Frequently Asked Questions
Everything you need to know about post-quantum cryptography and our services
General
Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to resist attacks from quantum computers. Unlike current RSA/ECC algorithms, PQC is based on mathematical problems that quantum computers cannot efficiently solve, such as lattice-based problems and hash-based signatures.
The timing of a cryptographically relevant quantum computer remains uncertain; expert forecasts vary widely. However, the harvest now, decrypt later threat is already real: data encrypted with current algorithms and intercepted today can be stored and decrypted later once such a computer becomes available. Organisations should begin identifying cryptographic dependencies and planning their migration.
This refers to the strategy where adversaries record encrypted communications today, store them, and plan to decrypt them once quantum computers are available. Any data with long-term sensitivity (contracts, medical records, government communications) is at risk now.
Technical
We implement ML-KEM (FIPS 203) for key encapsulation, ML-DSA (FIPS 204) for digital signatures, and SLH-DSA (FIPS 205) for hash-based signatures. All are NIST-standardised as of August 2024.
No. Fira implements hybrid approaches: PQC runs alongside your existing classical cryptography. If either is compromised, the other still protects you. No disruption to current operations.
ML-KEM key sizes are larger than ECDH but the performance overhead is minimal in most enterprise deployments. We benchmark against your specific environment during the pilot phase.
Yes. Fira delivers packaged modules with deployment runbooks and configuration guides. Your team operates them independently. Algorithm updates, security patches, and standards evolution remain with Fira under separate maintenance terms.
Commercial
A single service block (e.g., Transport Security) takes 10-14 weeks. A full quantum-safe upgrade across all three services takes 5-7 months.
Yes. Each service is a standalone deliverable. Most clients start with Transport Security (Block A) and expand later.
Yes. We provide certificates of completion, project descriptions, CVs, and reference documentation formatted for UK, Italian (MePA, ANAC), and Greek (ΕΣΗΔΗΣ) public sector RFP requirements.
Fira Software Ltd is registered in the UK (East Sussex). All work is delivered remotely. We have experience working with partners across the UK, Greece, and Italy.