Skip to content
The Algorithm
Insights

Technical intelligence for people who build regulated systems.

Not policy summaries. Not lawyer-written compliance guides. Engineering analysis for the teams that actually have to implement it.

20
Articles
5
Categories
Weekly
Updated
800–1200
Words each
Latest
Security Engineering·Cross-Industry

Post-Quantum Cryptography Migration: Timeline, Standards, and Engineering Plan

NIST finalised three post-quantum cryptography standards in August 2024: FIPS 203 for key encapsulation, FIPS 204 for digital signatures, and FIPS 205 for stateless hash-based signatures. The recommendation is to begin transitioning away from RSA and elliptic curve cryptography before 2030. CNSS Policy 15 mandates migration of National Security Systems by 2033. The engineering challenge is not adopting the new algorithms — it is finding every place the old algorithms are used across a large enterprise codebase, including dependencies, third-party libraries, hardware security modules, and long-lived certificates. A crypto-agility architecture, where cryptographic primitives are abstracted behind configurable interfaces rather than hardcoded, is what makes the migration timeline achievable without rewriting every system that uses cryptography.

2025-01-20 · 13 min
Read →
All Articles — 200 pieces
Industry Intelligence10 min
Vanta / Drata
Leading compliance automation platforms — useful for evidence management, not engineering control implementation

Compliance Automation Platforms in 2026: What Vanta, Drata, and Secureframe Actually Automate

Vanta, Drata, and Secureframe automate evidence collection and policy management. They do not automate engineering controls, architecture decisions, or technical remediation. The distinction matters when you are scoping a compliance programme.

Cross-Industry · 2026-08-08
Read →
Industry Intelligence11 min
$2.4T
McKinsey upper estimate of technical debt in financial services alone — compliance debt is a subset of this

Technical Debt in Regulated Industries: The Research Behind the $2.4 Trillion Problem

McKinsey estimates $1-2.4 trillion in technical debt in financial services alone. CAST Research Lab quantifies it per line of code. In regulated systems, technical debt has a compliance dimension that standard debt metrics don't capture.

Cross-Industry · 2026-08-12
Read →
Industry Intelligence11 min
Level 4
Compliance-native architecture — the level where engineering controls satisfy compliance by design, not by audit

Engineering Maturity for Regulated Industries: A Five-Level Assessment Framework

Level 1 organisations do compliance reactively. Level 5 organisations have continuous compliance embedded in their CI/CD pipeline. Most regulated industry organisations are between Level 2 and Level 3, and the gap to Level 4 is where the significant engineering investment sits.

Cross-Industry · 2026-08-14
Read →
Compliance Engineering
65 articles
Vendor Recovery
9 articles
AI in Regulated Industries
11 articles
Architecture
45 articles
Industry Intelligence
22 articles
Industry Intelligence10 min
Vanta / Drata
Leading compliance automation platforms — useful for evidence management, not engineering control implementation

Compliance Automation Platforms in 2026: What Vanta, Drata, and Secureframe Actually Automate

Vanta, Drata, and Secureframe automate evidence collection and policy management. They do not automate engineering controls, architecture decisions, or technical remediation. The distinction matters when you are scoping a compliance programme.

Cross-Industry · 2026-08-08
Read →
Industry Intelligence11 min
$2.4T
McKinsey upper estimate of technical debt in financial services alone — compliance debt is a subset of this

Technical Debt in Regulated Industries: The Research Behind the $2.4 Trillion Problem

McKinsey estimates $1-2.4 trillion in technical debt in financial services alone. CAST Research Lab quantifies it per line of code. In regulated systems, technical debt has a compliance dimension that standard debt metrics don't capture.

Cross-Industry · 2026-08-12
Read →
Industry Intelligence11 min
Level 4
Compliance-native architecture — the level where engineering controls satisfy compliance by design, not by audit

Engineering Maturity for Regulated Industries: A Five-Level Assessment Framework

Level 1 organisations do compliance reactively. Level 5 organisations have continuous compliance embedded in their CI/CD pipeline. Most regulated industry organisations are between Level 2 and Level 3, and the gap to Level 4 is where the significant engineering investment sits.

Cross-Industry · 2026-08-14
Read →
Work with Us

Building something regulated? Talk to the team that's done it.

The first call is with a senior engineer. Tell us the regulation, the system, and the deadline. We'll tell you whether we've seen it before, what it should cost, and whether it's achievable.

Talk to an EngineerCompliance Services →
Engage Us