01 / Cybersecurity & Cryptography
Sentinel
AI-Native Post-Quantum Cryptographic Readiness
Organizations cannot migrate cryptography they cannot see.
Cryptographic assets are scattered across source code, certificates, libraries, protocols, infrastructure, and policy. As CNSA 2.0 timelines approach, every RSA and ECC dependency is a potential outage, a compliance failure, or a harvest-now-decrypt-later exposure.
Sentinel ingests cryptographic evidence from static analysis of code, network protocol observation, infrastructure and configuration data, and policy mandates, and assembles it into a Crypto Asset Graph: a typed graph connecting cryptographic assets to the software, systems, and mission functions that depend on them.
On top of the graph, the platform scores risk by mission impact and HNDL exposure by data class, produces a dependency-aware migration roadmap in POA&M form, and then does the part most tooling skips: it predicts what will break. Predictive Migration Failure Detection forward-simulates each migration step against the graph, and a liboqs-based Migrate-and-Prove Harness validates candidate suites such as hybrid X25519 + ML-KEM-768 behaviorally before rollout.
Every finding is grounded against a file path, certificate serial, or mandate paragraph anchor, and the platform emits a machine-readable CycloneDX 1.6 CBOM alongside an executive mission-risk summary, so the evidence survives contact with an assessor.
The system answers
- Where is quantum-vulnerable cryptography being used?
- Which systems should migrate first, and in what order?
- What mission functions depend on those systems?
- What will break when an algorithm or implementation changes?
- What evidence proves the migration actually worked?
The Quantum Value Pipeline
- Discover Ingest cryptographic evidence from code, network protocols, infrastructure, and policy into the Crypto Asset Graph.
- Prioritize Score assets by mission impact and HNDL exposure by data class, not just algorithm age.
- Plan Generate a dependency-aware migration roadmap with sequencing constraints, in POA&M form.
- Prove Forward-simulate failure modes with PMFD, then validate migrations behaviorally in the liboqs harness.
- Evidence Emit an executive mission-risk summary, the roadmap, and a machine-readable CycloneDX 1.6 CBOM.
The Mandate Landscape
PQC migration is required, and the deadlines are set.
Post-quantum migration is no longer discretionary for federal systems. A connected set of statutes, memoranda, and standards defines what must move, and by when. Sentinel is built around these obligations: its mandate edges link discovered cryptographic assets to the specific requirement paragraphs they answer to.
Timeline last reviewed August 2026 · sources linked per instrument
- National Security Memorandum 10 (NSM-10)
-
Directs federal agencies to begin migrating vulnerable cryptographic systems to quantum-resistant cryptography, prioritizing the most sensitive systems first.
Mitigate as much quantum risk as feasible by 2035
- Commercial National Security Algorithm Suite 2.0 (CNSA 2.0)
-
Sets the quantum-resistant algorithm suite for national security systems. New NSS acquisitions must support CNSA 2.0 from January 1, 2027, and equipment that cannot support it phases out by the end of 2030.
NSS transition complete by 2033
- OMB Memorandum M-23-02, Migrating to Post-Quantum Cryptography
-
Requires annual cryptographic inventories from federal agencies, prioritization of high-impact systems and long-lived data, and designated migration leads.
Annual inventories through 2035
- Quantum Computing Cybersecurity Preparedness Act
-
Requires federal agencies to inventory quantum-vulnerable cryptography, plan migration, and report progress, with OMB directing implementation.
Ongoing statutory obligation
- FIPS 203, 204, and 205
-
Finalizes the ML-KEM, ML-DSA, and SLH-DSA standards that replace quantum-vulnerable key establishment and digital signatures.
Standards final and available now
- NIST IR 8547, Transition to Post-Quantum Cryptography Standards (draft)
-
Proposes the deprecation schedule for existing public-key algorithms including RSA, ECDSA, ECDH, and EdDSA. Still in draft; the 2030 date has since been hardened by Executive Order 14412.
RSA and ECC deprecated after 2030, disallowed after 2035 (proposed)
- Executive Order 14306
-
Directs CISA to publish and maintain a list of product categories where PQC-capable products are widely available (released January 2026), and requires agencies to support TLS 1.3 as part of migration.
Product list live; TLS 1.3 support by January 2030
- Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks
-
Requires every agency to designate a PQC migration lead, migrate key establishment to NIST-approved PQC by December 31, 2030 and digital signatures by December 31, 2031, and directs a FAR rule requiring covered contractors to meet NIST PQC standards by the end of 2030.
Key establishment by 2030; signatures by 2031
- OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography
-
The execution roadmap for EO 14412: agency migration plans within 120 days, a phased 2026 to 2035 migration prioritizing High Value Assets and High Impact Systems, and alignment with FIPS 203, 204, and 205.
Phased migration 2026 through 2035
Inside the system
Working on problems Sentinel addresses?
We collaborate with government organizations, research institutions, and technology partners. Tell us what you are trying to solve.