← Knowledge areas
Knowledge area 08 · Prepare

Quantum
Readiness

Quantum readiness is not a prediction exercise. It is preparation for an orderly, risk-based transition away from quantum-vulnerable public-key cryptography.

The migration challenge connects every part of cryptographic resilience: discovery, dependency mapping, governance, crypto-agility, PKI, key management and third-party readiness.

Last reviewed: August 2026

Timeline uncertainty does not remove the need to prepare.

Cryptographically relevant quantum computers do not exist today at the scale required to break widely deployed public-key cryptography, and the future timeline remains uncertain. Risk management should not build its programme around guessing a date.

The actionable question is whether important data and services depend on public-key cryptography that will require replacement — and whether the organisation has enough lead time to discover, prioritise, test and migrate those dependencies.

Risk lens

Quantum risk is partly a future threat problem. Quantum readiness is a present-day dependency, governance and change-management problem.

Not all cryptography is affected in the same way.

PUBLIC-KEY

RSA

Quantum-vulnerable public-key mechanism requiring transition planning.

PUBLIC-KEY

Elliptic-curve cryptography

ECC-based signatures and key establishment also require transition planning.

SYMMETRIC

Symmetric cryptography

Quantum impact differs from RSA and ECC; current guidance and appropriate key strengths remain relevant.

HASHING

Hash functions

Hashing is affected differently; organisations should follow applicable standards rather than treating all cryptography as equally vulnerable.

Move from awareness to controlled transition.

01DiscoverIdentify quantum-vulnerable public-key cryptography.
02ContextualiseConnect findings to criticality, data lifetime, owners and dependencies.
03PrioritiseCombine exposure, consequence, migration complexity and lead time.
04GovernSet ownership, standards, risk decisions and reporting.
05Plan & migrateCoordinate suppliers, testing, interoperability and technology refresh.
06Sustain agilityUse this transition to make future change easier.

PQC is no longer only a research topic.

NIST published its first three final PQC standards in August 2024: FIPS 203 for ML-KEM key establishment, and FIPS 204 and FIPS 205 for ML-DSA and SLH-DSA digital signatures. Migration governance should distinguish final standards from algorithms, profiles and integrations still evolving.

FIPS 203

ML-KEM

Module-lattice-based key-encapsulation mechanism.

FIPS 204

ML-DSA

Module-lattice-based digital signature standard.

FIPS 205

SLH-DSA

Stateless hash-based digital signature standard.

ONGOING

Ecosystem integration

Products, protocols and additional standards continue to evolve; readiness requires controlled adoption, not algorithm chasing.

Readiness is evidenced through ownership, visibility and a risk-based roadmap.

Programme ownershipClear accountability across security, architecture, technology, risk, procurement and business ownership.
Cryptographic inventoryQuantum-vulnerable use is linked to purpose, location, owner and dependencies.
Business & data contextCriticality, sensitivity, protection lifetime and exposure inform priority.
Migration roadmapPlans align to standards, refresh cycles, supplier capability and testing windows.
Supplier engagementCritical vendors provide evidence on support, timelines and constraints.
Progress & residual riskBlockers, exceptions and decisions are visible to leadership.

Prioritisation principle

Prioritise by exposure, protection lifetime, business consequence and migration difficulty — not fear or a speculative quantum date.

Start with decisions that are useful even if the timeline changes.

Identify vulnerable public-key useFocus first on critical services and long-lived sensitive data.
Map migration blockersFind embedded, hardware-bound, protocol and supplier-controlled dependencies.
Engage strategic suppliersRequest credible PQC support and interoperability roadmaps.
Align technology refreshAvoid buying or extending long-lived dependencies that create unnecessary migration debt.
Build crypto-agilityUse PQC preparation to make the next cryptographic transition less disruptive.

Quantum readiness is an outcome of good cryptography governance.

An organisation that can discover cryptography, understand dependencies, assign ownership, prioritise risk and execute controlled change already has much of the capability required for PQC migration.

The goal is not simply to become “post-quantum compliant.” It is to become resilient enough to manage this transition — and the transitions that follow it.

Further reading

Quantum-computing timelines remain uncertain. This page focuses on risk-based preparedness and current public standards.

Previous knowledge area← Third-Party DependenciesKnowledge baseReturn to all topics →