Measure Your Post-Quantum Readiness.
Verify your organisation's mathematical risk, audit infrastructure constraints, and establish an evidence-driven baseline of post-quantum readiness.
The PQC Readiness Framework
DISCOVER
Scan physical, virtual, and cloud assets to discover cryptography.
INVENTORY
Catalog active certificates, keys, and algorithms.
ASSESS
Determine mathematical exposure to quantum-scale computing decryption.
PRIORITISE
Map assets against operational criticality and data lifespan.
PLAN
Draft target hybrid and post-quantum cryptographic configurations.
GOVERN
Enforce ongoing standards, policies, and crypto-agility frameworks.
Key Assessment Dimensions
Cryptographic Inventory
Checking if the organisation maintains an accurate, automated list of all cryptographic assets and codebases.
Algorithm Exposure
Identifying vulnerabilities in active algorithms (e.g. RSA, ECC) and assessing the mathematical security levels.
Application Dependencies
Analyzing third-party software, internal APIs, and libraries to verify support for quantum-resistant algorithms.
Certificate / PKI Dependencies
Inspecting trust stores, certificate authorities, and enrollment speeds to check compatibility with larger PQC keys.
Hardware & Firmware Constraints
Analyzing embedded hardware (HSMs, operational devices, SCADA) to determine memory or processor limits.
Data Longevity
Evaluating the commercial sensitivity of historical data and determining exposure to 'store-now, decrypt-later' actions.
Vendor Dependencies
Auditing third-party technology providers and cloud software for formal post-quantum support timelines.
Crypto-Agility
Measuring how easily an organisation can change algorithms, certificates, and protocols without major code rebuilds.
TO: Chief Information Security Officer (CISO) & Risk Committee
FROM: Independent Cryptography Assurance Team
SUBJECT: UK Post-Quantum Preparedness & CBOM Longevity Analysis
“A review of cryptographic inventory records indicates that approximately 72% of current internal APIs depend on TLS cipher configurations vulnerable to Store-Now, Decrypt-Later (SNDL) threat profiling. Transition waves should target core PKI authority migration and customer-facing authentication modules by H2.”
Measure Your Post-Quantum Readiness
Understand where your digital trust is exposed and formulate a board-aligned transition framework.