Use this checklist to determine whether an organization is ready to plan, pilot, and govern a post-quantum cryptography migration. Readiness means the organization can identify cryptographic dependencies, prioritize risk, coordinate suppliers, test changes safely, and maintain evidence of decisions.
Practical definition of ready: the organization does not need to complete every PQC cutover immediately, but it should know where vulnerable public-key cryptography exists, who owns each dependency, which systems need early action, and how migration will be validated.
Readiness checklist
| Domain | Checklist item | Acceptance criteria | Evidence | Status |
|---|---|---|---|---|
| Governance | Accountable owner and working group are assigned. | Named owner, RACI, cadence, and decision log exist. | Program charter; RACI; meeting notes. | ☐ Not started ☐ In progress ☐ Complete |
| Governance | Crypto-agility policy is published. | Policy requires configurable algorithms, approved cryptographic libraries, migration-friendly architectures, and exception handling. | Policy document; architecture standard. | ☐ Not started ☐ In progress ☐ Complete |
| Inventory | Cryptographic inventory is established. | Inventory captures applications, certificates, protocols, libraries, services, devices, identities, signing keys, HSM/KMS, and suppliers. | Completed inventory template with evidence links. | ☐ Not started ☐ In progress ☐ Complete |
| Inventory | Unknown cryptography is tracked as discovery debt. | Assets with missing algorithm, library, certificate, or supplier information have owners and due dates. | Discovery debt register. | ☐ Not started ☐ In progress ☐ Complete |
| Data risk | Long-life sensitive data is prioritized. | Data shelf life, sensitivity, regulatory requirements, and store-now/decrypt-later exposure are recorded. | Data classification and retention mapping. | ☐ Not started ☐ In progress ☐ Complete |
| Architecture | Crypto agility is classified for every priority asset. | Hard-coded algorithms, fixed certificate profiles, non-upgradeable libraries, and protocol constraints are documented. | Crypto agility field in inventory. | ☐ Not started ☐ In progress ☐ Complete |
| PKI | Certificate authority and trust-store readiness is assessed. | CA profiles, trust anchors, renewal automation, revocation, relying-party compatibility, and chain-size impact are understood. | PKI assessment and certificate profile matrix. | ☐ Not started ☐ In progress ☐ Complete |
| Cloud/IAM | Identity and federation crypto dependencies are mapped. | SAML, OIDC/OAuth, JWT, workload identity, mTLS, SSH, service identity, and signing paths are documented. | Cloud/IAM dependency map. | ☐ Not started ☐ In progress ☐ Complete |
| Network | Transport crypto is mapped. | TLS, VPN, SSH, remote access, service mesh, API gateway, and database driver dependencies are documented. | Network crypto inventory. | ☐ Not started ☐ In progress ☐ Complete |
| Suppliers | Critical supplier PQC roadmaps are requested. | Vendors disclose PQC support, upgrade path, cryptographic dependencies, update mechanism, and product support windows. | Supplier responses and contract language. | ☐ Not started ☐ In progress ☐ Complete |
| Testing | Interoperability and performance testing is planned. | Tests include handshake behavior, certificate/signature size, latency, fragmentation, logs, client compatibility, and rollback. | Test plan and pilot report. | ☐ Not started ☐ In progress ☐ Complete |
| Operations | Monitoring and runbooks are updated. | New protocols, certificates, signing changes, exceptions, and rollback paths are visible to operations teams. | SOC rules; runbooks; change records. | ☐ Not started ☐ In progress ☐ Complete |
Scoring guidance
| Score | Meaning | Action |
|---|---|---|
| 0–25% | Initial | Start with cryptographic discovery, governance ownership, and supplier roadmap requests. |
| 26–50% | Developing | Complete priority inventories and classify crypto agility blockers. |
| 51–75% | Managed | Build migration backlog, pilot plan, monitoring updates, and change-control procedure. |
| 76–100% | Operationalized | Run recurring discovery, maintain exception governance, and refresh plans as standards, protocols, and products evolve. |
Minimum evidence package
- Cryptographic inventory export for priority assets.
- Risk scoring method and prioritized backlog.
- PQC migration owner, RACI, and decision log.
- PKI, IAM, cloud, application, network, and OT/ICS dependency maps.
- Supplier roadmap and support-window tracker.
- Non-production pilot test plan and results.
- Exception register with compensating controls and expiration dates.
Reference sources
This resource hub is an independent, vendor-neutral planning aid. It is not a NIST, CISA, or government publication and does not imply endorsement by any public agency.