SecureAzCloud PQC Readiness Checklist

A reusable checklist for planning and governing post-quantum cryptography readiness.

SecureAzCloud Vendor-neutral NIST-aligned Version 1.0 Updated 2026-06-07

Use this checklist to determine whether an organization is ready to plan, pilot, and govern a post-quantum cryptography migration. Readiness means the organization can identify cryptographic dependencies, prioritize risk, coordinate suppliers, test changes safely, and maintain evidence of decisions.

Practical definition of ready: the organization does not need to complete every PQC cutover immediately, but it should know where vulnerable public-key cryptography exists, who owns each dependency, which systems need early action, and how migration will be validated.

Readiness checklist

DomainChecklist itemAcceptance criteriaEvidenceStatus
GovernanceAccountable owner and working group are assigned.Named owner, RACI, cadence, and decision log exist.Program charter; RACI; meeting notes.☐ Not started ☐ In progress ☐ Complete
GovernanceCrypto-agility policy is published.Policy requires configurable algorithms, approved cryptographic libraries, migration-friendly architectures, and exception handling.Policy document; architecture standard.☐ Not started ☐ In progress ☐ Complete
InventoryCryptographic inventory is established.Inventory captures applications, certificates, protocols, libraries, services, devices, identities, signing keys, HSM/KMS, and suppliers.Completed inventory template with evidence links.☐ Not started ☐ In progress ☐ Complete
InventoryUnknown cryptography is tracked as discovery debt.Assets with missing algorithm, library, certificate, or supplier information have owners and due dates.Discovery debt register.☐ Not started ☐ In progress ☐ Complete
Data riskLong-life sensitive data is prioritized.Data shelf life, sensitivity, regulatory requirements, and store-now/decrypt-later exposure are recorded.Data classification and retention mapping.☐ Not started ☐ In progress ☐ Complete
ArchitectureCrypto agility is classified for every priority asset.Hard-coded algorithms, fixed certificate profiles, non-upgradeable libraries, and protocol constraints are documented.Crypto agility field in inventory.☐ Not started ☐ In progress ☐ Complete
PKICertificate authority and trust-store readiness is assessed.CA profiles, trust anchors, renewal automation, revocation, relying-party compatibility, and chain-size impact are understood.PKI assessment and certificate profile matrix.☐ Not started ☐ In progress ☐ Complete
Cloud/IAMIdentity and federation crypto dependencies are mapped.SAML, OIDC/OAuth, JWT, workload identity, mTLS, SSH, service identity, and signing paths are documented.Cloud/IAM dependency map.☐ Not started ☐ In progress ☐ Complete
NetworkTransport crypto is mapped.TLS, VPN, SSH, remote access, service mesh, API gateway, and database driver dependencies are documented.Network crypto inventory.☐ Not started ☐ In progress ☐ Complete
SuppliersCritical supplier PQC roadmaps are requested.Vendors disclose PQC support, upgrade path, cryptographic dependencies, update mechanism, and product support windows.Supplier responses and contract language.☐ Not started ☐ In progress ☐ Complete
TestingInteroperability and performance testing is planned.Tests include handshake behavior, certificate/signature size, latency, fragmentation, logs, client compatibility, and rollback.Test plan and pilot report.☐ Not started ☐ In progress ☐ Complete
OperationsMonitoring and runbooks are updated.New protocols, certificates, signing changes, exceptions, and rollback paths are visible to operations teams.SOC rules; runbooks; change records.☐ Not started ☐ In progress ☐ Complete

Scoring guidance

ScoreMeaningAction
0–25%InitialStart with cryptographic discovery, governance ownership, and supplier roadmap requests.
26–50%DevelopingComplete priority inventories and classify crypto agility blockers.
51–75%ManagedBuild migration backlog, pilot plan, monitoring updates, and change-control procedure.
76–100%OperationalizedRun recurring discovery, maintain exception governance, and refresh plans as standards, protocols, and products evolve.

Minimum evidence package

Reference sources

SourcePublic URL
NIST FIPS 203 — Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)https://csrc.nist.gov/pubs/fips/203/final
NIST FIPS 204 — Module-Lattice-Based Digital Signature Standard (ML-DSA)https://csrc.nist.gov/pubs/fips/204/final
NIST FIPS 205 — Stateless Hash-Based Digital Signature Standard (SLH-DSA)https://csrc.nist.gov/pubs/fips/205/final
NIST PQC Standardization Projecthttps://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization
NIST NCCoE Migration to Post-Quantum Cryptographyhttps://www.nccoe.nist.gov/applied-cryptography/migration-to-pqc
NIST CSWP 39 — Considerations for Achieving Crypto Agilityhttps://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.39.pdf
NIST Cybersecurity Framework 2.0 announcement and resourceshttps://www.nist.gov/news-events/news/2024/02/nist-releases-version-20-landmark-cybersecurity-framework
NIST SP 800-53 Rev. 5 — Security and Privacy Controlshttps://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final
NIST SP 800-82 Rev. 3 — Guide to Operational Technology Securityhttps://csrc.nist.gov/pubs/sp/800/82/r3/final
NIST SP 800-161 Rev. 1 Update 1 — Cybersecurity Supply Chain Risk Managementhttps://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final
CISA — Quantum-Readiness: Migration to Post-Quantum Cryptographyhttps://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography
CISA — Post-Quantum Considerations for Operational Technologyhttps://www.cisa.gov/resources-tools/resources/post-quantum-considerations-operational-technology
CISA — Product Categories for Technologies that Use PQC Standardshttps://www.cisa.gov/resources-tools/resources/product-categories-technologies-use-post-quantum-cryptography-standards

This resource hub is an independent, vendor-neutral planning aid. It is not a NIST, CISA, or government publication and does not imply endorsement by any public agency.