top of page

The PQC Baker's Dozen: 13 Mistakes That Derail a Post-Quantum Cryptography Transition

Writer: Brian Couzens
Brian Couzens
2 minutes ago
3 min read
Egg box of twelve eggs etched with PQC migration mistakes, and a cracked ostrich egg reading Buying the Product First.

The costliest mistake in a post-quantum cryptography (PQC) transition is made before a single algorithm changes. It is buying a product first.

Each mistake below sets out what goes wrong and what to do instead, across PQC and crypto modernisation programmes, with the SITG-Consulting analysis and the primary source behind it.

1. Starting with a PQC product

A product cannot tell you where your cryptography sits. Board mandate first, discovery second, vendor fifth.

2. No board mandate

Quantum risk is known and foreseeable. No mandate means no owner, no funding and no leverage over suppliers.

3. Making the CISO the owner

This is an enterprise risk programme, not a security project. Ownership sits with the Chief Risk Officer, with the Chief Information Security Officer accountable for the security controls.

4. Treating a scan or a CBOM as discovery

Initial discovery should give you the as-is: the current state of your crypto estate, what exists, where it runs and who owns it. A cryptographic bill of materials records that state. It does not replace the work of establishing it.

5. Starting with infrastructure, not data

Begin with the data that must stay secret longest, then trace the cryptography protecting it.

6. Waiting for Q-day, the day a quantum computer breaks today's encryption

Mosca's test: if data shelf-life plus migration time exceeds the time to that machine, you are already late.

7. Mistaking a supplier's roadmap for yours

Theirs says when a capability exists. Yours must say when your systems are ready.

SITG-Consulting analysis: PQC Roadmap vs PQC Migration Roadmap

8. Accepting "PQC-ready" without evidence

A questionnaire records a claim, not a control. FIPS 140-2 certificates moved to NIST's historical list in September 2026, so check claims against FIPS 140-3.

9. Going estate-wide before a bounded pilot

Hybrid is a bridge, not the destination. Agree success thresholds and rollback first.

10. Deploying without proving it works

Deployment is logistics. Assurance is governance. The builder should not mark its own work.

11. Running public key infrastructure, key management and PQC as separate projects

Public TLS certificate lifetimes fall to 47 days by March 2029 while post-quantum signatures grow fiftyfold. One programme, not three.

12. Ignoring entropy

A post-quantum algorithm running on weak randomness is not a post-quantum implementation.

13. Treating crypto-agility as a product

It rests on entropy, interoperability and visibility. Remove one and it fails.

SITG-Consulting analysis: Crypto-Agility Is Not the Goal

The pattern

Eight of the thirteen happen before any cryptography changes. The fix is sequence, not technology.

Board mandate first. Discovery second. Governance third. Dependency mapping fourth. Vendor selection fifth. Remediation sixth. Then deploy, test and prove it, in an order set by risk rather than commercial convenience.

SITG-Consulting provides independent PQC advisory and assurance, from board mandate through discovery to validated migration.



Brian Couzens, CEO, SITG-Consulting

 
 
 

Comments


bottom of page