top of page
FIPs140-3 A Thematic Review
A half-year read on where FIPS 140-3 validation actually stands. Between January and mid-July 2026, 30 new FIPS 140-3 certificates were issued or announced across non-hyperscaler, non-tier-1 vendors, spanning HSMs, authentication, cryptographic libraries, edge/IoT and embedded modules. With FIPS 140-2 fully retiring on 21 September 2026, this is no longer a future consideration. It's active, measurable, and already reshaping vendor selection. This SITG-Consulting Thematic Rev
Brian Couzens
6 days ago1 min read
Β
Β
Β


A policy for a policy
ππ¨ π¨π«π ππ§π’π¬πππ’π¨π§π¬ π«πππ₯π₯π² π§πππ π π¬πππ§πππ₯π¨π§π ππ«π²π©ππ¨π π«ππ©π‘π² ππ¨π₯π’ππ²? Iβm starting to think the default answer of βyesβ might be wrong. I recently reviewed the Dutch Governmentβs Framework Cryptography Policy for the Central Government. Whatβs interesting is that it doesnβt push organisations to create yet another standalone document. Instead, it recognises that cryptographic governance can - and often should - be embedded across
Brian Couzens
Jul 92 min read
Β
Β
Β
PQC Discovery Sprint
One of the questions we're asked more than any other is: "What actually happens during a Discovery Sprint?" This carousel answers that question. Rather than talking about methodology, we've opened the lid on a real engagement for an anonymised digital challenger bank. You'll see how assumptions are tested, how evidence is gathered, why cryptographic inventories rarely reconcile, and how governance failures become visible long before any discussion about post-quantum algorithm
Brian Couzens
Jul 71 min read
Β
Β
Β
bottom of page