Skip to content

Post-quantum cryptography · Embedded and medical devices

Your device will outliveits cryptography.

PraQtic maps the cryptographic gap in embedded and medical devices, quantifies the risk, designs the migration, and executes it down to the firmware. On your hardware.

Next regulatory milestoneCRA Article 14

CRA vulnerability reporting

11 September 2026

T−000d00h00m00s
Layer / Network

Enterprise tools stop at the network.

Strong on enterprise IT inventory. They do not reach the embedded and firmware level.

Layer / Documentation

Consultancies stop at the report.

Breadth without embedded-crypto depth or medical regulatory fluency.

Layer / Firmware

PraQtic works where the product lives.

Gap assessment through hands-on hardware and software implementation, on your actual device.

Regulatory clock

Devices shipping today are still in service when the deadlines land.

Device lifetime from todayMilestone
  1. 11 September 2026CRA Article 14

    CRA vulnerability reporting

  2. 11 December 2027Regulation (EU) 2024/2847

    The CRA applies in full

  3. 2030NIST IR 8547

    RSA and ECC class algorithms deprecated

  4. 2035NIST IR 8547

    Removed from NIST standards

Three service lines

From cryptographic inventory to migrated firmware.

01

Consulting and program execution

Organizational PQC migration

For organizations that need to become quantum-safe across their IT and product estate.

  1. Map the cryptographic gap and quantify the risk (cryptographic inventory, CBOM).
  2. Suggest solutions and alternatives, vendor-neutral.
  3. Phased migration roadmap prioritized by risk level.
  4. Third-party equipment upgrades, or benchmarking for replacement where upgrades are not viable.
  5. Plans built around existing equipment and future product plans, not rip-and-replace.
  6. End-to-end execution, not just a report.
02

Hardware and software development

PQC migration for embedded devices

For device manufacturers whose products themselves must become quantum-safe.

  1. Map the gap and quantify the risk at the device and firmware level.
  2. Solution options across three paths: software-only migration, hardware add-on (for example, a secure element), or board redesign.
  3. End-to-end execution, software-only or combined hardware plus software.
03

Regulatory and security engineering

Cybersecurity consulting for embedded systems

Emphasis on medical devices and their regulatory obligations: FDA premarket cybersecurity requirements (Section 524B), the EU MDR's cybersecurity requirements, and the EU Cyber Resilience Act where it applies.

  1. Threat modeling.
  2. SBOM and CBOM work, built using the CycloneDX standard.
  3. Secure development lifecycle alignment (IEC 62304 context).
  4. Premarket submission support.

How an engagement works

01

Discovery call

The client's product, market, and deadlines.

02

Gap assessment

Cryptographic inventory and risk quantification.

03

Roadmap

Phased options with effort, cost, and compliance mapping.

04

Execution

PraQtic implements, or the client's team does with PraQtic oversight.

CRA Article 2(2)

Exempt does not mean unaffected.

Regulation (EU) 2017/745 · 2017/746

  1. Regulation (EU) 2024/2847
  2. CRA Article 2
  3. CRA Article 14 · MDR Annex III
  4. MDR Annex I · MDCG 2019-16

Net position

Common questions

The questions buyers actually ask.

Do we really need PQC before quantum computers exist?
Our device has a tiny MCU. Can it even run PQC?
Software-only update, hardware add-on, or redesign: how do we choose?
Does the CRA apply to our medical device?
What does the CRA require right now?
We already work with a security consultancy. Why PraQtic?
What is a CBOM?

Founder

“We do not sell a platform. We recommend what fits your device, then we build it.”

PraQtic is led by Adi, a hands-on R&D executive with approximately 25 years leading development of regulated medical and IoT/RF products, including VP R&D roles at multinational MedTech and IoT companies.

Clients get an executive-level engineer, not a junior team learning on their dime.

Practice
Founder-led
Domains
Regulated MedTech, IoT and RF
Experience
Approximately 25 years
Stance
Vendor-neutral
Scope
Silicon, firmware, protocols, compliance documentation

Contact

Start with a discovery call.

Tell me the product, the market, and the deadline you are working to. I will tell you which regime applies and what the gap looks like.

adi@praqtic.com

A scheduling link is being set up. Until it is live, email reaches us directly.