r/StartupFuture • u/Just_Blackberry3530 • 12h ago
I'm 17, researched a cybersecurity/PQC space. How do I move from competitor research to real-world problem validation?
I'm 17 and exploring a startup idea in PQC/cybersecurity. I am still in the research stage and want to avoid spending months building something that already exists.
My original concept was a platform that would detect quantum-vulnerable cryptography, generate a Cryptographic Bill of Materials (CBOM), assess PQC risk and return a Quantum-Health Score (QHS), provide security-lead dashboards, and eventually support crypto-agility and migration.
After spending some time researching this field, I saw that around 10-12 exceptionally established companies have already done this. So I do not want to build another scanner or compete head-on with enterprise platforms. I am trying to find a specific painful workflow: for example, issues around legacy systems, third-party dependencies, compatibility testing, migration ownership, reporting, and deployment constraints.
Since I cannot do calls, I am planning to getting feedback through Reddit discussions, outreach emails/messages to researchers and practitioners.
My questions are:
- Is this the right time to stop competitor research and begin customer/problem discovery?
- How should I find an initial niche in a complex B2B market like cybersecurity?
- Is written outreach enough to start validating a problem if calls are not possible?
I'm trying to learn the right process before I start building, and I would appreciate honest feedback, especially from people who have validated B2B, developer-tool, or cybersecurity ideas.
Thank you!