Post-Quantum Readiness
PQC Readiness Checklist: A Practical Guide for Security and IT Teams
Download this practical PQC readiness checklist for security and IT teams. Covers crypto asset discovery, TLS certificate inventory, vendor assessment, and migration planning.
PQC Readiness Checklist: A Practical Guide for Security and IT Teams
Post-quantum cryptography readiness can feel overwhelming. NIST standards, regulatory timelines, vendor dependencies, algorithm migration — where do you actually start?
This checklist breaks PQC readiness into concrete, sequential steps that security and IT teams can execute without a dedicated PQC program. Each section includes the action, the owner, and the expected output.
Phase 1: Cryptographic Discovery
- [ ] Identify all public-facing domains — List every domain your organization owns or operates. Include marketing sites, customer portals, API endpoints, and subdomains.
- [ ] Run external TLS certificate inventory — For each domain, record every TLS certificate: issuer, algorithm (RSA, ECC), key size, signature algorithm, expiry date, and SAN entries.
- [ ] Map DNS records — Document A, AAAA, MX, CNAME, and TXT records for each domain. Note any unexpected or forgotten entries.
- [ ] Review HTTP security headers — Check for HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy presence.
- [ ] Classify by quantum risk — Assign Critical/High/Medium/Low risk tiers based on data sensitivity, algorithm type, and key size.
Expected output: A spreadsheet or dashboard listing every public-facing TLS endpoint, its cryptographic configuration, and its risk classification.
Phase 2: Internal Crypto Inventory
- [ ] Inventory application-level cryptography — For critical applications, document which crypto libraries are used, which algorithms are called, and where keys are generated or stored.
- [ ] Map internal PKI — Document all internal certificate authorities, certificate templates, issuance policies, and renewal processes.
- [ ] Inventory cloud KMS keys — List all keys in AWS KMS, Azure Key Vault, GCP Cloud KMS, and any managed HSM services. Record algorithm, key purpose, and rotation policy.
- [ ] Check database encryption — Verify encryption at rest configuration for production databases. Record which keys protect which data stores.
- [ ] Document SSH host keys — For critical servers, record SSH key algorithms and key sizes in use.
Expected output: An internal crypto register covering applications, infrastructure, cloud, and data stores.
Phase 3: Vendor Crypto Assessment
- [ ] List all vendors with cryptographic dependencies — SaaS platforms, API providers, payment processors, cloud services, managed security providers.
- [ ] Send PQC readiness questionnaire — Ask each vendor about their PQC roadmap, NIST algorithm support, hybrid certificate plans, CBOM availability, and migration timelines.
- [ ] Classify vendor risk — Critical vendors (direct access to regulated data, no PQC roadmap) vs Low (no access to sensitive data, PQC roadmap published).
- [ ] Document vendor gaps — For vendors without PQC roadmaps, note the gap and begin architectural mitigation planning.
Expected output: A vendor crypto risk register with questionnaire responses and risk classifications.
Phase 4: Migration Planning
- [ ] Build dependency map — For each cryptographic asset, identify shared libraries, shared certificates, and vendor dependencies.
- [ ] Prioritize migration order — Critical assets first, grouped by dependency to minimize rework.
- [ ] Estimate effort and resources — For each migration group, estimate timeline, required skills, and tooling needs.
- [ ] Identify quick wins — Certificate reissuance with larger key sizes, algorithm policy updates, decommissioning of expired/unused certificates.
- [ ] Set up scheduled monitoring — Monthly scans for high-priority domains, quarterly for others. Track readiness score trends.
Expected output: A prioritized 90-day migration roadmap with resource estimates and monitoring plan.
Phase 5: Executive Reporting
- [ ] Create executive summary — One-page document covering current readiness score, top 5 risks, and recommended next 90-day actions.
- [ ] Build risk heat map — Visual prioritization of cryptographic assets by risk tier and data sensitivity.
- [ ] Align with regulatory frameworks — Map findings to NSM-10, CNSA 2.0, DORA, PCI DSS, HIPAA, or other applicable regulations.
- [ ] Schedule quarterly review — Establish a recurring review cadence to update the crypto inventory, assess vendor progress, and track migration milestones.
Expected output: A board-ready executive readiness report.
Quick-Start: Run Your First Assessment
The fastest way to complete Phase 1 is an external cryptographic posture assessment. CipherReady automates TLS certificate inventory, DNS review, HTTP header analysis, and readiness scoring for any domain you own — in under 3 minutes, with no agents and no credentials.
FAQ
Q: How long does the full checklist take? A: Phase 1 (external discovery) can be completed in a day. Phases 2-5 typically span 30-90 days depending on organizational complexity.
Q: Can I skip directly to migration without inventory? A: No. You cannot migrate what you cannot see. Every PQC standard and regulatory framework assumes a cryptographic inventory exists as the starting point.
Q: What if I manage hundreds of domains? A: Start with the domains handling the most sensitive data. External scanning tools like CipherReady can process domains rapidly. Prioritize by data sensitivity, not domain count.
Start Free Readiness Scan →
View Resources →