EXECUTIVE BRIEFING
A register of scored assets is not a decision, and a board cannot act on a heat map. An Executive Briefing is a working session with the people who allocate budget and carry the risk, built on an exposure position we or your own team have already established. We work through what expires and when, which obligations already apply, what changes if the work is deferred by a cycle, and which sequence of steps is defensible to an auditor. What leaves the room is a written record of the decisions taken and who owns each one.
AutoPQC · board view
- MED
exposure-position
75/100 — Elevated
- MAP
regulatory-map
CNSA 2.0 · DORA
- OK
decision-list
owners named
- MED
migration-window
estate-dated
- OK
next-review
minuted
Illustrative — synthetic reference estate, not customer data
- Duration
- [PLACEHOLDER: engagement duration, Executive Briefing]
- Method
- theos-method-v1.0
- Surface
- The executive team
- Depth
- Position · dates · owners
- Artefact
- Decision minute
- Standards
- CNSA 2.0 · DORA
The starting point
The board will ask for a number, not a standard.
Somewhere between the procurement questionnaire and the audit committee, the question stops being cryptographic and becomes fiduciary: what is exposed, what does it cost to close, and who owns each date. The briefing exists to carry an exposure position into that room in the language the room uses — and to leave decisions behind, not slides.
Scope
In scope, and not in scope
In scope
- A structured read of your current exposure position: the aggregate score, the tier distribution beneath it, and what each tier means in operational terms.
- The expiry and dependency calendar: what lapses first, what is blocked by a counterparty or by hardware, and where a decision has a deadline attached.
- Regulatory obligations that already apply, cited to their issuing documents rather than to a vendor summary.
- The consequence of deferral stated in operational terms: which windows close, which options narrow, and which work becomes sequential instead of parallel.
- The decision set for the coming cycle, framed so each option has a named owner, a scope and a verifiable completion condition.
- The questions your board, audit committee or regulator is likely to ask, and the evidence that answers each one.
Not in scope
- A budget figure or a cost-of-delay number. We will not put a currency value on deferral, because a defensible one would need cost data we do not have.
- A date for when a quantum computer breaks a given primitive. No such date is defensible, and we decline to supply one for a slide.
- An audit opinion or a certification. We are not an audit firm and no output of this session is assurance a third party can rely on.
- Penetration test findings, incident response readiness, or any security programme review beyond cryptography.
- Identity governance, cloud posture management, and vendor risk assessment generally.
- Discovery. This session reads an exposure position; it does not establish one. If none exists, start with an Estate Inventory.
Surfaces
What we look at
01
The current position
The aggregate estate score and the distribution of tiers beneath it, read together so an average never hides a small set of acute assets.
02
The expiry calendar
Certificates, keys and vendor support windows in date order, with the decisions that must be taken before each one closes.
03
Obligations already in force
The published requirements that apply to your sector today, including the CNSA 2.0 timeline for federal-facing work and DORA for financial entities in the EU, each cited to its issuing document.
04
The migration window
The Mosca inequality applied to your own inputs, with the inputs visible so the conclusion can be argued with. The working tool is at the migration window calculator.
05
Deferral consequences
What changes if the next cycle is skipped: options that expire, parallel work that becomes sequential, and renewals that turn into coordinated programmes.
06
The decision set
Each candidate decision with its scope, owner, dependencies and the condition under which it can be called complete.
Scoring
How it is scored
The session uses the scores your register already carries rather than producing new ones, and the five dimensions of the Theos Method give the vocabulary for the discussion: Primitive Fragility, Confidentiality Horizon, Reachability, Change Cost and Substitution Gap. The value at board level is that they separate urgency from difficulty. Two assets can share a tier while one is a configuration change and the other is a procurement cycle, and a decision-maker needs that difference on the table. The weights behind the aggregate are published on the methodology page and are not restated in the briefing pack.
Read the method specificationDeliverables
What you receive
01
Primary artefact
Board Summary
PDF written for a non-specialist reader
The exposure position, the obligations in force, the decision set and the recommended sequence, in language a board can act on without a translator.
02
Decision Record
PDF, one row per decision with owner and target date
What was decided in the session, what was deferred, who owns each item, and the condition that closes it. Circulated after the session as the working record.
03
Remediation Sequencing Plan
PDF with a CSV work-item export
The sequence agreed in the room, in the same format Migration Engineering executes against, so the decision and the delivery plan are one document.
04
Evidence Pack
Archive with a
sha256manifestThe register extract, source citations and calculation inputs behind every figure in the Board Summary, hashed so a later reader can check the pack against what was presented.
Evidence
Evidence and reproducibility
Every number in the briefing pack traces to a row in your register or to a public document we cite by name and identifier. Scores are quoted with the method version that produced them, theos-method-v1.0, so a figure repeated in a board minute six months later can still be checked. Where a question cannot be answered from evidence we hold, the pack records it as open rather than filling the gap with an estimate. Reproducing our numbers is the procedure we hand to anyone who wants to verify a figure independently.
The standards floor
What the work stands on
Eight standards, runtime and custody lines sit underneath every engagement in the catalogue. Each card names the groundwork the estate needs for it to land, and the failure mode it retires.
FIPS 203
ML-KEM — key establishment
The module-lattice key-encapsulation standard. It replaces classical key exchange in TLS 1.3 handshakes, tunnel establishment and key wrapping — the surfaces where traffic captured today can be stored against a future decryption.
- Groundwork
- A runtime line that can load a post-quantum provider, stated per service rather than assumed estate-wide.
- Risk retired
- Sessions recorded now being opened later, once the classical exchange underneath them falls.
FIPS 204
ML-DSA — digital signatures
The module-lattice signature standard, the replacement path for RSA and ECDSA signing across code, documents and server authentication. During a transition it runs alongside the classical signature rather than instead of it.
- Groundwork
- A signing pipeline that can carry two signatures on one artefact for the length of the transition window.
- Risk retired
- A forged release or a forged server identity signed by an algorithm that no longer resists forgery.
FIPS 205
SLH-DSA — hash-based signatures
The stateless hash-based signature standard: the conservative member of the family, resting on hash-function assumptions alone. Its natural home is firmware and other signatures that must still verify decades from now.
- Groundwork
- Room in the artefact path for a larger signature than the lattice schemes produce.
- Risk retired
- A structural surprise in lattice mathematics taking both primary schemes down at once.
Policy
CNSA 2.0 — the dated timeline
The published NSA algorithm suite sets dates, not suggestions: post-quantum operational across national-security systems by 2030, exclusive by 2035. Even estates far from that perimeter inherit its dates through their suppliers.
- Groundwork
- A register the timeline can be laid against, asset by asset, rather than a single estate-wide guess.
- Risk retired
- Discovering a contractual algorithm deadline in a procurement questionnaire instead of in your own plan.
Transition
Hybrid establishment — classical + ML-KEM
The transition posture for key establishment: derive the session from a classical curve and ML-KEM together, so a flaw in either primitive alone leaves the session standing. Mainstream clients already advertise the combined group.
- Groundwork
- TLS 1.3 endpoints, and visibility into which peers negotiate the hybrid group and which quietly do not.
- Risk retired
- Betting the confidentiality of day-one traffic on a single primitive, new or old.
Runtime
The provider-capable runtime line
Post-quantum negotiation arrives through the runtime, and an estate pinned to older lines does not negotiate it. The version actually loaded per service is a finding in its own right, not a build-system detail.
- Groundwork
- Retiring the oldest runtime pins — or naming them in the register as accepted, dated exceptions.
- Risk retired
- One service negotiating hybrid while its neighbour, one pin behind, silently falls back to classical.
Tooling
Open post-quantum tooling, pinned
The open-source implementations the ecosystem tests against. Where they appear in an estate we record the exact build, because a reviewed library and a deployed library are only the same thing if their hashes say so.
- Groundwork
- A pinned build with its hash recorded in the register, not a floating dependency.
- Risk retired
- Drift between the implementation that was reviewed and the one that ships the following quarter.
Custody
KMS and HSM key custody
Where the keys actually live. Managed key services and hardware modules are adding post-quantum key types on their own schedules, and custody boundaries — who can wrap, rotate, restore — decide how a migration lands there.
- Groundwork
- Audit access to key inventories and rotation policy. Key material itself never crosses the boundary.
- Risk retired
- A replica, backup or recovery region migrating out of step with the primary it must mirror.
Inputs
Inputs and duration
- Duration
- [PLACEHOLDER: engagement duration, Executive Briefing]
- Precondition
- An exposure position for the estate, whether from this catalogue or produced by your own team.
- What we need beforehand
- The current register or its equivalent, your certificate and key expiry data, and the sectoral obligations you already track.
- People we need
- The accountable executive, the security or technology leader who owns delivery, and one person who can speak for audit or compliance.
- What we never ask for
- Private keys, production credentials, board minutes, or anything covered by legal privilege.
- Handover
- The Decision Record circulated to attendees, with each open item carrying a named owner.
Questions
Questions we are asked
- Is this a presentation or a working session
- A working session. We bring the position, the obligations and the options; the room takes the decisions. If nobody in attendance can commit to an owner or a scope, the session produces a record of what still needs deciding, which is a weaker outcome than it should be.
- Can you tell us how much deferring a year will cost
- Not in currency. We can state what a deferral changes operationally: which renewals become coordinated programmes, which options close, and which work loses the ability to run in parallel. A monetary figure would be a rhetorical device rather than a measurement.
- What this engagement will not tell you
- It will not tell you when quantum attack becomes practical, and it will not certify your position to anyone. It reads the evidence you have, states what already obliges you, and frames the decisions in front of you. Any figure that would need a date for quantum capability is absent by design, not by oversight.
- Do we need an Estate Inventory first
- You need an exposure position, and an Estate Inventory is the usual way to get one. If your own team holds a credible inventory we will work from it, and we will say plainly where its coverage is thinner than the decisions being taken require.
- Who should be in the room
- The executive who can allocate the work, the leader whose teams will do it, and someone who can speak for audit or compliance. Briefings that omit the third seat tend to reopen once an assessor asks for evidence.
Signed · Verifiable
Every engagement in the catalogue ends with a Posture Attestation you can verify.
The attestation names the scope, the method version and the date, and anyone holding its code can check it on this site.
Related reading
Three articles that go further
The scope conversation
Take Executive Briefing to a scope conversation
Tell us the estate you have in mind and we will walk through what this engagement would cover, what it would produce, and where its boundary sits — before anything is signed. If you would rather put questions in writing first, write to us instead.