Choose which optional cookies and similar storage we may use. Strictly necessary storage is always on, because the site cannot work without it.

Technical due diligence

We carry out independent technical due diligence for venture capital, private equity and acquirers: an engineer-led assessment of a company's code, architecture, security and open-source risk, and of the use cases its technology can support.

Last updated

Draft (D4): What we assess: the confirmed list.

What we assess

[TO CONFIRM: the confirmed list from D4]

Who does the work

Our engineers and security specialists.

Draft (F17): Who leads the due diligence work.

Led by [TO CONFIRM].

Draft (F17): The engagement process, deliverables and timescales: confirm each.

The process

  1. Scope and non-disclosure agreement

  2. Secure, read-only access

  3. Automated analysis

  4. Expert review

  5. Report

  6. Debrief

Deliverables

[TO CONFIRM]

Timescales

[TO CONFIRM]

Confidentiality

A non-disclosure agreement is available before you share any details about a target.

Draft (F17): Independence: how we handle conflicts.

Independence

[TO CONFIRM]

Draft (D4): Vendor due diligence for founders (a proposed offer to confirm).

Vendor due diligence for founders

Founders preparing for investment can find and fix issues before investors do.

Is the code ready for post-quantum cryptography?

You find out with a cryptographic inventory: a record of where a codebase and its dependencies use cryptography that will have to change. We carry one out, inside due diligence or as a review on its own, and plan the move in line with the milestones set by the National Cyber Security Centre (NCSC).

Ask about a post-quantum review

What timeline does the NCSC set?

  1. By 2028

    Discovery and a plan: know where cryptography is used, and decide which systems move first.

  2. By 2031

    The highest-priority systems moved.

  3. By 2035

    The move complete across every system.

Source: NCSC: PQC migration roadmap

For the financial sector, the G7 Cyber Expert Group published a roadmap in January 2026 for moving the sector together, pointing to around 2030 to 2032 for the most critical systems.

Sources: GOV.UK: G7 roadmap for post-quantum cryptography in the financial sector, US Treasury: G7 Cyber Expert Group roadmap announcement

Why start now?

Because of "harvest now, decrypt later". Data protected today by public-key cryptography can be copied now and read later, once a quantum computer able to break that cryptography exists. No one knows when that will be, and it does not need to be soon for the risk to matter: what counts is how long your data must stay confidential, and how long the move will take you. Replacing cryptography touches code, libraries, certificates, devices and suppliers, which is why the first milestone is finding where it is used.

What we do

  • A cryptographic inventory of the codebase and the open-source libraries it depends on: where it uses RSA and elliptic-curve keys, for example in TLS connections, signed tokens and certificates, and which algorithms and key lengths it relies on.
  • How hard each change will be: which parts can switch algorithm through a library update or a setting, which have the algorithm fixed in code, and which wait on a supplier.
  • Inside technical due diligence, for investors and acquirers: what the target's product will have to change before 2035, and how readily its code can switch algorithm, set out with the rest of the findings.
  • As a review on its own, for banks, payments firms, fintechs and other firms that hold data which must stay confidential for years.
  • A migration plan in line with the NCSC's milestones: what to find by 2028, what to move by 2031 and what is left for 2035, in order of how long each system's data must stay confidential.

Who decides: A senior engineer signs every finding in the inventory. In due diligence, you decide what the findings mean for the deal. In a review on its own, your security lead decides the migration plan: what moves first, when, and what to ask of suppliers.

The inventory and the plan support your own security work. We do not certify a system as quantum-safe, and where a rule applies to you, we work alongside your legal advisers rather than giving legal advice.

How Gateway Assay fits

We run Gateway Assay, our own product, first. Then our engineers add the expert judgement no tool replaces.

Read about Gateway Assay

Questions people ask

Can you sign a non-disclosure agreement first?

Yes. A non-disclosure agreement is available before you share any details about a target.

Draft (F17): Timescales.
How long does an engagement take?

[TO CONFIRM: Timescales.]

Draft (F17): How we handle conflicts (independence).
How do you handle conflicts of interest?

[TO CONFIRM: How we handle conflicts (independence).]

What is a cryptographic inventory?

A record of where a system uses cryptography: which algorithms, keys, certificates and libraries, and in which parts of the code. It is the first step in moving to post-quantum cryptography, and part of the discovery the NCSC asks organisations to complete by 2028, which also covers infrastructure, devices and suppliers.

Know what you are buying before you sign.