Executive briefing · CISO & Compliance

Compliance that survives the quantum computer

One online cybersecurity platform to assess cryptographic risk with economic impact (FAIR), CIS/STIG/PCI hardening, IPS/IDS firewalling, post-quantum PKI, an artificial intelligence (AI) remediation agent and auditable evidence — for the operational resilience of banking, defense and financial institutions facing the quantum threat.

DORA · PCI-DSS v4.0 NIST 800-53 / SP 800-208 EBA ICT · ISO 27001/2 FAIR · NIST CSF 2.0 · CIS v8
The problem

The cryptography protecting the bank today silently expires

A fault-tolerant quantum computer will break RSA-2048, ECDSA and ECDH (Shor's algorithm). The adversary is already recording encrypted TLS traffic today to decrypt it tomorrow — "Store Now, Decrypt Later". Financial and defense records must be kept for 10+ years: whatever you encrypt now with classical cryptography is exposed before it expires.

Why it's critical for banking and defense

  • 10+ year data (transactions, KYC, state secrets) protected today with RSA/ECDSA that Shor breaks in hours.
  • TLS traffic intercepted now and archived: today's captures are decrypted once quantum hardware matures.
  • Slow PKI rotation (roots, HSMs, server certificates): migration takes years, not months.
  • The regulator demands anticipation: DORA (Arts. 5/6/8), EBA ICT, NIST SP 800-208 and DoD RMF mark the start of the transition.
  • Hardening and PCI-DSS aren't optional: the average breach cost exceeds €4M (IBM 2024); in defense, the exposure is strategic.
RSA-2048 / ECDSA P-256 — vulnerable to Shor
90% of endpoints today
3DES / RC4 / SHA-1 — still in legacy
incompatible with PCI-DSS v4.0
TLS 1.0/1.1 — deprecated by PCI-DSS
explicit negotiation forbidden
SNDL (Store Now, Decrypt Later)
capture window: 5–10 years active
ML-DSA / SLH-DSA / Falcon — NIST finalized
resistant to Shor and Grover
Learn more about quantum readiness
Why now

The standard is closed. The migration window is open.

The post-quantum cryptography (PQC) standard is no longer theoretical. NIST finalized FIPS 203, 204 and 205 in 2024, and the regulators — DORA, EBA, NIST SP 800-208, CNSS Policy 15 / CNSA 2.0 and the DoD RMF — now expect cybersecurity teams to demonstrate quantum readiness, not just talk about it. artificial intelligence accelerates the adversary's side too: AI-assisted cryptanalysis and automated exploitation shrink the window in which classical cryptography remains safe. The organizations that start their cryptographic inventory and PQC migration now are the ones that stay compliant when hybrid TLS 1.3 (X25519+ML-KEM) becomes the browser default.

2024NIST publishes FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA). Post-quantum algorithms are standardized.
2025–27CNSS Policy 15 / NSA CNSA 2.0 require PQC for national systems. NIST SP 800-208 and DoD RMF guide migration.
2025DORA in force (EU): digital operational resilience and cryptographic risk management as a governance obligation.
2026–28Hybrid TLS 1.3 (X25519+ML-KEM) ships in browsers. Those who don't migrate fall out of compliance.

Cryptographic risk timeline

Today SNDL capture active 2026 Crypto inventory 2027–28 PKI migration 2030 PQC hybrid 2030–35 Quantum hardware

Starting inventory and prioritization now reduces the exposure window and aligns with the regulator's expectation of “reasonable anticipation”. Every quarter of delay is a quarter of Store Now, Decrypt Later traffic accumulated against you.

Learn more about quantum readiness
The platform

QROS: one platform, the full cryptographic compliance chain

From risk detection to auditable evidence, without switching tools. Nine integrated modules with real cybersecurity tools and remote execution via Ansible — the client only uses the online platform. An artificial intelligence remediation agent closes the loop from finding to fix, and every artifact is anchored to quantum-safe cryptography so the evidence itself survives the post-quantum transition.

See all services
Feature · Assessment

Quantum readiness assessment with prioritized scoring

QROS · Scan · retail-bank.example.com:443job done
50quantum score
Retail banking · endpoint TLS
retail-bank.example.com
RSA-2048 · ShorTLS 1.2SHA-256HSTS on
RSA-2048 vulnerable to ShorPriority: Immediate
Data retention ≥10 years (transactions)HNDL +20
No PQC support in the TLS stack12 months
Migrate to Ed25519 / ML-DSA-65 hybridremediated
0–100Per-system scoring weighting algorithm, key, data type and retention (HNDL)
Immediate · 12m · LPPriority bands with actionable recommendation per finding
LaTeX reportExportable executive document for committee and audit
CVE NVDLinks the OpenSSL/TLS version to CVEs and concrete remediation
Learn more about the TLS + CVE scan
Feature · AI Remediation

Every scan finding gets resolved by an AI agent

QROS · AI Agent · retail-bank:443Ollama · llama3
Finding (scan)
RSA-2048 vulnerable to ShorCVE-2024-…
AI remediation proposal
- name: Rotate to hybrid PQC cert qros_pki_cert: cn: app.banco.com algorithm: p256_mldsa44 state: present when: confirm | bool
confidence 92% NIST SP 800-208 CIS §2.2 CVE refs

AI under your control, not a black box

  • Local Ollama or any OpenAI-compatible endpoint: your data never leaves the perimeter.
  • Per finding: generates an Ansible task, rationale, severity and links to the standard and CVE.
  • Human-in-the-loop: nothing runs without the operator's confirm=true.
−1 clickfrom finding to a remediation task ready to launch
On-premlocal models without sending evidence to third parties
Learn more about the AI remediation agent
Feature · Hardening

CIS / NIST-STIG / PCI-DSS audits with real Ansible roles

Hardening is where cybersecurity compliance becomes concrete. QROS runs the real ansible-lockdown galaxy roles and OpenSCAP profiles — not toy templates — over SSH against your fleet, with section selection so you audit only what the regulator asks this quarter. Hundreds of controls per OS, persistent evidence, and a score the auditor can read.

QROS · Audit · RHEL 9ansible
CISNIST-STIGPCI-DSS
Audit onlyAudit + Repair
Sections (group selection)
Section 1 — Initial setup84
Section 2 — Services61
Section 4 — Logging39
Section 5 — Access72
Section 6 — Network55
63score
471 controls · 627–1241 real tasks per OS

Real galaxy roles, not toy templates

  • ansible-lockdown complete CIS/STIG (627–1241 controls per playbook), pinned versions.
  • PCI-DSS via OpenSCAP: installs openscap + SSG, evaluates the pci-dss profile and returns the HTML report.
  • Real SSH execution: you generate the key, install it on the host and launch the playbook as an async job (RQ).
  • Section selection with --tags: audit only what the regulator asks this quarter.
  • Persistent evidence: ansible log + score saved to the profile, downloadable for audit.
10 OSUbuntu/Debian/RHEL/Win · 20 CIS + 8 STIG + 8 PCI playbooks
Cat. I/II/IIISTIG grouped by severity (RHEL 9 = 478 controls)
Learn more about CIS / STIG / PCI hardening
Feature · Perimeter

Firewall: Cloudflare-style IPS + IDS + Monitoring deployed by Ansible

The perimeter is the first line of cybersecurity defense and a PCI-DSS requirement. QROS deploys a Cloudflare-style WAF, an IDS feeder and a monitoring stack — all via Ansible, all with the same auditable evidence as the rest of the platform. The WAF blocks what the IDS detects, and monitoring taps traffic at the firewall itself, so no agents are installed on servers running third-party services.

QROS · Firewall · IPS (HAProxy)ips.qros.dev
IPS features
Anti-Tor
Anti-Proxy/VPN
Anti-Bots
Block IDS (Suricata)
Anti-Scan
Block malware IPs
Frontends / Backends
frontend fe_web bind :443 ssl crt /etc/haproxy/site.pem alpn h2 acl host_app req.ssl_sni -i app.banco.com use_backend be_app if host_app backend be_app server s1 10.0.0.5:8443 check ssl verify none

Three deployments, one wizard

IPS / WAF (HAProxy) — Cloudflare-style reverse proxy; DNS → ips.qros.dev; ACLs, anti-Tor/proxy/bot/scan, malware and IDS-drop blocking.
IDS (Suricata + Snort) — community/ET-Open rules; feeder pouring dropped IPs into /etc/haproxy/ids_blocks.lst.
Monitoring — OpenSearch/Grafana via Docker, tapped at the firewall itself; no agents on the backends.
LinuxUbuntu / Debian / RHEL · generated or reused SSH key · RQ job with evidence
Learn more about the firewall, IPS & IDS
Feature · PKI

Post-quantum PKI: CA, hierarchy, CRL and NIST-finalized certificates

The quantum migration lives or dies in your PKI. QROS issues ML-DSA, SLH-DSA, Falcon and hybrid classical+PQC certificates (FIPS 204/205/206) via an on-host oqs-provider, builds a CA + CRL hierarchy, and verifies the full chain — including revocation — in real time. Issue PQC certificates today so there is zero re-architecture when the regulator mandates it.

QROS · Generate · certificatePQC ✓
Subject
CN=app.banco.com · O=Banco SA
ML-DSA-65Ed25519ECDSA P-256RSA-3072
p256_mldsa44 hybridSLH-DSAFalcon-512
Validation (8 checks)
✓ Key length ≥ 256-bit eq
✓ Modern curve
✓ SHA-2/3 signature
✓ SAN present
✓ Validity ≤ 398d
✓ CA:FALSE / EKU
✓ Must-staple
✓ Shor-resistant
passesAllTests = true

CA hierarchy + real revocation

ROOT CA Intermediate Leaf TLS CRL · REVOKED
oqs-providerliboqs + oqs-provider compiled in place; ML-DSA 44/65/87, SLH-DSA, Falcon and hybrids (FIPS 204/205/206)
Public CRLCA-signed revocation, served at /ca/{fingerprint}/crl; integrated chain verification
Learn more about post-quantum PKI
Feature · Identity

W3C Verifiable Credentials signed with your PKI

Issue credentials — KYC/AML, access, employee clearance, accreditations — signed with your certificate (classical or post-quantum) and verify them publicly via a shared link. The private key never leaves the browser. This is AI-ready digital identity: reusable, cryptographically verifiable credentials that an artificial intelligence workflow or a regulator can check without contacting your backend.

QROS · Credential · AccessBadgequantum
JD
Jane Doe · Risk Officer
Banco SA · Clearance: HIGH
typeAccessBadge, EmployeeCredential
proofML-DSA-65 · Ed25519Fallback
issuerdid:web:banco.qros.dev
statusverified · not revoked
verify → bancomark.qros.dev/v/k7T…9xQ

Public verification, no backend

  • Anyone with the link re-verifies the proof (no login, no account).
  • Checks CA chain and CRL revocation in real time.
  • Quantum posture badge: “Shor/Grover-resistant” if ML-DSA.
KYC / AMLReusable verifiable client credential across institutions
ClearanceAccess badge for cross-system authorization (banking/defense)
No key custodyThe public PKI is stored to verify; the private key stays in the issuer's browser
Learn more about verifiable credentials
Feature · Data

Document cryptography: .qros envelopes, signatures and OTP

Records must stay verifiable for 10+ years — long enough that they will be re-verified post-quantum. QROS hybrid .qros envelopes wrap files in a classical + PQC key with a detached signature and SHA-256 fingerprint, plus a cert-bound OTP. Own auditable format, transport-independent: the integrity of transactions, KYC and classified documentation survives the transition.

Hybrid .qros envelopes

File encrypt/decrypt with a hybrid key (classical + PQC), with a separate verifiable signature and SHA-256 fingerprint. Own auditable format, transport-independent.

$ qros verify envelope.qros doc.pdf cert.pem ✓ algorithm: Ed25519 + ML-DSA-65 (hybrid) ✓ quantum: true ✓ verified · integrity OK

Detached signature + cert-bound OTP

Detached signature with your cert (incl. PQC) and an OTP seeded by the certificate fingerprint + a chain block height — not a shared secret, but cryptographically derived.

otpauth://…QR generatedquantum-resistant

Port scanner + CVE (NVD)

Banner grab + NVD lookup per host/port, aggregate scoring and multi-host executive summary for fleet inventory.

Record integrity (SOX/GDPR)

Signed .qros envelopes for immutable evidence of transactions, KYC and classified documentation — integrity verifiable years later, even post-quantum.

Learn more about document cryptography
Feature · CVE Scanner

Port + CVE scanner (NVD): from banner to CVE in one job

Port mapping, banner grabbing and NVD lookup per host/port — IPs, domains or expanded CIDR ranges. Global CVSS×10 scoring and a multi-host executive summary for fleet inventory; every CVE is one click from the AI remediation agent. This is continuous cybersecurity hygiene aligned with NIS2/DORA ICT-asset inventory obligations.

QROS · CVE Scan · retail-bank.example.comNVD · done
Target ports
22 ssh80 http 443 https6379 redis 80809200 elastic
Vulnerability reportCRITICAL
1 target · 4 ports · 3 open · 5 CVEs · worst CVSS 9.8
Global score (CVSS×10) 98/100
:6379redisRedis 6.2.6critical · 2 CVEs
CVE-2023-25155criticalCVSS 9.8
Lua sandbox escape via cjson in Redis — unauthenticated remote RCE.
:443httpsnginx 1.20.1high · 3 CVEs
CVE-2021-23017highCVSS 7.7
DNS resolver off-by-one — 1-byte out-of-bounds write.
:22sshOpenSSH 9.3p1no known CVEs

How it works

  • Banner grab per port (HTTP probe + TLS on 443/8443), with bounded timeouts.
  • Banner parser → software + version (nginx, Apache, IIS, Redis, MySQL, Tomcat, OpenSSH…).
  • NVD lookup (public API, no key) by software/version: CVSS, CWE and references.
  • Global CVSS×10 scoring with critical/high/medium/low bands per host and fleet.
Multi-hostIPs, domains or CIDR (expanded, max 256) in a single RQ job
→ AIevery CVE is sent to the remediation agent in one click
NVD + CWEid, CVSS, severity, weakness (CWE) and mitigation per CVE; link to the vendor patch
Learn more about the port + CVE scanner
Feature · Risk assessment

Assisted risk system with economic impact (FAIR)

The crisis cabinet decides in money, not in traffic lights. QROS guides you from departments → systems → keys → scenarios and quantifies each in €/year (ALE = LEF × LM), with a threat & control catalog suggested from NIST 800-30 and what-if remediation simulation. This is the economic spine of DORA/EBA ICT-risk reporting.

QROS · Guided Assessment · Banco SAFAIR + NIST 800-30
TreasuryTradingRetailKYC/AMLBackoffice
Exposure by department (€/month at risk)
Treasury€18k/m Trading€14k/m Retail€9k/m KYC/AML€6k/m Backoffice€3k/m
ScenarioLEFLMALE
TLS compromise — Treasury0.4/yr€2.4M€960k/yr
KYC leak (SNDL)0.8/yr€1.1M€880k/yr
Credential fraud — Retail1.2/yr€180k€216k/yr
ALE = LEF × LMAnnualized loss exposure = frequency × loss magnitude (FAIR)

Assisted, step by step

  • Wizard: departments → systems → keys → scenarios.
  • Threat & control catalog suggested (NIST 800-30).
  • Prioritization by ALE and “what-if” simulation with remediation.
  • KPIs ready for the crisis cabinet and DORA/EBA reporting.
€/yrAggregated exposure by department
CrisisDashboards for activation and decision
Learn more about the guided assessment
Methodological framework

Risk methodologies we comply with — from FAIR to the military RMF

QROS is not a proprietary scoring invention. Every risk number is traceable to an internationally recognized cybersecurity methodology, so the evidence holds up in front of a DORA, EBA or DoD RMF auditor. artificial intelligence assists the analyst; the methodology — not the model — owns the conclusion.

Every scenario is quantified in economic impact (€/year)

Essential for the crisis cabinet (decisions in money, not in traffic lights) and for banking reporting DORA/EBA — with traceability down to each control and evidence.

Learn more about the risk methodologies
Feature · Reports & evidence

Automatic reports and evidence ready for auditors

The regulator and the auditor get the paper, not the word. QROS generates LaTeX/PDF executive and technical reports automatically, with per-control evidence packages (Ansible log, scan result, certs, .qros signatures) and a signed, immutable chain of custody — classically or post-quantum signed, verifiable years later.

QROS · Report · DORA Q4 2026.pdfauditor-ready
Executive Risk Report
Banco SA · DORA Art. 5/6/8 · Q4 2026
Executive summary + score 88/1002 pp
Cryptographic inventory (47 hosts)6 pp
CIS/PCI evidence per control31 pp
FAIR scenarios + ALE (€/yr)8 pp
Signed chain of custodyappendix
94evidence
Evidence coverage 94% · digitally signed (PQC)

Evidence packages per standard

  • DORA / EBA, PCI-DSS v4.0, ISO 27001, NIST 800-53 / DoD RMF — one click.
  • Per-control artifacts: Ansible log, scan result, certs, .qros signatures.

Immutable chain of custody

  • Every action logs actor + timestamp + hash; exportable to SIEM.
  • Signed appendices (classical or PQC) — verifiable years later.
LaTeX + PDFExecutive and technical reports generated automatically
1 clickFrom finding to an auditor-deliverable package
Learn more about reports & evidence
Regulatory mapping

How QROS covers the banking and defense regulatory framework

One platform, every framework. Each row below maps a regulatory requirement to the QROS module that satisfies it and the evidence artifact it produces — from DORA and EBA ICT risk to the DoD RMF, PCI-DSS v4.0 and NIST SP 800-208 PQC migration. The same evidence and scoring serve the banking supervisor and the defense accreditor.

Standard / regulationKey requirementQROS coverageModule
DORA (EU)Arts. 5/6/8 — ICT risk, resilience, cryptographyCrypto inventory + hardening + firewall + evidenceScan · Audit · Firewall
NIST SP 800-208 (PQC)Migration to post-quantum algorithmsML-DSA/SLH-DSA/Falcon + hybrid certificatesGenerate · PKI
CNSS Policy 15 / CNSA 2.0PQC use in national systemsHierarchical PQC PKI + CRLPKI · CA
DoD RMF (NIST 800-37)Risk management & authorization (defense)FAIR + NIST 800-30 assessment + per-control evidenceAssessment · Reports
PCI-DSS v4.0Req. 2/4/11/12 — strong crypto, TLS, firewall, monitoringOSCAP audit + WAF + IDS + MonitoringAudit · Firewall
NIST 800-53 / STIGOS hardening (hundreds of controls)Real ansible-lockdown CIS/STIG rolesAudit
NIST CSF 2.0Govern · Identify · Protect · Detect · Respond · RecoverMapping of all 9 modules to the 6 functionsPlatform
EBA ICT & Security RiskICT risk governance and reportingLaTeX report + FAIR economic exposureAssessment
ISO 27001/27002 (Annex A)Cryptographic controls (A.10), access (A.9), network (A.13)PKI + VC + WAF + hardeningPKI · VC · Firewall
GDPR / SOX (integrity)Personal data protection and record integritySigned .qros envelopes + detached signaturesCrypto
Learn more about cryptographic compliance
Architecture

Online platform, self-hostable, no external SaaS

The client uses the online platform; deployment, operation and patching are our responsibility. No data leaves the client's perimeter. A FastAPI API fronts a Redis + RQ job queue that drives the real cybersecurity tools (testssl.sh, oqs-provider, ansible-lockdown, OpenSCAP) and the artificial intelligence remediation agent — all reached over SSH/WinRM against the on-prem or cloud fleet.

Frontend React/Vite + shadcn API FastAPI (OpenAPI /docs) Redis + RQ (jobs/worker) Real tools (testssl, oqs…) Ansible + AI agent Client fleet (SSH/WinRM · on-prem / cloud)
Operated by QROSDeployment, patching and operation are our responsibility; the client only consumes the platform.
AgentlessMonitoring tapped at the firewall frontends/backends: zero agents on hosts with third-party services.
Ansible autoAutomatic deployment of galaxy roles; no manual intervention per host.
Data in your perimeterRedis stores reports, certs, signatures, VCs and artifacts; never the private key.
Learn more about how QROS works
Trust & security

Designed never to touch your secrets

Trust is engineered, not promised. Private keys for certificates and signatures are generated and kept in the browser; the server only sees public material and the result. Any action that mutates a host requires an explicit confirm=true and a valid operator SSH key. Standard, audited tools throughout — no opaque homegrown cryptography.

No private-key custody

Private keys for certs/signatures are generated and kept in the browser; the server only sees public material and the result.

JWT + OAuth + rate-limit

JWT sessions (HS256), Google OAuth PKCE, email/pwd bcrypt login, per-IP rate-limit and CSP/X-Content-Type-Options headers.

Explicit, confirmed execution

Any action that mutates a host (audit/repair, firewall, AI remediation) requires confirm=true and a valid operator SSH key.

Auditable evidence

Each job leaves a log + score + artifact on the profile, downloadable; the regulator and auditor get the paper, not the word.

Standard tools

testssl.sh, RsaCtfTool, oqs-provider, ansible-lockdown, OpenSCAP, Ollama: no opaque homegrown cryptography.

Worker isolation

Heavy jobs and the AI agent run in a separate RQ process with timeout and pinned venv; the API stays light and responsive.

Read the legal notice
What the CISO gains

Measurable benefit, not a promise

From unquantified risk to €X/yr and 88/100 in a single quarter: inventory + ALE-prioritized remediation + PCI hardening + a pilot PQC PKI, with evidence ready for the ICT risk committee and the crisis cabinet. artificial intelligence compresses the finding-to-fix loop; quantum-safe issuance today removes the re-architecture bill tomorrow.

−70%cryptographic inventory time for the fleet (automated scan vs. manual)
Ansible autoautomatic deployment with galaxy roles; 1 platform vs. 5–7 loose tools
Agentlessmonitoring tapped at the firewall frontends/backends; zero agents on machines with third-party services
€/yr (FAIR)exposure quantified per department for the crisis cabinet
AI −1 clickfrom finding to a proposed remediation, with no manual work
Evidencedownloadable per control for DORA/PCI/ISO auditors, no manual screenshots
PQC-readyML-DSA/SLH-DSA issuance today; zero re-architecture when the regulator mandates it
Banking + DefenseDORA/EBA and DoD RMF/STIG mapping with the same evidence and scoring
88post-QROS

From unquantified risk to €X/yr and 88/100 in a single quarter

Inventory + ALE-prioritized remediation + PCI hardening + pilot PQC PKI, with evidence ready for the ICT risk committee and the crisis cabinet.

See pricing and plans

Start your quantum-readiness assessment now — it's free

Explore your exposure →

FAQ

Why do I need QROS if I already have Shodan?

Shodan and Censys index open ports and certificates, but they don't score quantum risk, don't generate PQC certificates, don't run CIS audits, and don't produce compliance evidence. QROS adds the quantum-readiness and compliance layer that Shodan lacks.

Is the quantum threat real?

Yes. 'Store Now, Decrypt Later' attacks are already happening — adversaries collect encrypted traffic today, knowing a future quantum computer will break RSA and ECC. NIST has standardised post-quantum algorithms (FIPS 204/205). The question is not 'if' but 'when', and organisations that start migration early have a massive advantage.

Is QROS free?

QROS Explore — the public search engine — is free and requires no login. The authenticated platform (TLS scans, PQC certificates, CIS audits, guided assessments) has paid plans starting at €50/month.

Is QROS compliant with NIS2 and DORA?

Yes. QROS produces the cryptographic asset inventory and risk assessment evidence that NIS2 Article 21 and DORA Article 9 require. The guided assessment generates audit-ready reports with per-asset risk scores and remediation plans.

Start your cryptographic risk assessment with QROS

Explore now →