# Technical due diligence

We carry out independent technical due diligence for venture capital, private equity and acquirers: an engineer-led assessment of a company's code, architecture, security and open-source risk, and of the use cases its technology can support.

[Request due diligence](https://gateway-global.co.uk/contact/due-diligence/) Post-quantum readiness

Last updated 26 September 2026

## Who does the work

Our engineers and security specialists.

## Confidentiality

A non-disclosure agreement is available before you share any details about a target.

## Is the code ready for post-quantum cryptography?

You find out with a cryptographic inventory: a record of where a codebase and its dependencies use cryptography that will have to change. We carry one out, inside due diligence or as a review on its own, and plan the move in line with the milestones set by the National Cyber Security Centre (NCSC).

[Ask about a post-quantum review](https://gateway-global.co.uk/contact/engineering/)

### What timeline does the NCSC set?

1. By 2028
   Discovery and a plan: know where cryptography is used, and decide which systems move first.
2. By 2031
   The highest-priority systems moved.
3. By 2035
   The move complete across every system.

Source: [NCSC: PQC migration roadmap](https://www.ncsc.gov.uk/news/pqc-migration-roadmap-unveiled)

For the financial sector, the G7 Cyber Expert Group published a roadmap in January 2026 for moving the sector together, pointing to around 2030 to 2032 for the most critical systems.

Sources: [GOV.UK: G7 roadmap for post-quantum cryptography in the financial sector](https://www.gov.uk/government/publications/advancing-a-coordinated-roadmap-for-the-transition-to-post-quantum-cryptography-in-the-financial-sector), [US Treasury: G7 Cyber Expert Group roadmap announcement](https://home.treasury.gov/news/press-releases/sb0355)

### Why start now?

Because of "harvest now, decrypt later". Data protected today by public-key cryptography can be copied now and read later, once a quantum computer able to break that cryptography exists. No one knows when that will be, and it does not need to be soon for the risk to matter: what counts is how long your data must stay confidential, and how long the move will take you. Replacing cryptography touches code, libraries, certificates, devices and suppliers, which is why the first milestone is finding where it is used.

### What we do

- **A cryptographic inventory** of the codebase and the open-source libraries it depends on: where it uses RSA and elliptic-curve keys, for example in TLS connections, signed tokens and certificates, and which algorithms and key lengths it relies on.
- **How hard each change will be:** which parts can switch algorithm through a library update or a setting, which have the algorithm fixed in code, and which wait on a supplier.
- **Inside technical due diligence,** for investors and acquirers: what the target's product will have to change before 2035, and how readily its code can switch algorithm, set out with the rest of the findings.
- **As a review on its own,** for banks, payments firms, fintechs and other firms that hold data which must stay confidential for years.
- **A migration plan** in line with the NCSC's milestones: what to find by 2028, what to move by 2031 and what is left for 2035, in order of how long each system's data must stay confidential.

Who decides: A senior engineer signs every finding in the inventory. In due diligence, you decide what the findings mean for the deal. In a review on its own, your security lead decides the migration plan: what moves first, when, and what to ask of suppliers.

The inventory and the plan support your own security work. We do not certify a system as quantum-safe, and where a rule applies to you, we work alongside your legal advisers rather than giving legal advice.

## How Gateway Assay fits

We run Gateway Assay, our own product, first. Then our engineers add the expert judgement no tool replaces.

[Read about Gateway Assay](https://gateway-global.co.uk/products/gateway-assay/)

## Questions people ask

**Can you sign a non-disclosure agreement first?**

Yes. A non-disclosure agreement is available before you share any details about a target.

**What is a cryptographic inventory?**

A record of where a system uses cryptography: which algorithms, keys, certificates and libraries, and in which parts of the code. It is the first step in moving to post-quantum cryptography, and part of the discovery the NCSC asks organisations to complete by 2028, which also covers infrastructure, devices and suppliers.

## Know what you are buying before you sign.

[Request due diligence](https://gateway-global.co.uk/contact/due-diligence/)

---

Source: https://gateway-global.co.uk/services/technical-due-diligence/
Updated: 2026-09-26
