← All 186 courses
SEC-106 Security

Post-Quantum Readiness & Cryptographic Inventory

Why post-quantum migration became urgent before any quantum computer exists, and what to do first. Learners work the harvest-now-decrypt-later argument, learn the NIST selected algorithms and their real size and performance deltas, then discover where cryptography actually lives across an estate and assemble a cryptographic bill of materials. The deliverable is a risk-ranked backlog prioritised by data lifetime rather than by vendor pressure.

B2Foundation
5modules
35skill atoms
2role journeys
Curriculum

What this course covers.

5 modules, 35 named skill atoms. Expand any module to see them.

1Why Now7 skill atoms
harvest-now-decrypt-laterdata lifetime vs migration durationthe Mosca inequalityCRQC timeline uncertaintyShor against RSA and ECC vs Grover against AESnational guidance and regulator deadlinesconfidentiality urgency vs signature urgency
2The Selected Algorithms7 skill atoms
ML-KEM under FIPS 203ML-DSA under FIPS 204SLH-DSA under FIPS 205lattice vs hash-based assumptionskey and signature size deltashybrid vs pure PQC modesstateful LMS and XMSS for firmware signing
3Finding The Crypto7 skill atoms
TLS endpoint discoverycertificate inventory from internal CAs and CT logsdependency and code scanning for crypto librariesHSM and KMS key cataloguesembedded and firmware signing keysthird-party and SaaS crypto you do not controlpacket capture as corroborating evidence
4Cryptographic Bill of Materials7 skill atoms
CBOM record fieldsalgorithm, key size, purpose and ownerCycloneDX CBOM representationlinking crypto assets to business servicesconfidence levels for discovered vs asserted entriesrefresh cadence and ownershipan explicit register of unknowns
5Prioritising The Estate7 skill atoms
data lifetime classificationlong-lived archives and stored secretsinternet-exposed before internalverification chains that outlive the hardwarevendor dependency blockersquick wins vs multi-year itemsproducing a defensible first-pass backlog
Where it fits

SEC-106 in the role journeys.

This course appears in 2 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

Security Engineer

Foundation stage
SEC-103SEC-106SEC-104

Cryptography / PQC Engineer

Foundation stage
SEC-103SEC-106SEC-104

Roles this course serves

The capability ladder

This course is authored to band B2.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-106 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free