Post-Quantum Cryptography
The CISO's Guide to Post-Quantum Cryptography Readiness
Complete CISO guide to post-quantum cryptography readiness: crypto inventory, risk assessment, vendor management, board communication, budget planning, and regulatory alignment.
The CISO's Guide to Post-Quantum Cryptography Readiness
This is the guide I wish every CISO had when their board first asks about quantum readiness. It covers what PQC readiness actually requires, how to build the business case, what your board needs to know, and how to start your program this quarter with minimal disruption. For related context, see NIST PQC standards guidance.
What PQC Readiness Actually Requires
PQC readiness is not a tool you buy. It is a program you run. The core deliverables are:
- A cryptographic inventory: You know where RSA, ECC, TLS certificates, and cryptographic keys are deployed across public-facing and (prioritized) internal infrastructure.
- A risk classification: Each asset is classified by quantum vulnerability, data sensitivity, and confidentiality lifetime.
- A vendor risk register: Every third party that manages cryptography on your behalf has been assessed.
- A migration roadmap: Prioritized, phased, with resource estimates, aligned to regulatory timelines.
- A board-ready report: One page summarizing posture, risk, timeline, and resource needs. For related context, see healthcare PQC readiness planning.
You do not need to complete the migration to be "PQC ready." You need to have the program in place with measurable progress.
The Business Case: How to Get Budget
Frame PQC readiness as three things your board already cares about:
Regulatory compliance: "NSM-10 mandates federal agencies. DORA requires operational resilience including crypto risk. Our cyber insurer asked about cryptographic posture in our last renewal. We need to be able to answer these questions with data."
Risk management: "Harvest-now-decrypt-later is a recognized threat model. Our customer data has a regulatory confidentiality requirement of 7-10 years under [regulation]. That timeline overlaps with expected quantum capability. We need to know where quantum-vulnerable crypto protects long-lived data."
Competitive positioning: "Our enterprise customers are beginning to ask about PQC readiness in their vendor assessments. Having a program in place is becoming a competitive requirement for government, financial services, and healthcare contracts."
The 90-Day CISO PQC Readiness Plan
Days 1-30: Discovery and Baseline
- Run external cryptographic posture assessment on every domain (CipherReady automates this)
- Produce certificate inventory with algorithm, key size, and quantum vulnerability classification
- Begin vendor PQC questionnaire campaign for critical vendors
- Deliver initial readiness score and findings summary
Deliverable: Certificate inventory spreadsheet + one-page readiness summary.
Days 31-60: Deepen and Classify
- Complete risk classification: assign Critical/High/Medium/Low tiers based on data sensitivity
- Audit cloud KMS keys (AWS, Azure, GCP)
- Compile vendor questionnaire responses
- Begin internal discovery planning for regulated system scope
Deliverable: Risk-classified crypto inventory + vendor risk register.
Days 61-90: Roadmap and Report
- Build prioritized migration roadmap with quarterly milestones
- Map findings to regulatory frameworks (NSM-10, PCI DSS, HIPAA, DORA as applicable)
- Produce board-ready executive report
- Establish quarterly review cadence
- Deliver budget recommendation for Year 1 program
Deliverable: Board-ready executive report + migration roadmap + budget request.
What to Tell Your Board (The 5-Slide Deck)
Slide 1: The Problem "We use RSA and ECC to protect our data. NIST published replacement standards in 2024. Quantum computers capable of breaking RSA are expected within 10-15 years. Data encrypted today with a 10-year confidentiality requirement is already at risk."
Slide 2: The Regulatory Landscape Show the specific mandates that apply: NSM-10, CNSA 2.0, DORA, PCI DSS 4.0, HIPAA, CMMC. Include dates.
Slide 3: Our Current Posture "Our external assessment of [X] domains found [Y] TLS certificates. [Z]% use RSA-2048 or ECC P-256 — both quantum-vulnerable. Our initial readiness score is [score]. We have begun vendor PQC assessment. We have not yet inventoried internal cryptographic dependencies."
Slide 4: The 12-Month Program Month 1-3: Complete discovery and risk classification. Month 4-6: Internal discovery for regulated systems. Month 7-9: Migration roadmap with resource plan. Month 10-12: Begin migration of highest-priority assets.
Slide 5: The Ask "I need approval to [specific request]. I will return in 90 days with a complete inventory, risk classification, and migration roadmap with full budget estimate."
How CipherReady Fits Into the CISO Toolkit
CipherReady automates the external discovery layer — the fastest, safest starting point for PQC readiness. In under an hour:
- TLS certificate inventory across all domains
- Algorithm and key size analysis
- Quantum vulnerability classification
- Readiness score with trend tracking
- Executive-ready PDF report For related context, see PQC compliance planning.
It requires no agents, no credentials, no infrastructure changes. It gives you the data you need for slides 3 and 5 of your board deck, and the foundation for your 90-day PQC readiness plan.
FAQ
Q: How urgent is this really? A: The migration itself will take years. The inventory — which must come first — takes months. Starting now gives you the runway to do it methodically. Waiting until a regulatory mandate forces your hand creates a compressed, expensive timeline.
Q: What if my organization has no regulatory requirement? A: Commercial organizations face the same cryptographic reality as regulated ones — RSA and ECC will be broken. And cyber insurers, enterprise customers, and procurement processes are starting to ask about PQC readiness regardless of regulatory status.
Q: Can I start without dedicated budget? A: Yes. The external discovery phase (CipherReady's free tier: 3 scans/month) requires no procurement, no infrastructure changes, and no dedicated headcount. Start with discovery. Use the results to build the business case for the next phase.
Start Free Readiness Scan →
View Pricing Plans →