This page is rendered with JavaScript. The text below is the full content for readers without JavaScript. For machine reading see /llms.txt and /llms-full.txt.
What you sign today can be forged tomorrow. But you can still re-certify it in time.
A cryptographically relevant quantum computer, one powerful enough to break the cryptography in use today, does not yet exist. It may never be built, or it may arrive within five years. i4p is among the first to re-certify your already signed documents, before it becomes a problem.
OUR TECHNOLOGY PARTNERS AND RESELLERS
Quantum reaches you from two directions
Your encryption and your digital signatures are exposed in different ways, and the defence is different too. It is worth looking at each of them separately.
Harvest Now, Decrypt Later
Your encrypted data can be collected today. An email may pass through fourteen servers before it reaches the next room, and a banking TLS connection travels across countless routers. Anyone who stores these packets, unbreakable as they are today, will be able to open them once a cryptographically relevant quantum computer arrives.
Move your encryption to post-quantum algorithms now. If a piece of your data stays sensitive for five or ten years, you have to act today, because what is captured now will be decrypted later.
Trust Now, Forge Later
A quantum computer can derive your private key from your public key and produce signatures in your name. At that moment every signature you have ever made loses its credibility, because a genuine signature created two years ago cannot be told apart from a forgery produced yesterday. Both were made with the same key.
Your existing signed documents receive a post-quantum seal now, while the original signature is still provably valid.
Imagine leaving a sealed envelope with a notary. Ten years later the glue dries out and the envelope opens by itself. If the notary moves it into a stronger, locked box in time, the contents stay safe. Re-certification is that stronger box for your documents.
Not a promise, but engineering
i4p is currently the first to offer a working solution for re-certifying already signed documents. Here is how we do it.
It all starts with discovery
Most organisations have no idea how many digitally signed documents they actually hold. There are PDFs sitting in folders, the contents of document management systems, databases and mailboxes, and there are the signed Windows DLLs your machine trusts every single day.
We do not hunt them down one by one
The engineering principle is simple. There is no need to locate and interpret every document individually. We re-certify everything that carries a signature, so nothing is missed and nobody has to decide what matters.
Write-protected archives are not an obstacle
On write-once, read-many storage such as tape archives, the new signatures are stored separately. The original medium stays untouched, yet its contents are protected.
These engineering decisions are what make the difference, and it is exactly in details like these that more than twenty years of cryptographic experience shows.
The two most widely used algorithms are the vulnerable ones
The overwhelming majority of asymmetric cryptography in use today rests on two algorithms, RSA and ECC. These are precisely the two that a cryptographically relevant quantum computer will be able to break.
Nobody knows when that machine will be finished; we are at the beginning of the curve. But where large amounts of money flow, progress can accelerate abruptly, as we saw with artificial intelligence. Governments and large corporations are racing each other to build it.
If there is a realistic chance that it works in five years, you should not be making decisions today that you will regret in five years.
The deadlines are already set
End of 2026
Every EU member state has to begin its post-quantum migration: a national strategy, a cryptographic inventory and the first pilot projects.
End of 2030
Critical infrastructure, meaning banking, energy, healthcare and telecommunications, has to move fully to quantum-safe encryption.
End of 2035
All remaining systems must be migrated and re-certified, as far as this is practically feasible.
2030 is less than five years away. If you work in financial services, healthcare or critical infrastructure, now is the time to start planning.
Source: the post-quantum migration roadmap of the European Commission and the NIS Cooperation Group (2025).
A three-step path to post-quantum migration
Cryptographic inventory
We map which cryptographic algorithms run in which of your systems, and with what key lengths. This is the cryptographic inventory: a stocktake of the cryptography you actually use.
Readiness assessment
We identify which systems are most exposed and produce the migration plan, with priorities and a schedule.
Implementation and crypto-agility
We roll out the post-quantum algorithms and build in crypto-agility, so that your systems are structured to allow algorithms to be replaced later on.
If you also want physical key protection
Post-quantum algorithms and re-certification work without hardware, so the choice is yours. If you do want your keys protected in a physical device, there is the Trident HSM, which supports both classical and post-quantum algorithms and handles them in a single device. The complete solution is 100% European in development and operation, with no dependency on the United States.
The NIST post-quantum standards, where they belong
NIST finalised the first post-quantum standards in 2024. You reach them through industry-standard interfaces, alongside your existing systems. Source: NIST Post-Quantum Cryptography project.
ML-KEM (FIPS 203)
Key encapsulation
ML-DSA (FIPS 204)
Digital signature
SLH-DSA (FIPS 205)
Hash-based signature
PKCS#11, OpenSSL
Industry-standard interfaces
EN 419221-5
European protection profile
PrimeKey EJBCA
PKI integration
More than twenty years of cryptographic experience
The i4p team was founded by the former owners and specialists of Netlock, one of the first European qualified trust service providers. That experience counts for exactly this kind of work, where everything comes down to the details.
trust service providers worldwide build on i4p systems. A side note, but a telling one: we are not their competitor, we provide the infrastructure underneath them.
Google Quantum AI unveiled its quantum chip called Willow at the end of 2024. And the European Commission published the roadmap for the post-quantum migration in 2025. So the question is not whether the change is coming, but whether you are ready for it.
Frequently asked questions
We add three real customer questions to this list every month.
What is a cryptographically relevant quantum computer?
A quantum computer built not for protein research or astronomical calculations, but to break the cryptographic algorithms in use today. It does not exist yet. It may never be built, or it may be here in five years.
What is Harvest Now, Decrypt Later?
An attack in which the attacker collects and stores your encrypted data today in order to decrypt it later, once a sufficiently powerful quantum computer exists. What is protected by RSA or ECC encryption today may become readable later, which is why data that stays sensitive for five to ten years has to be dealt with now.
What does document re-certification mean?
We place a post-quantum seal on your existing signed documents now, while the original signature is still provably valid. That way they keep their credibility even if the old signature algorithm becomes vulnerable later. i4p is currently the first to offer a working solution for this.
Do I have to locate every document one by one?
No. The engineering principle is that we do not locate and interpret documents individually; we re-certify everything that carries a signature. That way nothing is missed.
What if my signed material sits on write-protected archives?
On write-once, read-many storage such as tape archives, the new signatures are stored separately. The original medium stays untouched, yet its contents are protected.
When does the migration become mandatory in the EU?
Under the EU roadmap, every member state has to start the migration by the end of 2026, critical infrastructure has to be fully migrated by the end of 2030, and all remaining systems by 2035. Source: the European Commission's post-quantum migration roadmap (digital-strategy.ec.europa.eu).
What is a cryptographic inventory and why do I need one?
A cryptographic inventory is a stocktake of the cryptographic algorithms in use: what runs in which system, and with what key length. If you do not know what you are using, you cannot know what needs replacing. The latest version of PCI DSS also requires an inventory of cryptographic assets (pcisecuritystandards.org).
Does it work without hardware, that is, without an HSM?
Yes. Post-quantum algorithms and re-certification work without hardware. If you also want your keys protected in a physical device, there is the Trident HSM, but that is entirely your decision.
The first step is knowing where you stand
This is not an online purchase, it is a complex technical subject. If anything on this page caught your attention, we will go through where your organisation stands and what fits it, in a free consultation. If your whole team is interested, we can also run a webinar.
i4p informatics Kft. Pethényi út 7, 1122 Budapest, Hungary
INNOVATING FOR PROTECTION
SOLUTIONS
Signing Portal
Post-Quantum (PQC)
Trident datasheet
CERTIFICATIONS
QSCD certification
eIDAS Trusted List
i4p.com
© 2026 i4p informatics Kft. All rights reserved.