A KTU spin-off,
built for European critical infrastructure.
ResilQ exists because the question "is your cryptography quantum-safe?" should not require a six-month consulting engagement to answer.
Mission.
Make quantum-readiness measurable, defensible and routine for every regulated organisation in Europe — from the smallest municipality to the largest grid operator.
We believe that the migration to post-quantum cryptography is not a ten-year-from-now problem; it is a today problem with a ten-year deadline. The data your organisation handles right now will, in many cases, still need to be confidential when Q-Day arrives. The remediation work is multi-year. The regulatory deadlines are already booked. The clock is running.
ResilQ exists to make the first, hardest step concrete: an honest cryptographic inventory and a defensible quantum-readiness score. Everything else flows from there.
From research lab to product.
2018–2023 — KTU research
Years of work at the KTU Cybersecurity Competence Center on PQC migration strategies, the QARS scoring framework and the ICARUS multi-OS agent orchestrator. Initial engagements with Lithuanian KII operators.
2024 — NIST FIPS finalisation
FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) are finalised. The migration question turns from "if" to "when" — and "when" suddenly looks tight.
2025 — DORA, NIS2 in force
Cryptographic governance becomes auditable across financial services and essential entities in the EU. The market need for QARS-NI as a product, not a research artefact, becomes obvious.
2026 — ResilQ launches
We spin out as ResilQ to bring the platform to market — first to Lithuanian KII operators and EuroQCI participants, then across the EU. Sovereign edition is the default, not the exception.
How we operate.
Data stays in Europe.
Default deployment is EU-hosted in Vilnius. Sovereign edition is on-prem and air-gap-capable. Source code is shipped with Sovereign so customers can verify what they run.
Defensible scores.
QARS-NI is published, peer-reviewed and re-implementable. Every finding ships with the input vector that produced it. We will not ask you to trust a black box.
No agents, no risk.
Discovery is credential-less. Enrichment is short-lived and self-erasing. Every command is auditable. Read-only by default; nothing is modified without explicit consent.
Built on KTU.
QARS-NI, ICARUS and the sector test lab all originated as research. We keep one foot in the lab — every release is validated against reproducible Proxmox replicas.
What you can audit us on.
PQC readiness
We dogfood our own platform — ResilQ runs continuous QARS-NI scans against its own infrastructure. The score is part of our internal SLA.
NIS2 self-attestation
As an essential digital infrastructure provider, we operate to NIS2 standards ourselves and can share the self-attestation pack with prospects on request.
DORA-aligned
Vendor due-diligence package available for financial-sector customers on request — ICT third-party risk register, exit plan and resilience testing evidence.
Source escrow
Sovereign customers receive source-shipped deployment with a defined escrow arrangement, so continuity is guaranteed independently of the vendor.