that is still sensitive in ten or fifteen years.
If everything you hold stops mattering in eighteen months, you can wait. If you hold medical, financial, legal or personal records, you are already inside the window.
Most of it starts with a policy template. We start with a search, because a policy written before you know what you are running describes an organisation you do not have.
The first deliverable is a list of every AI system actually in use, including the ones nobody approved, each with a risk classification and a named owner. The policy comes after that, and it is shorter and truer for it.
For breadth, you should not. A large firm covers more ground than we do.
What you get here is a narrow specialism and direct access. The person who scopes your work stays on it, and you are not paying for layers between you and the people doing it. On post-quantum readiness specifically, very few firms of any size have real depth yet, so the gap is smaller than the logos suggest.
A fixed-scope discovery engagement on one domain. We agree what is in scope, run the inventory, and hand back a register, a risk ranking and a sequenced plan with costs against it.
It is deliberately self-contained. If you take that plan and run it with your own team, the engagement still did its job.
No, and trying to is how these programmes stall. The order is set by how long each piece of data stays sensitive, so long-lived records move first and short-lived operational data waits.
Most estates move in hybrid mode, running a classical and a post-quantum algorithm together, so nothing loses compatibility while the migration works through.
Qubi Advisory Service Ltd, registered in Scotland, company number SC817271, incorporated in July 2024. The registered office is in Glasgow and the details are on the public Companies House register.
Get in touch
Tell us what you are worried about. If it is something we are good at, we will say so and tell you what it would take. If it is not, we will say that too.