The team behind quantum readiness
QROS is built by Equantum Ciberseguridad y Blockchain S.L., a Spanish cybersecurity company in Vigo (Galicia) focused on one mission: give every organisation a clear, evidence-based path to cryptographic resilience and quantum readiness — before post-quantum cryptography becomes a compliance deadline, not a talking point.
Who we are
Equantum is a cybersecurity and blockchain engineering company. We build QROS — a platform that combines internet-wide discovery, cryptographic risk assessment, automated hardening and on-prem AI agents into a single quantum-readiness workflow. Our team works across post-quantum cryptography (NIST PQC), cryptographic risk (FAIR, NIST SP 800-30/37), baseline hardening (CIS, STIG, PCI-DSS) and regulatory compliance (DORA, NIS2). We publish what we build and cite the standards we work against, so our methods are auditable rather than proprietary folklore.
Leadership
Pablo López — Founder & CEO
Founded Equantum in 2021 to make cryptographic resilience a tractable engineering discipline. Cryptographer by training; leads QROS product, research and the post-quantum readiness framework. LinkedIn →
Equantum on LinkedIn
Company updates, the QROS Cryptographic Readiness Framework™ and field notes from the team. Follow Equantum QROS →
Our mission
RSA and ECC — the cryptography that secures the internet today — are broken by a sufficiently large quantum computer (Shor's algorithm). Migration to post-quantum cryptography (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) is not optional; it is a multi-year programme that regulators are already scheduling (DORA Article 9, NIS2). Our mission is to make that programme tractable: discover what you have, score what is at risk, and remediate it with signed, reversible automation — with evidence your auditor can read.
What we work against
We do not invent our own methodology. Every QROS assessment and remediation is grounded in a published, peer-reviewed standard, so the result is defensible in an audit:
Post-quantum cryptography
NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA); NIST SP 800-208 (stateful hash signatures); the Open Quantum Safe oqs-provider for OpenSSL.
Cryptographic risk
FAIR for quantitative loss exposure; NIST SP 800-30 (risk assessment) and SP 800-37 (RMF) for the assessment lifecycle.
Hardening baselines
CIS Benchmarks (L1/L2), DISA STIG, and PCI-DSS for both Linux (RHEL, Debian) and Windows Server fleets.
Regulation
DORA (digital operational resilience, Art. 9 ICT security) and NIS2 (EU cybersecurity of essential entities) for the compliance evidence layer.
How we build
QROS runs on open, auditable technology rather than black boxes — HAProxy, Suricata and Snort at the perimeter; OpenSearch and Grafana in the SOC; OpenSSL with oqs-provider for post-quantum; Ansible for idempotent, check-vs-repair automation; and an Ollama-compatible AI harness so you keep control of your models and your data. See the full technology stack. The on-prem agent signs every action it takes, so a remediation is always attributable and reversible.
Our partners
Equantum is backed by institutional, venture-capital and deep-technology partners who reinforce the quantum-readiness mission: Wayra (Telefónica), Amtega (Xunta de Galicia), Horizen Labs and EternaX.
Research and content
The articles, guides and host dossiers on qros.dev are written and reviewed by the Equantum Research Team — practising engineers, not a content farm. Each page carries a byline and a last-reviewed date so you can see when it was last checked against the standard it cites. The 230 000+ host dossiers in QROS Explore are original first-party scan data, not repackaged third-party feeds.
Questions about our methods or a partnership? Write to support@qros.dev, or read our legal notice.
FAQ
Who is behind QROS?
QROS is built by Equantum Ciberseguridad y Blockchain S.L., a Spanish cybersecurity and blockchain engineering company based in Vigo, Galicia (VAT B42854737). The Equantum Research Team — practising engineers — writes and reviews all content on qros.dev.
What standards does QROS work against?
QROS assessments and remediations are grounded in published standards: NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for post-quantum cryptography; FAIR and NIST SP 800-30/37 for risk; CIS, STIG and PCI-DSS for hardening; and DORA Article 9 and NIS2 for compliance. We never invent our own methodology.
Is the content on qros.dev written by people or AI?
Every article, guide and host dossier is written and reviewed by the Equantum Research Team — engineers who build and operate QROS. The 230,000+ host dossiers in QROS Explore are original first-party scan data, not repackaged third-party feeds. We do not publish AI-summarised filler.
Start your cryptographic risk assessment with QROS
Explore now →