Start with the operational decision
Post-quantum security solutions for real operational decisions.
These are not customer claims or interchangeable industry templates. Each scenario names its accountable owner, concrete failure mode, QNSI contribution, decision artifact, validation boundary, and external source context.
Evidence-backed evaluation paths
Explore the complete solutions library
A primary source establishes the external problem context; it does not endorse QNSI or prove that any deployment completed the scenario.
01 · AI & data platforms
4 scenariosML Platform · AI Security · Model Risk
Verify an AI model artifact before production loading
Does the model match the approved training run, evaluation, code, and release authority?
Open the evidence path →Data Governance · ML Engineering · Responsible AI
Trace training data from source agreement to model run
Which dataset version, license, transformation, and approval contributed to a specific model?
Open the evidence path →AI Governance · Compliance · ML Operations
Protect integrity of logs supporting a high-risk AI review
Can reviewers trust the model version, input context, human intervention, and output recorded for each consequential decision?
Open the evidence path →AI Platform · Identity Security · Application Owners
Govern credentials used by autonomous AI agents
Which agent instance may call which tool, with what credential, data boundary, and expiration?
Open the evidence path →02 · Automotive & mobility
4 scenariosVehicle Cybersecurity · OTA Platform · Homologation
Transition vehicle OTA signing across mixed model years
Which vehicles can verify a new signing scheme, and how will older fleets receive trusted updates?
Open the evidence path →Connected Vehicle Architecture · PKI · Roadside Infrastructure
Measure PKI agility for vehicle-to-everything communications
Can vehicles and roadside units adopt new certificate and signature profiles without losing safety-message interoperability?
Open the evidence path →Aftersales Security · Dealer Systems · Vehicle Engineering
Replace shared vehicle diagnostic credentials with accountable identities
Which technician, tool, and service action is authorized for a specific vehicle and time window?
Open the evidence path →Product Cybersecurity · Supplier Assurance · Platform Engineering
Trace cryptographic evidence through automotive tier suppliers
Which supplier component introduces each algorithm, key, certificate, or software signer into the vehicle?
Open the evidence path →03 · Aviation
4 scenariosAirworthiness · Aircraft Cybersecurity · Configuration Control
Verify the signing chain for aircraft-loadable software
Does each loadable part originate from an approved configuration and authorized release identity?
Open the evidence path →Airport CISO · Baggage Systems · Airfield Operations
Inventory certificates across airport operational technology
Which safety or continuity functions share issuers, expired trust, or unmanaged vendor certificates?
Open the evidence path →Continuing Airworthiness · MRO IT · Quality
Prove integrity of digital aircraft maintenance records
Can a reviewer establish who created, changed, approved, and transferred each maintenance record?
Open the evidence path →Identity Architecture · Airport Partnerships · Crew Systems
Modernize identity trust across an airline partner ecosystem
How can crew, ground handlers, alliance partners, and contractors authenticate without permanent overbroad federation?
Open the evidence path →04 · Banking & payments
4 scenariosCISO · Head of Payments · Cryptography Lead
Map cryptography across a bank payment rail before migration
Which payment services can move first without breaking clearing, fraud, or settlement dependencies?
Open the evidence path →PKI Lead · HSM Operations · Payments SRE
Rehearse an HSM-backed signing-key rollover without payment downtime
Can old and new signing trust coexist long enough to rotate safely across every payment participant?
Open the evidence path →API Security Architect · Open Banking Product Owner
Introduce hybrid post-quantum protection at an open-banking API boundary
Where can quantum-resistant handshakes be introduced while legacy aggregators still require classical interoperability?
Open the evidence path →Incident Commander · General Counsel · Disclosure Committee
Assemble cryptographic evidence for a bank cyber-incident materiality decision
What cryptographic assets, data paths, and business services were affected, and when was that known?
Open the evidence path →05 · Cloud & data centres
4 scenariosCloud Platform · Security Architecture · SaaS Assurance
Prove tenant separation in a multi-tenant cloud key service
Can an operator, software defect, or compromised tenant cross the intended cryptographic boundary?
Open the evidence path →Platform SRE · Service Mesh · PKI
Make service-mesh certificate rotation measurable before PQC change
Can every workload receive, activate, validate, and retire new trust without hidden static certificates?
Open the evidence path →Data Centre Operations · Network Engineering · Incident Management
Prevent a data-centre certificate expiry from becoming a regional outage
Which internal and external services depend on the expiring chain, and can replacement be rolled back safely?
Open the evidence path →Security Operations · Regulatory Affairs · Data Centre Management
Prepare incident evidence for a Singapore foundational digital infrastructure operator
Can the operator rapidly identify affected cryptographic services, supplied functions, customers, and containment actions?
Open the evidence path →06 · Defense & national security
4 scenariosAuthorizing Official · ISSM · Cryptographic Modernization
Scope a CNSA 2.0 transition for a national-security system
Which mission components, interfaces, and data lifetimes fall inside the transition boundary?
Open the evidence path →Mission Network Architect · Coalition Interoperability · Crypto Custodian
Test post-quantum interoperability for a coalition mission network
Can partners negotiate approved protection without exposing the mission to silent downgrade or incompatible credentials?
Open the evidence path →DevSecOps · Release Authority · Configuration Management
Modernize signing for defense software delivered into disconnected enclaves
How will an offline enclave verify the release, signer authority, dependency evidence, and revocation state?
Open the evidence path →Supply Chain Risk · Programme Protection · Contracting
Challenge a defense supplier's cryptographic assurance claims
Which supplier claims are independently evidenced, configuration-specific, inherited, or still unqualified?
Open the evidence path →07 · Digital assets & fintech
4 scenariosCustody CTO · Wallet Security Lead · Risk Officer
Separate digital-asset custody approval from signing execution
Which people, services, thresholds, and key stores may authorize each class of asset movement?
Open the evidence path →Wallet Platform Lead · Business Continuity Manager
Design a recoverable wallet-key lifecycle without creating a master-key shortcut
How can the service recover from device loss or operator unavailability without introducing an ungoverned universal recovery secret?
Open the evidence path →Platform Engineering · Third-Party Risk · Fraud Operations
Contain fintech partner API credentials by product and counterparty
Can one compromised integration credential be prevented from reaching every product, ledger, and partner?
Open the evidence path →Controller · Treasury Systems · Internal Audit
Preserve authenticity of stablecoin reserve and reconciliation reports
Can a reviewer prove which system produced each reserve snapshot and whether the file changed after approval?
Open the evidence path →08 · Education & research
4 scenariosUniversity CISO · Registrar · Privacy
Classify quantum exposure in lifetime student records
Which transcripts, identity, disability, conduct, and financial records remain sensitive for decades?
Open the evidence path →Research IT · Principal Investigator · Data Steward
Preserve provenance across a multi-university research consortium
Can collaborators prove which institution, instrument, pipeline, and researcher produced each dataset version?
Open the evidence path →Identity Management · Library IT · Research Computing
Rotate federation signing keys across campus and research services
Which relying services will reject a new federation signer, and how quickly can stale metadata be corrected?
Open the evidence path →Core Facility · Research Integrity · Instrument IT
Authenticate data from shared scientific instruments
Can a result be attributed to the correct instrument, configuration, operator, and acquisition session?
Open the evidence path →09 · Energy & electric grid
4 scenariosOT Security · Transmission Operations · CIP Compliance
Map cryptography between grid control centres and substations
Which operational links and devices can migrate, and which must be isolated until replacement?
Open the evidence path →Substation Engineering · PKI · Field Operations
Rotate substation device certificates inside narrow outage windows
Can relay, gateway, and engineering trust change without creating a protection or visibility gap?
Open the evidence path →Business Continuity · Control Systems · Key Custodians
Test cryptographic key recovery during a grid blackstart scenario
Can essential operators and systems recover credentials when normal identity, network, and key services are unavailable?
Open the evidence path →OT Access Management · Vendor Risk · Operations
Constrain supplier remote-access trust in electric operations
Which supplier identity can reach which asset, for what task, using which credential and approval?
Open the evidence path →10 · Government
4 scenariosAgency CIO · Identity Programme · PKI Authority
Pilot a dual-stack post-quantum PIV migration
How can new credentials and services be tested without locking out users or breaking relying applications?
Open the evidence path →Procurement · Agency Security · System Owner
Require a cryptographic bill of materials in government procurement
Does a proposed product expose enough algorithm, library, certificate, and key-custody detail to plan future transition?
Open the evidence path →Chief Data Officer · Privacy · Records Management
Protect citizen records with confidentiality horizons longer than system life
Which identity, tax, health, benefits, and justice records need protection beyond the next platform replacement?
Open the evidence path →API Platform · Mission Owner · Security Authorization
Transition cryptographic trust across an interagency API
Which agency owns issuer trust, version negotiation, revocation, and failure response when algorithms change?
Open the evidence path →11 · Healthcare providers
4 scenariosHealthcare CISO · Privacy Officer · Clinical Applications
Find ungoverned cryptography around a hospital's ePHI
Where is ePHI encrypted, signed, transmitted, or left dependent on unknown cryptographic components?
Open the evidence path →Clinical Engineering · PKI Team · Patient Safety
Transition medical-device PKI without interrupting clinical care
Which device cohorts can accept new certificates or algorithms, and which require compensating controls until replacement?
Open the evidence path →Cloud Security · Privacy Officer · Infrastructure
Evaluate customer-managed key custody for a healthcare cloud workload
Does customer-managed custody materially reduce risk without making recovery or clinical availability fragile?
Open the evidence path →Incident Response · Privacy · Clinical Operations
Determine cryptographic scope during a healthcare breach
Was compromised ePHI actually protected, were relevant keys exposed, and which records fall inside the incident boundary?
Open the evidence path →12 · Insurance & asset management
4 scenariosCISO · Records Officer · Chief Actuary
Prioritize quantum exposure in life-policy archives
Which policy, medical, beneficiary, and actuarial records remain sensitive beyond the life of today's public-key protection?
Open the evidence path →Claims CTO · Fraud Lead · Litigation Counsel
Prove the integrity of claims evidence from intake to settlement
Can the insurer distinguish an original claimant artifact from later transformation, annotation, or fraud-review output?
Open the evidence path →Third-Party Risk · Enterprise Architecture · Procurement
Measure cryptographic concentration across an insurer's SaaS estate
Which critical business processes depend on the same certificate authority, cloud KMS, identity provider, or unsupported algorithm?
Open the evidence path →Cyber Underwriting · Risk Engineering · Broker
Replace a PQC underwriting checkbox with measurable evidence
Has the applicant identified material cryptographic exposure and funded a credible transition, or only adopted a policy statement?
Open the evidence path →13 · IoT & smart cities
4 scenariosSmart City Platform · Device Operations · Procurement
Enroll unique identities for a citywide sensor fleet
Can each camera, meter, light, and environmental sensor be traced to an authorized manufacturing and enrollment event?
Open the evidence path →IoT Architecture · Network Security · Device Vendor
Prove secure communications from constrained devices through an IoT gateway
Where does end-to-end protection terminate, and which gateway can see or modify device data?
Open the evidence path →Device Fleet · Firmware Security · Customer Support
Rollover OTA signing trust across a fragmented IoT fleet
Which deployed devices can learn a new signer before the current key or algorithm becomes unsafe?
Open the evidence path →Product Management · Product Security · EU Compliance
Align IoT cryptographic support with the promised support period
Can the manufacturer maintain keys, certificates, libraries, and update trust for the whole declared support period?
Open the evidence path →14 · Legal & professional services
4 scenariosLitigation Technology · Records Counsel · CISO
Keep signed legal evidence verifiable after algorithms and firms change
What must be preserved so a future reviewer can validate signer authority and document integrity?
Open the evidence path →Law Firm CISO · General Counsel · Records
Prioritize harvest-now-decrypt-later exposure in client archives
Which privileged matters retain strategic, personal, or commercial sensitivity beyond current public-key protection?
Open the evidence path →M&A Technology · Client Security · Deal Counsel
Evaluate customer-controlled keys for a transaction deal room
Can the client revoke provider access without making the deal room unrecoverable during a transaction?
Open the evidence path →Digital Forensics · Investigations Counsel · Evidence Custodian
Sign forensic evidence at every custody handoff
Can every acquisition, copy, analysis, export, and transfer be linked to an authorized actor and unchanged content?
Open the evidence path →15 · Manufacturing
4 scenariosOT Architecture · Plant Engineering · Identity
Use machine identity to enforce factory-cell boundaries
Can a machine authenticate only to the controllers, brokers, and services required for its production role?
Open the evidence path →Automation Engineering · Quality · Plant Cybersecurity
Verify robot firmware and configuration before a line restart
Does the robot image match the approved safety-tested build and cell configuration?
Open the evidence path →Industrial Data Platform · Process Engineering · Quality
Protect the integrity of data feeding a manufacturing digital twin
Can planners identify which sensors, transformations, and models produced a decision-driving analytical output?
Open the evidence path →Supplier Quality · Product Security · Procurement
Find certificate concentration across an OEM supplier network
Which products and factories depend on a supplier root, signing service, or unsupported crypto library?
Open the evidence path →16 · Maritime & ports
4 scenariosFleet CISO · Marine Operations · Communications
Map cryptography across vessel-to-shore communications
Which satellite, radio, VPN, identity, and application paths protect operational and commercial data?
Open the evidence path →Marine Assurance · Navigation Systems · Fleet IT
Verify navigation-data updates before bridge installation
Can bridge staff prove the update source, content, approval, and target system while offline?
Open the evidence path →Port OT · Terminal Operations · Automation
Assign rotatable identities to port cranes and gate systems
Can each crane, gate, scanner, and control service be authenticated without shared terminal credentials?
Open the evidence path →Trade Digitization · Legal · Port Community Systems
Preserve signature provenance for electronic cargo documents
Can parties prove who issued, endorsed, transformed, and presented each cargo record?
Open the evidence path →17 · Media & digital content
4 scenariosNewsroom Technology · Content Authenticity · Editorial
Sign media provenance from capture through publication
Can audiences and partners verify which device, editor, and publishing system produced an asset?
Open the evidence path →Archive · Broadcast Engineering · Rights Management
Preserve authenticity of a broadcast archive across format migration
Can the archive prove an asset's origin and editorial state after storage and codec migrations?
Open the evidence path →Newsroom Security · Investigations Editor · Legal
Protect confidential newsroom sources against future decryption
Which communications and source records remain dangerous if captured now and decrypted years later?
Open the evidence path →Streaming Platform · Content Protection · Rights Operations
Rotate streaming distribution keys without blacking out licensed audiences
Can origin, CDN, packager, player, and partner trust change within rights and availability constraints?
Open the evidence path →18 · Medical devices
4 scenariosDevice Security Architect · Firmware Lead · Quality
Qualify post-quantum signing for medical-device secure boot
Can the boot chain verify a new signature scheme within memory, timing, safety, and update constraints?
Open the evidence path →Product Security · Quality Systems · Regulatory Affairs
Bind a medical-device SBOM to the exact released firmware
Can a hospital or assessor verify that the SBOM, vulnerability status, and firmware image describe the same release?
Open the evidence path →Fleet Operations · Device Engineering · Customer Support
Rotate field-update trust on devices that cannot all reconnect
How can offline or intermittently connected devices learn a new update key without accepting an attacker-controlled root?
Open the evidence path →Regulatory Affairs · Product Security · Systems Engineering
Build the cryptography section of a medical-device premarket file
Is every cryptographic claim connected to a design requirement, implementation, verification result, and residual risk?
Open the evidence path →19 · Oil, gas & pipelines
4 scenariosPipeline Cybersecurity · Control Room · Field Engineering
Inventory cryptographic trust in pipeline remote access
Which human and machine credentials can cross from enterprise access paths into operational pipeline systems?
Open the evidence path →OT Engineering · Product Security · Maintenance
Verify firmware before it reaches a pipeline controller
Can field staff prove that a controller image is authentic, approved, and compatible before installation?
Open the evidence path →Field IoT · Production Technology · Asset Integrity
Control identity over the lifetime of remote oilfield sensors
How will each sensor authenticate, rotate trust, and be retired when physical access is costly?
Open the evidence path →Incident Commander · Pipeline Operations · Regulatory Affairs
Produce a pipeline cyber-incident evidence pack during operations
Which operational assets and cryptographic controls were affected, and what containment is safe while product continues to move?
Open the evidence path →20 · Pharma & life sciences
4 scenariosClinical Systems · Quality Assurance · Biostatistics
Keep clinical-trial signatures verifiable through the study lifecycle
Will consent, source-data, analysis, and submission signatures remain attributable and verifiable years after systems change?
Open the evidence path →Laboratory IT · Quality Control · OT Security
Give laboratory instruments distinct, rotatable machine identities
Can each instrument authenticate without shared credentials that outlive ownership or calibration status?
Open the evidence path →Research CISO · Intellectual Property Counsel · Data Platform
Prioritize harvest-now-decrypt-later risk in drug-discovery data
Which target, compound, genomic, and partnership datasets retain economic value past current encryption assumptions?
Open the evidence path →Quality Systems · Data Integrity · Validation Lead
Prove provenance of transformed regulated laboratory records
Can an inspector follow a result from instrument output through parsing, normalization, review, and final report?
Open the evidence path →21 · Rail & public transit
4 scenariosRail Cybersecurity · Signalling Engineering · Safety Assurance
Stage a PKI transition for rail signalling support systems
Which support, management, and communications components can change trust without affecting safe train movement?
Open the evidence path →Fare Systems · Payments Security · Station Operations
Rotate fare-system keys across gates, validators, and mobile wallets
Can new keys become active across every channel without rejecting riders or extending old trust indefinitely?
Open the evidence path →Asset Management · Maintenance Control · Safety
Sign rail maintenance work orders at safety-critical handoffs
Can the operator prove which technician completed, inspected, and released work on a specific asset?
Open the evidence path →Fleet Engineering · Vendor Management · Security Operations
Time-bound supplier remote diagnostics for rolling stock
Can a supplier diagnose one fleet subsystem without retaining access to other trains or depots?
Open the evidence path →22 · Retail & ecommerce
4 scenariosRetail CISO · Payments · PCI Programme
Find cryptography that actually touches a retailer's card-data environment
Which terminals, gateways, token services, applications, and vendors are inside or connected to the cryptographic scope?
Open the evidence path →Store Technology · Payment Security · Vendor Management
Verify point-of-sale firmware before store deployment
Does each terminal image come from the authorized vendor release and match the approved device model?
Open the evidence path →Privacy · Loyalty Platform · Data Governance
Assess quantum exposure in loyalty and customer-profile data
Which behavior, identity, location, and preference records remain exploitable long after collection?
Open the evidence path →Marketplace Platform · Seller Risk · Fraud
Contain seller-app credentials in an ecommerce marketplace
Can one compromised seller application be prevented from reading other merchants, orders, payouts, or customer data?
Open the evidence path →23 · Software & SaaS
4 scenariosProduct Security · Engineering · EU Compliance
Create the cryptography evidence index for a CRA product technical file
Can every material cryptographic design claim be traced to implementation, test evidence, lifecycle support, and residual risk?
Open the evidence path →PSIRT · Legal · Product Operations
Connect a product cryptography incident to the CRA reporting clock
Does an exploited vulnerability or severe incident meet reporting criteria, and what is known at each deadline?
Open the evidence path →Release Engineering · Product Security · Customer Trust
Give SaaS customers verifiable release-signing provenance
Can a customer verify which build produced an artifact and which authorized identity approved it?
Open the evidence path →Application Security · Platform Engineering · Architecture
Find hidden cryptography in a SaaS dependency graph
Which libraries, runtimes, services, and managed dependencies will block a cryptographic transition?
Open the evidence path →24 · Telecommunications
4 scenariosMobile Core Security · Network Architecture · PKI
Inventory PKI dependencies across 5G network functions
Which network functions, vendors, and interfaces depend on shared trust anchors or non-agile certificate profiles?
Open the evidence path →eSIM Platform · Device Certification · Roaming Security
Plan long-lived signature agility for eSIM provisioning
How will profile-signing and trust anchors evolve across devices that remain deployed for a decade?
Open the evidence path →Privacy · Data Governance · Telecom CISO
Reduce long-term quantum exposure in telecom subscriber records
Which call-detail, location, account, and network records remain sensitive long enough to justify early re-protection?
Open the evidence path →Network Cloud · Vendor Assurance · Change Authority
Verify network-function software before carrier rollout
Does the candidate image originate from the approved vendor build and match the tested configuration?
Open the evidence path →25 · Water & wastewater
4 scenariosUtility Manager · SCADA Engineering · Cybersecurity
Establish a cryptographic baseline for a water SCADA network
Where does cryptography protect control, telemetry, engineering, and business interfaces—and where is it absent?
Open the evidence path →SCADA Operations · Field Maintenance · PKI
Rotate certificates on remote water PLC gateways
Can trust be replaced across unmanned sites without losing telemetry or control?
Open the evidence path →Emergency Management · SCADA · Infrastructure
Recover treatment-system keys during a flood or facility loss
Can an alternate control location authenticate and decrypt essential systems when the primary site is inaccessible?
Open the evidence path →Maintenance Manager · Procurement · Cybersecurity
Expire vendor cryptographic access after water-system maintenance
Does each vendor credential terminate when the approved service task ends?
Open the evidence path →Evidence boundary
A use case is an evaluation path—not proof of deployment.
Every page separates QNSI's potential contribution from the customer testing, legal applicability, accreditation, integration, production evidence, and independent assurance still required.