Services

Cryptography

Strong cryptography is not about choosing the right algorithm. It is about managing it properly for the whole life of your data.

Expert consultancy across the full cryptographic lifecycle. From strategy, design and algorithm selection through to key management, approvals, assurance and post-quantum migration, we help you protect information at rest, in transit and in use, in a way that stands up to scrutiny.

Cryptography

What we deliver.

Cryptography that holds up under scrutiny

Cryptography is the control that everything else depends on. It protects classified material, personal data, financial transactions, safety critical commands and the integrity of the systems that carry them. When it works, it is invisible. When it fails, whether through a weak algorithm, a mishandled key, an expired certificate or an unsupported library buried in a supplier product, the consequences reach every part of the organisation at once.

Most organisations do not have a cryptography problem they can see. They have cryptography spread across cloud platforms, legacy estates, operational technology and third party products, with no single owner, no complete inventory, and no clear view of which keys protect what. We help you change that. We establish what cryptography you are actually running, define the standard you need to meet, and put the strategy, architecture, key management and assurance in place to reach it.

Soteria aligns cryptographic work to the frameworks and standards that apply to your sector. That includes NCSC guidance and the national timelines for migration to post-quantum cryptography, JSP 440, JSP 453 and Def Stan 05-138 for defence, the NCSC Cyber Assessment Framework and IEC 62443 for critical national infrastructure, and ISO 27001, FIPS 140-3, GDPR and PCI DSS for the wider private sector.

Cryptographic Strategy & Policy

We help you set out how cryptography is governed, who owns it, and what good looks like across your estate. That means clear standards for approved algorithms, key lengths, protocols and certificate use, backed by policy your teams and suppliers can actually follow.

Cryptographic Discovery & Inventory

You cannot protect or migrate what you cannot see. We build a cryptographic inventory across applications, infrastructure, cloud services, operational technology and supplier products, identifying where cryptography is used, what it protects, and where it is weak, unsupported or unknown.

Key Management & PKI

Keys are where cryptography usually fails. We design and review key management arrangements end to end, covering generation, distribution, storage, rotation, escrow, revocation and destruction, along with public key infrastructure, hardware security modules and cloud key management services.

Cryptographic Architecture & Design

We embed cryptography into system architecture from the outset, selecting proportionate mechanisms for data at rest, data in transit and, where required, data in use. Our consultants help you make informed choices about protocols, libraries, hardware and configuration.

Post-Quantum Readiness

The NCSC expects organisations to have identified the cryptographic services needing upgrade and built a migration plan by 2028, to have delivered high priority upgrades between 2028 and 2031, and to have completed migration by 2035. We help you scope that programme, build crypto agility into your estate, and plan the move to standardised post-quantum algorithms.

Approvals, Custodianship & Key Material

For defence and government work we support the handling of cryptographic key material and the use of approved cryptographic products, including custodian arrangements, accounting and audit obligations, and the assurance evidence needed to satisfy accreditors and security authorities.

Cryptographic Assurance & Independent Review

We provide an independent review of cryptographic designs, implementations and key management practices, assessing them against your requirements and the relevant standards, and giving you objective advice on the risks that remain.

Vendor & Supply Chain Cryptography

From procurement onwards, we help you set cryptographic requirements in contracts, evaluate what suppliers are genuinely delivering, and confirm that certification claims such as FIPS 140-3 or Common Criteria apply to the configuration you are buying.

CRYPTOGRAPHY

Client outcomes.

Cryptography You Can Evidence

A complete view of the cryptography across your estate, with the documentation and assurance evidence to demonstrate it to auditors, accreditors, regulators and clients.

Regulatory & Policy Compliance

Meet NCSC guidance, JSPs, ISO 27001, IEC 62443, GDPR and PCI DSS cryptographic obligations with confidence, and avoid the cost of retrofitting controls late.

Quantum Readiness

A credible, funded migration plan that keeps you aligned to national timelines and protects data whose confidentiality must outlive today’s cryptography.

Fewer Cryptographic Failures

Well managed keys and certificates mean fewer expired certificate outages, fewer emergency rotations, and fewer incidents caused by weak or obsolete cryptography.

Informed Decision-Making

Our contextualised approach gives leadership a clear view of cryptographic risk in business terms, so decisions on investment and risk acceptance are made on evidence.

Cost Efficiency

Designing cryptography properly, and migrating it in a planned way, is significantly cheaper than emergency remediation or a rushed programme against a hard deadline.

Graphic showing points on a radial graph.
Secure by Design

How we work.

A typical example of how we work with clients. Please note that our engagement model is flexible and tailored to your needs. We work as an extension of your team, integrating into your existing processes and governance structures.

Weeks 1–2

1. Discovery & Cryptographic Inventory

We work with your stakeholders to understand your business objectives, data, regulatory obligations and technology landscape, then build a picture of the cryptography in use across the estate, including what it protects and who owns it.

Weeks 2-4

2. Strategy, Requirements & Target State

We define your cryptographic standards, requirements and target state, agree the risk appetite for cryptographic risk, and identify the right approach for your context, whether that is design guidance, key management redesign, procurement support or assurance oversight.

Weeks 4–12

3. Risk Assessment & Implementation Support

Contextualised risk sits at the centre of our work. We assess cryptographic risk against the threats relevant to your organisation and use that assessment to select proportionate controls, so that risk either sits within appetite or is presented to the business risk owner for a decision. We then support delivery, from key management and PKI design through to migration planning and supplier engagement.

Ongoing

4. Assurance & Validation

We conduct independent reviews of cryptographic designs, implementations and key management practices, assess them against your requirements, and provide objective advice on risk decisions. Where appropriate we coordinate specialist cryptographic testing.

As Required

5. Continuous Support

Many clients retain us for ongoing advisory support, providing access to specialist expertise as standards, algorithms and the threat landscape evolve. Post-quantum migration in particular is a multi year programme rather than a single project.

Why us

Strong algorithms are the easy part

Trusted Expertise

Our consultants hold industry-recognised certifications and bring extensive experience of cryptography in highly regulated environments, from national security systems to regulated commercial estates.

Pragmatic & Business-Focused

We take a pragmatic, risk-based approach. Our recommendations are proportionate to the value of the data and the threat you actually face, not a theoretical maximum, and they are built to be operated by your teams.

Security-Cleared Consultants

Our team holds active UK security clearance, qualifying us to work on sensitive government and defence projects. This clearance ensures we can securely manage classified information and cryptographic material.

Client Partnership

We prioritise building strong, enduring client relationships by deeply understanding your business, collaborating closely with your teams, and serving as a trusted partner throughout your security journey.

Clear Communication

Cryptography is easily lost in technical detail. We explain cryptographic risk in business language, so boards, programme managers and engineers all understand the exposure and the path forward.

Flexible Engagement

Our engagement model is flexible, from a focused cryptographic review through to a multi year migration programme with retained advisory support. We adapt to your needs and work within your existing structures.

Three people working at computers in a modern office with large windows and a red chair.
Three British Airways airplane tails with red, white, and blue designs parked in a row under a clear sky.
Gray military fighter jet flying with visible tail markings and the code 11-32 on the side.

FAQs

Explore some of the questions regularly asked about this service. Have a question not covered here? Get in touch.

What are cryptography services?

Cryptography services cover the strategy, design, management and assurance of the encryption and key management that protect your data and systems. That includes deciding which algorithms and protocols to use, managing the keys and certificates behind them, meeting the standards your sector requires, and planning for the move to post-quantum cryptography. It is advisory and engineering work rather than the supply of a product.

We do not know what cryptography we are using. Can you help?

Yes, and that is a very common starting point. Cryptographic discovery is usually the first piece of work we do. We build an inventory across your applications, infrastructure, cloud services and supplier products so you can see what cryptography is in use, what it protects, and where the weaknesses are.

What is post-quantum cryptography, and do we need to act now?

Post-quantum cryptography refers to algorithms designed to resist attack by a sufficiently capable quantum computer. The NCSC has set out a national timeline: identify affected services and build a migration plan by 2028, deliver high priority upgrades by 2031, and complete migration by 2035. For most organisations the discovery and planning work needs to start now, and it matters more urgently where data must stay confidential for many years, because encrypted traffic captured today could be decrypted later.

Do you supply cryptographic products or hardware?

No. We are independent consultants, which means our advice on products, hardware security modules and cloud key management services is not tied to any vendor. We help you define requirements, evaluate options, and validate that what you buy is configured to deliver the protection you need.

How is this different from penetration testing?

Penetration testing looks for exploitable weaknesses in systems as they are built. Cryptographic consultancy addresses the design and management of cryptography itself, including the key management and governance that testing rarely reaches. The two are complementary, and we can coordinate specialist testing where it is needed.

Can you support work involving government or defence cryptography?

Yes. Our security-cleared consultants support organisations working to defence and government cryptographic requirements, including the handling of key material, the use of approved cryptographic products, and the assurance evidence needed by accreditors and security authorities.

What standards and regulations does this address?

We help organisations meet cryptographic obligations under NCSC guidance and the national post-quantum migration timelines, JSP 440, JSP 453, JSP 490 (Defence Manual of Cryptography), JSP 491 (Cryptographic Handling Instructions) and Def Stan 05-138, the NCSC Cyber Assessment Framework, IEC 62443, ISO 27001, FIPS 140-3, the UK GDPR and PCI DSS. We translate that complexity into practical action.

How long does an engagement typically last?

It depends on scope. A focused cryptographic review or discovery exercise typically runs over 6 to 12 weeks. Post-quantum migration and key management transformation are longer programmes, and many clients retain us for ongoing advisory support as their estate and the standards evolve.