Cryptography Compliance Assessment & Risk Audit

Job ID: 39975221

Budget: ₹500,000 – ₹1,000,000 INR

I need a seasoned cryptography specialist to review our existing encryption protocols, key-management setup and digital-signature workflows with one clear objective: prove that everything we run can stand up to recognised standards and regulations.

Here’s what the engagement will look like:

• You receive full technical documentation and limited test-environment access to the three areas in scope.
• You analyse algorithm choices, key sizes, entropy sources, storage and rotation practices, signature generation and verification paths, plus any supporting libraries or HSM integrations.
• You map each finding to the most relevant benchmark—Saudi NCS, NIST guidance, FIPS 140-3, ISO 27001 Annex A controls, ETSI, or comparable frameworks—highlighting any compliance gaps or latent vulnerabilities.
• You deliver a concise risk report that ranks issues by severity, explains potential impact, and recommends practical, standards-aligned remediation steps. A short executive summary for non-technical stakeholders closes the loop.

Acceptance criteria
– All three system categories are covered.
– Each recommendation references the specific clause or section of the governing standard.
– The final document is clear enough for our auditors to trace evidence without follow-up questions.

Experience with formal cryptographic validation, code review tools, and threat-modelling techniques will help you move quickly. I will be available for questions throughout testing and can provision additional logs or sample data on request.

If you are confident deciphering complex crypto stacks and translating them into plain-English compliance insights, let’s get started.