About

Compliance

Standards-alignment guidance for FIPS, CNSA 2.0, BSI, NIS2, and procurement review without unverified claims.

Abstract evidence panels and standards mapping layers connected to a verification grid.

Page sections

Scan the major sections before moving into the full technical detail.

Regulatory alignment for PQC migration.

Talk to our security team

GDPR and data protection

Quanten Security’s website and service workflows are intended to minimise personal data, limit retention, and keep customer engagement data tied to a documented purpose. Customer-specific processing terms should be agreed in the relevant contract.

NIS2 and CRA readiness

For organisations subject to NIS2 or Cyber Resilience Act obligations, Quanten Security supports crypto-inventory work, vulnerability disclosure processes, secure update planning, and documentation needed for risk management. Regulatory scope and filing obligations should be confirmed for each customer and jurisdiction.

DORA support

Financial-sector engagements can be structured to support DORA-aligned ICT risk management, including exit planning, audit evidence, incident-notification workflows, and data-location review. Contract terms should define the exact obligations.

NIST PQC alignment

The platform roadmap tracks the final NIST post-quantum FIPS standards: FIPS 203 for ML-KEM, FIPS 204 for ML-DSA, and FIPS 205 for SLH-DSA. HQC is tracked as NIST’s selected backup KEM while its standard is developed, and FN-DSA/Falcon is tracked on the FIPS 206 signature path while that standard remains in development.

Customer evidence should distinguish standard alignment, known-answer-test evidence, validated cryptographic modules, and completed third-party certification. CNSA 2.0 and BSI TR-02102 mappings should be reviewed against the customer’s jurisdiction and deployment date.