Watch + readVideo companion
After Q-Day Explained: what mid-market CISOs should do this quarter
Original takeaways from a popular Q-Day explainer — plus what to do this quarter.
Open article →
Public curriculum
A structured path for CISOs, security engineers, and developers. Each layer pairs YouTube explainers with Qtangl articles, NIST references, and checkpoints you can use in planning meetings.
Video companions
Every video opens with an embedded player on the blog article — plus source citations, checkpoints, and inventory steps Qtangl customers use.
Watch + readVideo companion
Original takeaways from a popular Q-Day explainer — plus what to do this quarter.
Open article →
Watch + readVideo companion
Practitioner insights on HNDL — and how to inventory before migration finishes.
Open article →
Watch + readVideo companion
ML-KEM, ML-DSA, and SLH-DSA in plain language — with a migration checklist.
Open article →
Watch + readVideo companion
Shor's algorithm in plain language — plus what to inventory this quarter.
Open article →
Watch + readVideo companion
From Shor's to NIST FIPS — the full arc in one video companion.
Open article →
Watch + readVideo companion
Period-finding without a math degree — and PKI inventory next steps.
Open article →
Watch + readVideo companion
Hear Shor explain the algorithm — then inventory your certificates.
Open article →
Watch + readVideo companion
Dustin Moody's 12-month playbook for enterprise PQC migration.
Open article →
Watch + readVideo companion
FIPS status, backup algorithms, and 2035 deprecation tiers.
Open article →
Watch + readVideo companion
Mosca inequality for executives — with board-ready framing.
Open article →
Watch + readVideo companion
Why NIST keeps standardizing after FIPS 203–205.
Open article →
Watch + readVideo companion
What Cloudflare's 2029 roadmap means for your program.
Open article →
Watch + readVideo companion
CISA guidance translated for mid-market security teams.
Open article →
Watch + readVideo companion
Lattice KEM and signatures from Alfred Menezes' course.
Open article →
Watch + readVideo companion
Prototype ML-KEM with liboqs — and know production limits.
Open article →
Five layers
Work through the layers in order, or jump to the checkpoint that matches your next board question.
Layer 1
Checkpoint: Can you explain in two minutes why Shor's algorithm breaks RSA but AES mostly survives?

Layer 2
Checkpoint: Can you apply Mosca's X + Y > Z to a dataset with a 20-year confidentiality requirement?

Layer 3
Checkpoint: Can you name FIPS 203, 204, and 205 and what each replaces in today's PKI?

Layer 4
Checkpoint: Can you describe hybrid TLS and why signature migration is harder than KEM?

Layer 5
Checkpoint: Can you explain what a CBOM is and why re-scan proof matters for auditors?

Diagrams
Stay on track
Week-by-week watchlist, NIST bibliography, and checkpoint reminders — delivered to your inbox. Or open the full printable guide.
Apply what you learn
When you finish a layer, run a baseline scan and export a CBOM — the curriculum links to Qtangl tools, but the concepts stand alone.