PUBLIC · securepeak.comAS216096 · L-717869-S
SecurePeak
Practice 01

Cryptographic Infrastructure

Root and issuing CA design, key ceremonies under dual control, custody in FIPS 140-3 Level 3 hardware, and a migration path to ML-KEM / ML-DSA (FIPS 203 / 204) before RSA-2048 and P-256 are deprecated in 2030 and disallowed in 2035.

Engagement parameters
PartnersThales (Luna HSM, listed partner) · SSL.com (public CA, listed partner)HardwareThales Luna · Entrust nShield · Utimaco · YubiHSM 2 — FIPS 140-3 L3 · PKCS#11 · KMIPEcosystemDigiCert · Sectigo · GlobalSign · Verisign registry PKI · ETSI/WebTrust auditorsAlgorithmsECDSA P-384 · Ed25519 · ML-KEM-768 · ML-DSA-65 · SLH-DSAStandardsFIPS 203/204/205 · RFC 5280 · 6960 · 8555 · 3161 · CA/B BRDeliverablesCP/CPS · CBOM · ceremony scripts · runbooks
Data sheet · A4 · SP-SVC-01Open PDF sheet
PKI · SP-SVC-01.01

CA hierarchy & HSM engineering

Offline root, online issuing CAs, CP/CPS authoring, ceremony scripts with M-of-N quorum, PKCS#11 integration on Thales Luna (we are a listed Thales technology partner), Entrust nShield and Utimaco, and the runbooks that keep a hierarchy trustworthy after the consultants leave. WebTrust / ETSI EN 319 411 audit preparation. Where public trust is required, subordination or cross-signing under SSL.com — a listed SecurePeak partner — or DigiCert, Sectigo and GlobalSign.

Post-quantum · SP-SVC-01.02

Post-quantum migration

Cryptographic bill of materials (CBOM) across code, config and HSM inventory. Hybrid X25519MLKEM768 for TLS 1.3, ML-DSA-65 / SLH-DSA for long-lived signatures, composite certificates for the transition. Crypto-agility built in so the next algorithm swap is a config change.

Transport · SP-SVC-01.03

TLS & protocol verification

TLS 1.3 profile hardening, ECH and certificate compression, ACME (RFC 8555) lifecycle automation. Custom protocols modelled in Tamarin or ProVerif before they ship — the way TLS 1.3 itself was verified.

Signing · SP-SVC-01.04

S/MIME, document & code signing

S/MIME 4.0 deployment, eIDAS qualified signatures, Authenticode and Sigstore code signing, RFC 3161 timestamping. Keys never leave the HSM; signing is brokered, logged and rate-limited.

Secrets · SP-SVC-01.05

Secrets management

Vault or OpenBao architecture, dynamic short-lived credentials, SPIFFE workload identity, rotation policy with the audit trail that proves it — across cloud, on-premises and CI.

Side channels · SP-SVC-01.06

Implementation review

Constant-time review of your crypto code, cache-timing and fault-injection testing of HSM and secure-element firmware. Timing leaks in KyberSlash-class implementations are found by measurement, not by reading the spec.

Operators · identities withheld
Named to clients under NDA at scoping
OP-03
Principal · vulnerability research
Name withheld · active CVD embargoes
Firmware
Browser
HSM
OP-07
Lead · detection engineering
Name withheld · client SOC placement
Streaming ML
Sigma
DFIR
OP-11
Senior · cryptographic engineering
Name withheld · government PKI programme
HSM ceremonies
PQC
Formal verification
OP-14
Network engineer · AS216096
Name withheld · NOC rotation
BGP
RPKI
Dark fibre
References

What this practice is currently working against.

Papers and public CVEs · updated Sep 2026
ReferenceFinding / paperSource
NIST IR 8547Transition to Post-Quantum Cryptography Standards — RSA-2048 / ECC-256 deprecated 2030, disallowed 2035NIST · 2024
CNSA 2.0ML-KEM-1024 / ML-DSA-87 required for new NSS acquisitions from January 2027NSA · 2022–25
FIPS 203 / 204 / 205ML-KEM, ML-DSA, SLH-DSA final standardsNIST · Aug 2024
KyberSlashTiming side channel in division in ML-KEM decapsulation across reference implementationsBernstein et al. · 2024
EU PQC roadmapNational strategies and cryptographic inventories by end 2026; high-risk use cases migrated by 2030NIS Cooperation Group · Jun 2025
Next: Offensive Security