top of page


FIPS 140-3 Gap Analysis: fix the module before the lab, not after
For many years we have run cryptographic module readiness reviews inside larger governance and assurance engagements. It was never a named line item. It was the work done before a vendor spent money at a testing laboratory, so the money was not wasted. We have now formalised it as a defined service: the SITG FIPS 140-3 Gap Analysis. The context is a hard deadline. FIPS 140-2 certificates sunset on 21 September 2026 and move to the Historical List. From that date, a module wit
Brian Couzens
Jul 232 min read


The #EO14409 isn’t a genesis point - it is a compliance hammer.
The #EO isn’t a genesis point - it is a compliance hammer. There is an immense amount of noise surrounding the newly issued Executive Order 14409, "Securing the Nation Against Advanced Cryptographic Attacks." Many commentators treat it as a sudden wake-up call that magically creates a post-quantum cryptography (PQC) migration strategy out of thin air. Before making that claim, look at what already existed. Federal policy did not start on 22 June 2026. Agencies have been opera
Brian Couzens
Jun 242 min read
𝐅𝐨𝐮𝐧𝐝𝐞𝐫 𝐏𝐫𝐨𝐝𝐮𝐜𝐭 𝐑𝐞𝐯𝐢𝐞𝐰 𝐚𝐧𝐝 𝐕𝐚𝐥𝐢𝐝𝐚𝐭𝐢𝐨𝐧™
For many years, SITG Consulting has delivered independent product assurance, validation and challenge as part of our broader Assurance and Validation services. What has changed is demand. Every week we receive enquiries from founders, technology companies, investors and advisory firms seeking independent assessment of products, platforms, governance frameworks and strategic claims. Many of those conversations begin in the same way. "We have built something." "Can we prove it?
Brian Couzens
Jun 192 min read
bottom of page
