HNDL / TNFL Risk Assessment
Prioritize post-quantum migration using confidentiality lifetime, threat horizon and time needed to change complex systems.
What this capability solves
Quantum risk is not only a future-event question. Data stolen today may remain valuable later, while migration can take years. Prioritization must combine data life, exposure and change difficulty.
Technology is implemented as an operating capability: architecture, integration, governance, assurance, people, procedures and measurable outcomes are designed together.
Capability model
Modular building blocks allow the scope to start with a focused pilot and expand into an enterprise operating model.
Data Lifetime
Estimate confidentiality/validity period of protected information and signatures.
Threat Horizon
Use scenario ranges rather than a single speculative Q-Day date.
Migration Lead Time
Estimate vendor, architecture, testing, procurement and rollout complexity.
Exposure Path
Assess harvest-now-decrypt-later and trust-now-forge-later scenarios.
Criticality
Factor business, safety, regulatory and national/strategic importance.
Priority Model
Rank assets into migration waves with transparent assumptions and owners.
How the capability fits together
Final topology, control placement and deployment model are validated during discovery and detailed design.
Controls & governance
- Approved cryptographic profile registry
- Hybrid-first transition where compatibility requires it
- No untested algorithm replacement in production
- Key/certificate lifecycle and fallback controls
- Vendor and firmware dependency tracking
- Independent test evidence for critical systems
- Exception ownership and retirement dates
Priority use cases
- Long-lived personal data
- Government/regulated records
- Signing trust chains
- Research/IP archives
- Industrial remote assets
Key deliverables
- HNDL/TNFL methodology
- Data-life classification
- Risk-ranked asset list
- Migration wave priorities
- Executive risk narrative
Integration considerations
- CMDB/asset inventory
- PKI/HSM/KMS
- Network/security platforms
- Application/CI-CD dependencies
- Cloud and SaaS configuration
- IoT/OT device inventory
- GRC/remediation workflow
Phased delivery
Each phase ends with evidence, acceptance criteria and a decision gate before broader scale-out.
