About QROS

The team behind quantum readiness

QROS is built by Equantum Ciberseguridad y Blockchain S.L., a Spanish cybersecurity company in Vigo (Galicia) focused on one mission: give every organisation a clear, evidence-based path to cryptographic resilience and quantum readiness — before post-quantum cryptography becomes a compliance deadline, not a talking point.

Equantum Ciberseguridad y Blockchain S.L. VAT B42854737 Vigo, Galicia · Spain Founded 2024

Who we are

Equantum is a cybersecurity and blockchain engineering company. We build QROS — a platform that combines internet-wide discovery, cryptographic risk assessment, automated hardening and on-prem AI agents into a single quantum-readiness workflow. Our team works across post-quantum cryptography (NIST PQC), cryptographic risk (FAIR, NIST SP 800-30/37), baseline hardening (CIS, STIG, PCI-DSS) and regulatory compliance (DORA, NIS2). We publish what we build and cite the standards we work against, so our methods are auditable rather than proprietary folklore.

Leadership

Pablo López — Founder & CEO

Founded Equantum in 2021 to make cryptographic resilience a tractable engineering discipline. Cryptographer by training; leads QROS product, research and the post-quantum readiness framework. LinkedIn →

Equantum on LinkedIn

Company updates, the QROS Cryptographic Readiness Framework™ and field notes from the team. Follow Equantum QROS →

Our mission

RSA and ECC — the cryptography that secures the internet today — are broken by a sufficiently large quantum computer (Shor's algorithm). Migration to post-quantum cryptography (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) is not optional; it is a multi-year programme that regulators are already scheduling (DORA Article 9, NIS2). Our mission is to make that programme tractable: discover what you have, score what is at risk, and remediate it with signed, reversible automation — with evidence your auditor can read.

What we work against

We do not invent our own methodology. Every QROS assessment and remediation is grounded in a published, peer-reviewed standard, so the result is defensible in an audit:

Post-quantum cryptography

NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA); NIST SP 800-208 (stateful hash signatures); the Open Quantum Safe oqs-provider for OpenSSL.

Cryptographic risk

FAIR for quantitative loss exposure; NIST SP 800-30 (risk assessment) and SP 800-37 (RMF) for the assessment lifecycle.

Hardening baselines

CIS Benchmarks (L1/L2), DISA STIG, and PCI-DSS for both Linux (RHEL, Debian) and Windows Server fleets.

Regulation

DORA (digital operational resilience, Art. 9 ICT security) and NIS2 (EU cybersecurity of essential entities) for the compliance evidence layer.

How we build

QROS runs on open, auditable technology rather than black boxes — HAProxy, Suricata and Snort at the perimeter; OpenSearch and Grafana in the SOC; OpenSSL with oqs-provider for post-quantum; Ansible for idempotent, check-vs-repair automation; and an Ollama-compatible AI harness so you keep control of your models and your data. See the full technology stack. The on-prem agent signs every action it takes, so a remediation is always attributable and reversible.

Our partners

Equantum is backed by institutional, venture-capital and deep-technology partners who reinforce the quantum-readiness mission: Wayra (Telefónica), Amtega (Xunta de Galicia), Horizen Labs and EternaX.

Research and content

The articles, guides and host dossiers on qros.dev are written and reviewed by the Equantum Research Team — practising engineers, not a content farm. Each page carries a byline and a last-reviewed date so you can see when it was last checked against the standard it cites. The 230 000+ host dossiers in QROS Explore are original first-party scan data, not repackaged third-party feeds.

Questions about our methods or a partnership? Write to support@qros.dev, or read our legal notice.

FAQ

Who is behind QROS?

QROS is built by Equantum Ciberseguridad y Blockchain S.L., a Spanish cybersecurity and blockchain engineering company based in Vigo, Galicia (VAT B42854737). The Equantum Research Team — practising engineers — writes and reviews all content on qros.dev.

What standards does QROS work against?

QROS assessments and remediations are grounded in published standards: NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for post-quantum cryptography; FAIR and NIST SP 800-30/37 for risk; CIS, STIG and PCI-DSS for hardening; and DORA Article 9 and NIS2 for compliance. We never invent our own methodology.

Is the content on qros.dev written by people or AI?

Every article, guide and host dossier is written and reviewed by the Equantum Research Team — engineers who build and operate QROS. The 230,000+ host dossiers in QROS Explore are original first-party scan data, not repackaged third-party feeds. We do not publish AI-summarised filler.

Start your cryptographic risk assessment with QROS

Explore now →