Post-Quantum Cryptography
Readiness Checklist
12-step framework for quantum-safe migration aligned with NIST FIPS 203/204/205, NSA CNSA 2.0, and applicable sector policy and compliance context.
~13 min readExecutive Summary
Forecasts for quantum computers capable of breaking RSA, ECC, and Diffie-Hellman vary materially and do not establish a break date. The Harvest Now, Decrypt Later (HNDL) threat model makes data lifetime relevant before hardware certainty: encrypted data can be collected now for future decryption attempts.
NIST finalized the first three post-quantum cryptography standards in August 2024:FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). Those standards create implementable options; adoption timing remains system- and policy-specific.
This checklist organizes guidance from NIST, NSA, CISA, and sector-specific regulators into a framework with source-backed control dates, algorithm decision criteria, and measurable maturity.
The Mosca Inequality
Why data lifetime can move action ahead of hardware certainty:
Y = time to migrate
Z = a chosen quantum-risk scenario horizon, not a known break date
Policy, Standards & Guidance Timeline
Final standards, binding federal dates, sector guidance, and draft deprecation proposals are different evidence classes. Each entry below names its scope and links to the primary source.
| Date | Authority | Status | Scoped requirement or guidance | Primary source |
|---|---|---|---|---|
| August 13, 2024 | NIST | Final standards | FIPS 203, 204, and 205 became the first finalized NIST PQC standards. | NIST release (opens in new tab) |
| Fall 2024 | OCC | Supervisory guidance | Banks are encouraged to inventory where encryption is used and assess third-party PQC transition plans. | OCC risk perspective (opens in new tab) |
| October 22, 2026 | OMB M-26-15 | Agency requirement | Federal agency PQC Migration Plans are due within 120 days of the June 24, 2026 memo; this date is derived from that window. | OMB M-26-15 (opens in new tab) |
| December 31, 2027 | EO 14412 | Executive order | NIST is directed to complete a PQC migration pilot on an appropriate subset of its systems. | White House EO 14412 (opens in new tab) |
| December 31, 2030 | EO 14412 | Executive order | Non-NSS federal high-value assets and high-impact systems are directed to transition key establishment to PQC. | White House EO 14412 (opens in new tab) |
| December 31, 2031 | EO 14412 | Executive order | Non-NSS federal high-value assets and high-impact systems are directed to transition digital signatures to PQC. | White House EO 14412 (opens in new tab) |
| 2030–2031 | NSA CNSA 2.0 | NSS requirement | For applicable NSS, unsupported equipment and services phase out by the end of 2030 and CNSA 2.0 use is required by the end of 2031 unless otherwise noted. | NSA CNSA 2.0 FAQ (opens in new tab) |
| After 2030 / 2035 | NIST IR 8547 | Initial public draft | The initial public draft proposes deprecation of specified quantum-vulnerable schemes after 2030 and broader disallowance after 2035. | NIST IR 8547 IPD (opens in new tab) |
Applicability varies by agency, system classification, sector, contract, and final rulemaking. Draft guidance is labeled; this timeline is not legal or compliance advice.
Financial Services
OCC encryption-inventory guidance, third-party transition planning, institution-specific obligations
Healthcare
HIPAA Security Rule risk analysis, applicable record-retention duties, OCR enforcement
Government/Defense
OMB M-26-15, EO 14412, and CNSA 2.0 for applicable national security systems
Critical Infrastructure
Sector-specific guidance, long-lived ICS/OT upgrade cycles, and contract-specific obligations
Algorithm Selection Guide
NIST finalized the first three PQC standards in 2024. Additional algorithms and implementation guidance remain in development; production selection must follow current standards, protocol support, and use-case constraints.
ML-KEM (Kyber)
FIPS 203Default for TLS, VPN, encrypted communications. Smaller ciphertext than alternatives. Best general-purpose choice.
ML-DSA (Dilithium)
FIPS 204Default for code signing, certificates, authentication. Fast signing/verification. Larger keys than classical.
SLH-DSA (SPHINCS+)
FIPS 205Conservative choice when lattice assumptions concern you. Hash-based security well understood. Large signatures but proven foundation.
FN-DSA (Falcon)
FIPS 206 in developmentSmallest signatures of lattice schemes. Requires careful implementation to avoid side-channel attacks. Wait for NIST finalization.
Implementation Note: Most organizations should start with ML-KEM for key exchange and ML-DSA for signatures. SLH-DSA serves as a fallback if future cryptanalysis weakens lattice-based schemes. Hybrid deployments (classical + PQC in parallel) provide defense-in-depth during transition.
Interactive PQC Readiness Checklist
Track your organization's progress toward quantum cryptography readiness.
Step 1: Establish Governance and Executive Sponsorship
Form a cross-functional quantum readiness team with C-suite sponsorship.
Step 2: Conduct Cryptographic Discovery and Inventory
Deploy approved discovery methods to identify in-scope cryptographic implementations.
Step 3: Assess HNDL Exposure and Data Classification
Calculate your Mosca Inequality for each data category.
Step 4: Develop Migration Roadmap
Create a phased migration plan working backward from regulatory deadlines.
Step 5: Evaluate and Select PQC Algorithms
Assess NIST-standardized algorithms against your use cases.
Step 6: Design Crypto-Agility Architecture
Architect systems for algorithm flexibility.
Step 7: Engage Vendors and Supply Chain
Survey all vendors on their PQC roadmaps.
Step 8: Execute Pilot Deployments
Deploy PQC in non-production environments first.
Step 9: Migrate Data-in-Transit
Upgrade TLS implementations to support ML-KEM key exchange.
Step 10: Migrate Data-at-Rest and Re-encrypt Archives
Address the HNDL backlog and re-encrypt high-value archived data.
Step 11: Validate and Audit Completion
Conduct post-migration audit to verify all identified vulnerabilities addressed.
Step 12: Establish Continuous Monitoring and Evolution
Institute continuous monitoring of NIST announcements and cryptanalysis research.
Enterprise-Grade Standards
Aligned with industry-leading regulatory and technical standards.
NIST Aligned
NSA CNSA 2.0
PQC Migration Ready
Procurement Ready
The 12-Step PQC Readiness Checklist
A phased approach from foundation through sustainment, with clear deliverables and maturity indicators.
Phase 1: Foundation
Months 1-3Establish Governance and Executive Sponsorship
Form a cross-functional quantum readiness team with C-suite sponsorship. Assign board-level or CISO ownership. Integrate quantum risk into existing enterprise risk management frameworks.
Quantum Risk Governance Charter with named accountable executive
Executive receives quarterly quantum risk briefings
Conduct Cryptographic Discovery and Inventory
Deploy approved discovery methods to identify in-scope cryptographic implementations across applications, infrastructure, and third-party dependencies. Build a Cryptographic Bill of Materials (CBOM).
Complete CBOM with quantum vulnerability classification
95%+ coverage of enterprise systems in inventory
Assess HNDL Exposure and Data Classification
Calculate your Mosca Inequality for each data category. Identify data with secrecy requirements exceeding the quantum threat timeline. Prioritize M&A records, litigation holds, healthcare PHI, financial archives.
HNDL exposure matrix with risk-ranked data categories
Board-approved prioritization of crown jewel data
Phase 2: Planning
Months 4-9Develop Migration Roadmap with Regulatory Alignment
Create a phased migration plan against applicable control dates. Map CNSA 2.0 dates for covered government work, distinguish supervisory guidance from binding requirements, and align with institution-specific obligations.
Board-approved PQC migration roadmap with budget
Roadmap milestones incorporated into IT strategic plan
Evaluate and Select PQC Algorithms
Assess NIST-standardized algorithms against your use cases. Test ML-KEM for key exchange, ML-DSA for signatures. Evaluate performance impact on latency-sensitive applications.
Algorithm selection matrix with performance benchmarks
Lab testing completed on candidate algorithms
Design Crypto-Agility Architecture
Architect systems for algorithm flexibility. Implement abstraction layers that allow cryptographic modules to be swapped without application changes. Design for negotiable cipher suites.
Crypto-agility architecture specification
Reference implementation in development environment
Engage Vendors and Supply Chain
Survey all vendors on their PQC roadmaps. Obtain written timelines for when products will support NIST standards. Update procurement requirements to request PQC readiness evidence.
Vendor PQC readiness assessment with risk ratings
PQC requirements in new contract language
Phase 3: Implementation
Months 10-36Execute Pilot Deployments
Deploy PQC in non-production environments first. Test hybrid TLS configurations. Validate certificate chain handling with PQC signatures. Measure performance overhead.
Pilot deployment report with performance metrics
Successful hybrid TLS handshakes in test environment
Migrate Data-in-Transit
Upgrade TLS implementations to support ML-KEM key exchange. Deploy hybrid cipher suites that combine classical and post-quantum algorithms. Prioritize external-facing endpoints.
Production TLS upgrade completion report
100% of external endpoints support PQC cipher suites
Migrate Data-at-Rest and Re-encrypt Archives
Address the HNDL backlog. Re-encrypt high-value archived data with post-quantum cryptography (PQC) algorithms. Update key management systems. Rotate certificates to PQC-signed versions.
Data-at-rest migration completion with exceptions documented
Crown jewel data protected with PQC algorithms
Phase 4: Sustainment
OngoingValidate and Audit Completion
Conduct post-migration audit to verify all identified vulnerabilities addressed. Run governed validation against PQC implementations. Validate compliance with applicable regulations.
Independent audit report confirming PQC implementation
Clean audit findings on cryptographic controls
Establish Continuous Monitoring and Evolution
Institute continuous monitoring of NIST announcements, cryptanalysis research, and quantum computing progress. Keep CBOM current. Drill crypto-agility procedures annually.
Crypto monitoring program with defined triggers for action
Annual crypto-agility drill completed successfully
PQC Readiness Maturity Model
Score each dimension 1-5 to assess your current state and track progress.
| Dimension | 1 - Initial | 2 - Aware | 3 - Planned | 4 - Active | 5 - Optimized |
|---|---|---|---|---|---|
| Governance | No ownership | CISO aware | Charter approved | Board reporting | Integrated ERM |
| Inventory | None | Partial manual | Automated scan | Full CBOM | Continuous update |
| Risk Assessment | Not started | Ad hoc review | HNDL mapped | Prioritized plan | Quantified risk |
| Crypto-Agility | Hardcoded | Some flexibility | Architecture spec | Implemented | Tested annually |
| Vendor Mgmt | Not addressed | Some inquiries | All surveyed | Contract terms | Ongoing validation |
| Implementation | No PQC | Lab testing | Pilot deployed | Production live | Full migration |
Ready to Assess Your Quantum Risk?
QScout delivers first findings in 72 hours, complete assessment in 7 days with board-ready reporting. QStrike provides comprehensive 4-month testing with proof-of-concept demonstrations.