A half-day executive briefing for Romanian banking leadership calibrated to real hardware timelines, anchored in the EU and national regulatory stack, and built to produce a defensible board-level decision.
The urgency for banks is not an abstract quantum threat date. It is a stack of EU and Romanian obligations already in force or dated, each of which touches cryptographic governance.
Most quantum messaging a bank board hears is either dismissive ("decades away") or breathless ("harvest-now, decrypt-tomorrow"). Neither helps you make a decision you can defend to a supervisor.
This briefing works from the published hardware trajectory and the peer-reviewed resource estimates, states plainly what is and is not known, and separates the regulatory obligations that are already dated from the cryptographic threat that is still on the horizon. The regulation is what creates the near-term work and the regulation is not speculative.
That calibration is deliberate. It is easier to act on a realistic picture than on a frightening one, and a realistic picture is what an audit committee can sign off against.
Roughly three hours with your leadership team. The output is a shared understanding of the obligation, the exposure, and a defensible first move captured in a short board-ready statement.
Exactly which obligations — DORA, NIS2, the DNSC roadmap, eIDAS 2.0 — apply to your institution, and on what dates.
What the current quantum hardware trajectory does and does not imply for RSA and ECC, from the published estimates.
Where the vulnerable cryptography actually lives in a banking estate — the surface a migration has to cover.
A migration sequence aligned to the DNSC, EU, and NIST timelines, prioritised by risk and system longevity.
The concrete first moves — inventory, ownership, governance — that a board can commit to immediately.
A short written position your audit committee can adopt as its documented decision on quantum-safe readiness.
The regulatory stack, the dated obligations, and what "scoped entity" means for your institution specifically.
Real hardware numbers, the peer-reviewed resource estimates, and an honest read of the timeline.
A structured walk through where vulnerable cryptography sits across a banking estate, and how exposure is assessed.
A phased plan aligned to DNSC, EU, and NIST timelines — sequenced by risk, not by convenience.
Agreeing the immediate moves and drafting the position your audit committee can adopt. Open Q&A to close.
This is an executive briefing, not a full cryptographic assessment. That boundary is deliberate.
A credible half-day gives your leadership the regulatory map, a calibrated threat picture, and a defensible first move. Where a deeper implementation assessment is the right next step, we say so plainly rather than overreaching.
Delivered on-site in Romania or remotely, in English, with Romanian-language materials available. Tell us your institution and timeframe, and we'll confirm a date.