About this assessment

Post‑quantum migration is a multi‑year program. This questionnaire highlights common readiness signals—inventory, data lifetimes, executive sponsorship, and regulatory drivers—so you can prioritize next steps. It takes about three minutes and does not collect personal data.

General guidance only—not cryptographic, legal, or compliance advice. For a tailored assessment, contact our team.

Self‑assessment

Where is your organization today?

Answer seven questions to receive a readiness snapshot and recommended next steps.

Question 1 of 7

Which best describes your organization?
Do you maintain an inventory of cryptographic algorithms in production?
How long must your most sensitive data remain confidential?
Have you assessed harvest‑now‑decrypt‑later (HNDL) exposure?
Are RSA, ECC, and other quantum‑vulnerable algorithms mapped across systems?
Is there executive or board‑level sponsorship for PQC migration?
Where are you in the PQC migration lifecycle?
FAQ

Common PQC questions

Grounded answers on standards, timelines, and migration—without the hype.

What is post‑quantum cryptography (PQC)?

PQC refers to cryptographic algorithms designed to resist attacks from large‑scale quantum computers. NIST has standardized ML‑KEM (key encapsulation), ML‑DSA and SLH‑DSA (digital signatures) for deployment alongside or in place of classical RSA and elliptic‑curve schemes.

When do we need to migrate?

There is no single deadline for every organization—but data with long confidentiality requirements is already exposed to harvest‑now‑decrypt‑later risk. Governments and regulators are publishing roadmaps with multi‑year horizons; starting discovery and planning now reduces cost and disruption compared to waiting for a mandate.

What is harvest‑now‑decrypt‑later (HNDL)?

Adversaries can record encrypted traffic today and decrypt it later once quantum computers break current public‑key cryptography. Any secret that must stay confidential for 10–20+ years should be protected with quantum‑resilient algorithms—or re‑encrypted— before those systems are considered at risk.

Which algorithms should we use?

NIST FIPS 203 (ML‑KEM), FIPS 204 (ML‑DSA), and FIPS 205 (SLH‑DSA) are the primary standards for new deployments. Selection depends on protocol, performance, certificate infrastructure, and interoperability constraints—often starting with hybrid classical‑plus‑PQC modes during transition.

What is a cryptographic bill of materials (CBOM)?

A CBOM is an inventory of algorithms, libraries, protocols, keys, and dependencies in your systems—similar to a software BOM but focused on cryptography. It is the foundation for prioritizing migration, measuring progress, and reporting to auditors or regulators.

Do we need hybrid cryptography during transition?

Hybrid schemes combine classical and post‑quantum algorithms so you maintain compatibility while PQC support matures across your stack. Many organizations use hybrids in TLS, code signing, or internal PKI during phased rollout, then simplify as ecosystems catch up.

How long does migration typically take?

Full enterprise migration is usually a multi‑year program: discovery (weeks to months), roadmap and architecture (months), pilots (quarters), and phased production rollout (1–3+ years depending on scale and legacy depth). Early inventory and crypto‑agility investments shorten later phases.

How can Quantum Transition Labs help?

QTL is a research-led post-quantum security engineering firm—not advisory-only. We deliver dedicated solutions including the PQC Readiness self-assessment and FAQ, SILMARILS designated-verifier authentication for permissioned ledgers, QTL Wallet (see /qtl-wallet/), end-to-end migration programs (discovery through production), quantum-safe protocol and PKI/HSM engineering, blockchain and custody hardening, and AI-assisted cryptographic analysis. Engagements range from sprint assessments to embedded program partnerships. Start at /pqc-readiness/ or contact contact@qtransitionlabs.com. View our services or get in touch.

Ready for a deeper assessment?

Our PQC Readiness Assessment delivers a cryptographic inventory, quantum risk scoring, and executive priority matrix—tailored to your environment.

Talk to an expert