The machines could create “secret vaults” for storing sensitive information and be called upon as needed. Your quantum computer may well expose your most hidden secrets before you are even aware of their existence! Part One: Are we ready for post-quantum cryptography? This is a question many an IT leader gets asked before they have any way of actually answering it! The truthful answer for many organizations is that nobody really knows yet, not because the threat isn’t understood, but rather because, in order to determine readiness, it’s unclear who needs to care most about this at risk of running afoul of measures like NIST’s, and because there is simply no visibility into how cryptography actually exists throughout entire systems. A true readiness assessment has to start by building that visibility, not by guessing at it.
PQC readiness for enterprise IT teams provides a structured framework for thinking through this assessment process, framing the shortage less as an authoritarian yes/no response and more as an organizational maturity model that companies can assess and even improve.
Start With Discovery, Not Assumptions
Most organizations dramatically underestimate how many places we actually find cryptography in our environment. It appears in plain sight, such as TLS certificates and VPN configurations, but also in sparsely visible places: firmware, embedded devices, legacy apps no one has worked on for decades, and third-party software where we never documented what crypto to use under the covers. When you have a readiness assessment that goes directly to planning without understanding this full footprint, it tends to miss the systems most likely to create problems for you later.
This guidance, structured around the challenge of discovery, is a practice guide that will help organizations prepare for quantum-allowed cryptographic discovery as a distinct phase of readiness work, applying their structured approach to identify instances of quantum-vulnerable cryptography in an environment prior to initiating migration planning. A project should be begun when people treat discovery as a real thing to do, rather than just something you automatically get done up front, which leads to far more being uncovered than most teams expect.
Not Just Cataloging Assets, But Scoring Risk
Once you have an inventory, not every finding demands collective action. Risk must be assessed based on a readiness evaluation that considers the sensitivity of protected data, the retention period for which such data needs to remain private and how exposed the system is to threat actors. Even though both might currently rely on the same vulnerable encryption method, data that needs to be protected for a few months has a very different risk profile than data that needs to remain private for decades.
However, it is at this point in the assessment where things typically go awry. Thought of every system as urgent means either paralysis, where the full scope feels unmanageable or misapplied effort to all the low-hanging fruit that you are picking that should just be going into a small handful of systems actually worth paying attention too. A good assessment will make a prioritized list, not a flat inventory.
Assessing Readiness of Vendor and Supply Chain
Enterprise agnosticism isn’t the whole story though because many enterprises rely on third party software, hardware and cloud services where they aren’t the one making the cryptographic choices. A readiness assessment should also reach out to vendors for specific details: what their timeline is for supporting post-quantum algorithms and how they will inform customers about the switch over, and provide support as that switch is made.
The vendor evaluation step matters because an organization may be internally ready to migrate, but a mission-critical vendor might still be blocked because it has not yet embedded post-quantum support into its product. As part of procurement and contract renewals, factoring in vendor readiness rather than treating it as a separate afterthought closes the gap that tends to pop up at precisely the worst time.
Building Governance Around the Assessment
A once-off readiness assessment and a paper that is then archived provides minimal incremental benefit. Because cryptographic standards, vendor timelines, and an organization’s own system inventory all shift over time, readiness should have: a governance structure with someone held accountable to keep the assessment fresh,a clear review frequency, and feed-forward into migration priorities for new findings.
But regional and international actors working on this problem repeatedly point to the coordination puzzle that it creates. The PQC resources of the European Cybersecurity Agency are a continuing multiyear endeavor including experts, standards bodies, and member states collaborating in all particular in light of the fact that a readiness work driven by a solitary group or snapshot of time will without a doubt age rapidly as the fundamental innovation and gauges scene keeps on transforming.
Testing Before Committing
Assessing readiness is not simply a paperwork exercise. A purely theoretical review would miss compatibility issues and performance impacts that arise when actually testing these new post-quantum algorithms in a controlled, non-production environment. As an example, post-quantum algorithms have larger message sizes which can impact protocols that were never intended to handle such large cryptographic material: this is the kinda thing you can only realize through actual testing and not just documentation review.
Organizations that embed testing into their readiness process, as opposed to treating migration as something to solve when the rollout is live, are able to identify these compatibility problems while they can be addressed with very little consequences. This step also develops some in-house confidence and expertise that pays very tangible dividends once the real migration work gets underway.
Transforming Assessment into an Ongoing Routine
Most organizations that manage this transition best approach readiness assessment not as a single effort with a start and end date but rather an ongoing practice. Systems get deployed, vendor roadmaps change, standards continue to evolve and mean your assessment yesterday turns stale faster than most teams expect. What keeps an organization truly ready as the rest of the quantum computing ecosystem evolves is incorporating these discovery, scoring and governance processes into a repeatable cadence, not one-off initiatives.
Frequently Asked Questions
How long does a standard PQC readiness assessment take for an average enterprise?
This depends a lot on how complex your systems are, but just the discovery phase often takes months for organizations with massive or poorly documented infrastructure. Approaching the entire assessment as an iterative practice rather than a finite project generates more consistent outcomes.
Do smaller businesses even need to conduct a formal readiness assessment?
Hopewell: Even smaller organizations can take a shrinked version of this process since almost every organization will have systems that contain the most sensitive and/or long-lived data, regardless of size.
What is the single biggest pitfall of organizations with respect to a readiness assessment?
One of the more common pitfalls is skipping or rushing the discovery phase, where organizations that move straight to planning without a full assessment often uncover critical gaps only after migration work has commenced.
