Post-Quantum Readiness
14 articles on post-quantum readiness.
- What a Post-Quantum Readiness Score Tells You (and How to Improve It) — Your readiness scan returns one number. Here's exactly what drives a post-quantum readiness score up or down — deprecated TLS, SHA-1, certificate hygiene, RSA/ECC exposure — what each finding means, and the concrete steps to improve it over time.
- Are You Ready for Post-Quantum Cryptography? The 2026 Readiness Gap — and the 3-Minute First Step — About 69% of enterprises recognize the quantum risk but only ~5% have acted. The reason most stall is they don't know where cryptography lives — and the first step, a cryptographic inventory, takes about 3 minutes.
- How Government Contractors Can Prepare for PQC Compliance — NSM-10, OMB M-23-02, CNSA 2.0, and CMMC 2.0 are driving PQC mandates for government contractors. Here's what defense and civilian agency contractors need to do now.
- Quantum Risk Assessment: How to Evaluate Your Organization's Cryptographic Exposure — Quantum risk assessment goes beyond algorithm inventory. It requires understanding data sensitivity, confidentiality lifetimes, vendor dependencies, and harvest-now-decrypt-later threat models.
- What Is a CBOM? Cryptographic Bill of Materials Explained — A Cryptographic Bill of Materials (CBOM) is the standard inventory format for cryptographic assets. Learn how CBOM extends SBOM, why CycloneDX 1.6 adopted it, and how to generate one.
- TLS Certificate Inventory: How to Find Every Certificate in Your Organization — Most organizations have hundreds more TLS certificates than they think. This guide covers external discovery, internal scanning, cloud KMS, and vendor-managed certificates — and how to build a complete inventory.
- NIST Post-Quantum Cryptography Standards Explained: FIPS 203, 204, and 205 — NIST finalized its post-quantum cryptography standards in 2024. Here's what FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) actually mean for enterprise security teams — in plain language.
- Vendor PQC Questionnaire: Questions to Ask Your Software, Cloud, and Infrastructure Suppliers — A structured questionnaire to assess whether your vendors are preparing for post-quantum cryptography. Covers crypto agility, NIST PQC support, CBOM availability, and migration timelines.
- PQC Readiness Checklist: A Practical Guide for Security and IT Teams — A practical, step-by-step checklist for inventorying cryptographic assets, assessing quantum risk, engaging vendors, and planning your organization's PQC migration.
- How Healthcare and Financial Organizations Can Start a PQC Readiness Program — Regulated industries face unique PQC readiness challenges — compliance obligations, long-lived sensitive data, and complex vendor dependencies. Here's a practical framework for healthcare and financial organizations to start their crypto inventory and migration planning.
- Why TLS Certificates, RSA, and ECC Create Hidden Quantum Risk — RSA and ECC underpin most TLS certificates in production today. When cryptographically relevant quantum computers arrive, every certificate that relies on these algorithms becomes a risk vector. Here's what security teams need to know.
- Crypto Agility Explained: How to Prepare Your Systems for Quantum-Safe Migration — Crypto agility is the ability to swap cryptographic algorithms without rewriting applications. For enterprises preparing for the PQC migration, it is the single most important architectural capability to build now.
- Post-Quantum Cryptography Readiness: A Practical Roadmap for Security Teams — PQC readiness isn't just about algorithms. It's about inventory, prioritization, vendor engagement, compliance alignment, and executive communication. Here's a practical 30/60/90-day roadmap.
- What Is a Cryptographic Inventory and Why Every Enterprise Needs One Before PQC Migration — Most organizations can't answer the question 'where does cryptography live in our infrastructure?' This is why a cryptographic inventory is the mandatory first step before any PQC migration.
All CipherReady blog posts