Quantum Security · Network Security · Data Center Security · Governance, Risk, and Compliance

PQC Migration Is a Hardware Refresh. Sitehop Just Proved It.

Sitehop's SAFEcore Edge is a 310-gram post-quantum encryption appliance for the network edge. The bet: PQC migration is partly silicon, not just code.

By Tal Eliyahu · · 9 min read

Editorial technical diagram for PQC Migration Is a Hardware Refresh. Sitehop Just Proved It.
A clean product control map showing Workflow, Control Layer, System, Policy, and Evidence as connected parts of the story. CyberBiz

The cybersecurity industry has spent two years treating post-quantum cryptography migration as a software problem. Sitehop's SAFEcore Edge bets a meaningful share is silicon.

The Sheffield-based vendor launched the device on April 15, 2026. It is small — 310 grams, USB-C powered, smaller than a paperback. It runs ML-KEM hybrid post-quantum key exchange and IPsec at 1 Gbps full-duplex through a FIPS 140-3 Level 3 secure element. It claims up to a thousand times lower PQC latency than a software-only stack. And it is designed to deploy at the places conventional crypto infrastructure does not reach: branch banks, oil platforms, retail sites, autonomous vehicles, tactical and diplomatic posts.

The launch is small, hardware-shaped, and easy to overlook. The thesis underneath it is not.

What happened

SAFEcore Edge is a hardware-enforced post-quantum encryption appliance. It is engineered to terminate ML-KEM hybrid key exchange and IPsec at the edge of a network rather than in the data center, with central management through Sitehop's SAFEnms console. The device interoperates with third-party IPsec, so buyers do not have to rip out existing VPN infrastructure to introduce quantum-safe key exchange.

Workflow diagram for PQC Migration Is a Hardware Refresh. Sitehop Just Proved It.
Workflow view of the control path, market pressure, and buyer impact behind PQC Migration Is a Hardware Refresh. Sitehop Just Proved It.. CyberBiz

Form factor matters here. At 37mm by 116mm by 68mm and under 10 watts, the appliance fits inside operational envelopes that conventional 1U and 2U HSMs and link encryptors do not. Sub-10W means it can run on USB-C from a vehicle or a portable power source. FIPS 140-3 Level 3 means it carries the regulatory check-box that critical-infrastructure and government buyers require.

Sitehop is not a stealth pre-funding outfit. The company has raised approximately £13.5 million to date, including a £7.5 million round in October 2025 led by Northern Gritstone, with participation from Amadeus Capital Partners, Mercia Ventures, Manta Ray, and NPIF. The company says its SAFE Series products are already deployed with a tier-one telco across seven countries plus government and defence customers.

The device is real. The customer base is real. The thesis is what the industry should be reading.

PQC migration was framed as a software problem

The dominant narrative on post-quantum cryptography migration since 2023 has been that the work is primarily software work. Library updates from Open Quantum Safe and the various PQC implementations of NIST-standardized algorithms (ML-KEM, ML-DSA, SLH-DSA). Hybrid TLS in the cloud platforms — Cloudflare shipped it, AWS shipped it, Confluent shipped it. KMS bolt-ons. Cryptography inventory tools. Discovery sweeps for legacy algorithm usage. Migration planning playbooks.

That narrative was not wrong. It was incomplete.

The unstated assumption was that most enterprise cryptography lives in software stacks where a library update is feasible. For a meaningful share of the actual install base, that assumption breaks. Network encryptors, link encryptors, secure tunneling appliances at branch sites, hardware security modules tied to specific protocol versions, and the bespoke crypto infrastructure deployed at critical national infrastructure sites are not refactor targets. They are appliance refreshes — and the appliances that exist today were not designed for ML-KEM hybrid handshakes.

Most of 2026's PQC migration coverage has skated past this. The federal regulatory clock is loud — NSA CNSA 2.0 deadlines, the finalized NIST FIPS 203/204/205 standards, the White House March 2026 Cyber Strategy naming PQC a federal priority — but the buyer-side conversation has been almost entirely about software stacks and inventory. The hardware refresh has been the assumed-away part of the project plan.

SAFEcore Edge says a meaningful share is hardware refresh

Sitehop's launch is the cleanest expression yet of the counter-thesis. PQC migration is partly software. It is also partly silicon.

The structural argument is not that hardware PQC will replace software PQC. It is that for specific deployment environments, software PQC is not viable on the timeline regulators are pushing. Three of those environments matter most.

The first is latency-sensitive infrastructure. High-frequency trading, real-time control systems, autonomous vehicles, and any environment where microseconds determine system behavior cannot absorb the latency tax of software-only post-quantum handshakes. Sitehop's claim of up to a thousand times lower PQC latency than software stacks is a marketing number; the underlying point — that hardware-accelerated PQC is meaningfully faster — is structurally durable regardless of where the precise multiple lands.

The second is the regulated edge. Branch banks, retail sites, hospitals, oil platforms, water treatment facilities, and military forward operating environments need crypto infrastructure they can certify, audit, and physically secure. Software running on commodity hardware is harder to certify at FIPS 140-3 Level 3 than dedicated silicon. Sitehop's appliance is purpose-built for this segment.

The third is classified networks. Government and defence customers running sovereign infrastructure need supply-chain provenance on every component of the crypto stack. A device built and validated under a specific national jurisdiction is a different procurement target than a software library compiled from open-source dependencies. SAFEcore Edge ships as exactly that kind of device.

If those three segments end up driving even a fifth of total PQC migration spend, hardware-PQC becomes a serious budget line. That category does not currently have a recognized leader.

The forgotten encryptor category

The dedicated network-encryptor category was a real product line through the 2000s and early 2010s. Thales, Senetas, IDQ, and a handful of others sold rack-mounted Layer 2 and Layer 3 encryptors into telcos, financial institutions, and governments. The category was assumed-absorbed when firewall and SD-WAN platforms grew encryption tunneling into their core capabilities. Why buy a dedicated encryptor when your firewall ships with IPsec?

PQC migration is reopening that question.

If PQC is going to be implemented in silicon at the edge for the segments above, the dedicated network-encryptor category gets re-instantiated. The question becomes whether the platform vendors — Palo Alto Networks, Fortinet, Cisco — ship competitive PQC silicon as part of their next-generation appliances, or whether the regulated-edge segment falls to specialists like Sitehop, Senetas, IDQ, and the next wave of pure-plays. Both outcomes are plausible. Both have implications for the cybersecurity M&A map we have been tracking.

The platform vendors have not yet announced credible PQC-silicon roadmaps at the regulated-edge form factor. Fortinet has gestured. Cisco has signaled but not shipped. Palo Alto has prioritized agent-runtime work. The window is open for specialists to establish position before the platforms catch up — or to become acquisition targets if the platforms decide buying is faster than building.

Sovereign crypto is the second story

The cap-table angle on Sitehop deserves separate attention.

Northern Gritstone is a UK-focused growth fund anchored by the Universities of Leeds, Manchester, and Sheffield. Its thesis centers on commercializing UK academic research at scale. Amadeus Capital Partners is a UK-based venture firm with a long history of European deep-tech bets. Mercia Ventures and NPIF are regional UK investors. The cap table is, almost entirely, British.

That is not coincidental. SAFEcore Edge is positioning explicitly as a UK-engineered, FIPS-certified, sovereign cryptography device for European and allied buyers. Adjacent moves in the same window — Airbus pursuing French cybersecurity research firm Quarkslab on a similar sovereign-cyber thesis — suggest the pattern is broader than one company.

European sovereign cryptography is not a niche. It is the buyer-side response to a US-dominated cybersecurity supply chain at the moment when US federal cyber capacity is itself under measurable strain. Allied governments and critical-infrastructure operators in the EU, UK, and parts of Asia are increasingly unwilling to accept US-only crypto in their most sensitive deployments. PQC migration is the moment when that preference becomes a procurement requirement.

The structural read for cybersecurity investors and corp-dev teams is that sovereign-cyber pure-plays in PQC silicon and other regulated-edge categories are about to see two things at once: rising procurement demand from government and CNI buyers, and rising acquirer interest from defense conglomerates and national-champion vendors. The next twelve months should produce one or two material sovereign-crypto transactions on each side of the Atlantic.

What changes for cybersecurity buyers

For procurement teams and CISOs in regulated industries, Sitehop's launch is the forward signal that PQC migration planning needs a hardware track separate from the software track.

Three practical implications.

The first is the project plan. PQC migration plans built in 2024 and 2025 typically scoped library updates, KMS replacement, hybrid TLS rollout, and inventory work. Add a hardware-refresh stream. Identify the legacy network encryptors, link encryptors, and bespoke crypto appliances in scope. Decide whether they get refreshed with PQC-capable hardware (Sitehop, Senetas, IDQ, vendor-shipped platform silicon when available) or retired in favor of a software stack with acceptable latency profile. The decision per asset is non-trivial; the inventory itself is necessary.

The second is the procurement timeline. Hardware refresh cycles run two to four times longer than software upgrades. If the regulatory deadline lands in 2030 — and CNSA 2.0 timelines suggest critical national security systems hit binding requirements earlier — the procurement work has to begin now in regulated environments. Buyers who scoped PQC as a 2028 software project will find their hardware track is already late.

The third is sovereign procurement. Buyers in regulated sectors, especially those headquartered outside the US, should expect their procurement language to add country-of-origin requirements on PQC-capable hardware over the next twelve months. The vendors that anticipate this — Sitehop is one — will land deals that pure technical comparisons miss.

What to watch next

Three signals over the next two quarters will tell us how durable the hardware-PQC thesis is.

The first is whether the platform vendors ship competitive PQC silicon at the regulated-edge form factor. PANW, Fortinet, and Cisco all have firewall families that could be extended; the question is whether they prioritize the work or concede the segment to specialists. The first platform vendor to ship a credible PQC-capable edge appliance reframes the category.

The second is whether sovereign-crypto specialists raise material rounds in the next two quarters. Sitehop's £13.5M cumulative is small for the category opportunity; meaningful follow-on funding would signal that the autonomous-publisher and software-PQC narratives are not the only games in cybersecurity. Watch for European or allied government-adjacent capital entering the space.

The third is the M&A read. If a defense conglomerate or a US public security platform acquires a sovereign-crypto pure-play before year-end, the consolidation thesis wins. If the specialists raise instead, the standalone thesis wins. Either signal is informative.

PQC migration is currently being scoped as a software project across most cybersecurity organizations. SAFEcore Edge says a meaningful share of the work is silicon. The buyers, founders, and investors who agree have a window before the platform vendors close it.

The encryptor category is back. It is just sized differently now.

Frequently asked questions

What is post-quantum cryptography (PQC), and why does the migration matter now?
Post-quantum cryptography is a class of public-key algorithms designed to resist attack by sufficiently powerful quantum computers. NIST finalized the first PQC standards (ML-KEM, ML-DSA, SLH-DSA) in 2024-2025 as FIPS 203/204/205. The migration matters now because adversaries can capture encrypted traffic today and decrypt it later once quantum computers reach scale — *harvest now, decrypt later*. NSA's CNSA 2.0 timeline and the White House March 2026 Cyber Strategy have made PQC a binding federal priority, with regulated industries expected to follow.
Why is Sitehop's launch different from other PQC products on the market?
Most PQC migration tooling shipped to date is software — libraries, KMS bolt-ons, hybrid TLS in cloud platforms like Cloudflare and AWS, cryptography inventory tools. SAFEcore Edge does the cryptography in dedicated silicon at the network edge. The differentiation is form factor and latency: a 310-gram, sub-10W appliance with FIPS 140-3 Level 3 certification, designed to deploy at branch sites and forward operating environments where conventional 1U and 2U HSMs and link encryptors do not fit. The bet is that hardware-PQC is the only viable answer for specific regulated and latency-sensitive deployment environments.
Which buyer segments will drive hardware-PQC procurement?
Three. Latency-sensitive infrastructure (high-frequency trading, real-time control systems, autonomous vehicles) where software-PQC's latency tax is unacceptable. The regulated edge (branch banks, retail sites, hospitals, oil platforms, water treatment) where dedicated silicon is easier to certify and audit at FIPS 140-3 Level 3. Classified networks (government and defence) where supply-chain provenance on the crypto stack is itself a procurement requirement. If those three segments drive even a fifth of total PQC migration spend, hardware-PQC becomes a serious budget line.
What does Sitehop's UK cap table signal beyond the company itself?
Northern Gritstone, Amadeus, Mercia, and NPIF make Sitehop's cap table almost entirely British. That is positioning. SAFEcore Edge is being marketed explicitly as a UK-engineered, FIPS-certified, sovereign cryptography device for European and allied buyers. Adjacent moves in the same window (Airbus pursuing French cybersecurity firm Quarkslab) suggest sovereign-cyber is becoming a recognized procurement axis. Allied governments and critical-infrastructure operators outside the US are increasingly unwilling to accept US-only crypto in sensitive deployments — and PQC migration is the moment when that preference becomes a contractual requirement.
  • Cybersecurity market map — Where quantum security and the dedicated encryptor category sit within the broader cybersecurity vendor landscape.
  • Public cybersecurity companies — The platforms (PANW, Fortinet, Cisco) that have not yet shipped credible PQC silicon at the regulated-edge form factor.
  • Palo Alto Networks stock profile — PANW has prioritized agent-runtime acquisitions over PQC silicon. The trade-off is starting to matter.
  • Fortinet stock profile — Fortinet has gestured at PQC; whether silicon ships in the next twelve months is the open question.
  • Cisco stock profile — Cisco has signaled PQC commitment but has not yet shipped competitive edge silicon.
  • Cybersecurity M&A 2026 pillar — Where sovereign-crypto pure-plays sit on the map the platforms are drawing — and where the next acquisition targets are likely to come from.
  • Federal cyber backstop privatizes — The companion piece on US federal cyber capacity strain — the demand-side reason allied buyers are reaching for sovereign crypto.
  • Newsroom — Live cybersecurity market feed: product launches, M&A, funding rounds.

Sources

  1. Sitehop's SAFEcore Edge enables ultra-low-latency, hardware-enforced post-quantum encryption — Help Net Security
  2. Sitehop launches SAFEcore Edge for remote network security — SecurityBrief UK
  3. World's smallest encryption device takes cybersecurity beyond the quantum realm — Prolific North
  4. Sheffield firm Sitehop launches pocket-sized cybersecurity device — Yorkshire Post
  5. Sitehop secures GBP 7.5m round (funding context) — UKTN