top of page

The PQC Readiness Assessment Evidence Gap: Why Aspiration Is Not Assurance

Writer: Brian Couzens
Brian Couzens
1 day ago
3 min read
An isometric view of a detailed engineering blueprint of machine parts, pinned to a workspace with red tacks. A vintage theodolite, steel rules, and other instruments are arranged on the paper, which shows a clear divide between complex drawings and a large blank planning space.


The post-quantum cryptography transition has moved beyond debate. NIST finalised FIPS 203, 204, and 205 in August 2024. NSA's CNSA 2.0 suite mandates signing migration by 2027, full deprecation by 2030, and prohibition by 2035. Executive Order 14412 directs US federal agencies to accelerate cryptographic inventory and migration planning. The EU, through NIS2 and DORA, has embedded cryptographic risk management into binding regulatory frameworks.

PQC readiness assessments have become a growth market. The question is not whether organisations are conducting them. It is whether those assessments measure anything that would survive scrutiny.


What a PQC Readiness Assessment Should Deliver

A PQC readiness assessment exists to answer one question: can this organisation migrate its cryptographic dependencies to post-quantum algorithms within its regulatory and operational constraints, and what evidence supports that conclusion?

That question demands falsifiable outputs. A cryptographic inventory is a necessary starting point, not an adequate endpoint. An assessment worthy of the name traces each cryptographic dependency through the operational stack: where the algorithm is instantiated, what certificates and key management infrastructure it relies on, which vendor products embed it, and who holds authority to approve its replacement. The output should be a structured evidence base that tells a board precisely which systems cannot migrate without breaking a production dependency, not a qualitative score that tells them the organisation is "moderately ready."


Inventory Without Dependency Mapping

Assessments routinely begin with cryptographic inventory, and many end there. An inventory records which algorithms are in use. It does not record why they are in use, what happens when they are replaced, or who is authorised to replace them.

The GAO's October 2026 audit (GAO-27-108740) examined 24 federal agencies against three preparatory practices: inventory, funding, and testing. None fully addressed all three. Six agencies sampled at random could not produce a complete cryptographic inventory.

An inventory without dependency mapping is a parts list without an engineering drawing. A structured discovery sprint must map the full chain of dependencies before the inventory has operational value.

Governance Without Authority

Cryptographic migration is a governance decision before it is a technical one. Replacing RSA-2048 with ML-KEM-768 in a TLS termination stack requires coordination across infrastructure teams, certificate lifecycle management, and vendor patch schedules. An assessment that does not map governance authority for each migration decision has catalogued aspiration, not readiness.

Neither DORA nor NIS2 accepts a self-declared readiness score as evidence of compliance. Both require demonstrable, testable cryptographic controls underpinned by a coherent assurance framework.


Six Domains a Rigorous PQC Readiness Assessment Must Examine

An assessment that produces actionable, defensible evidence covers at least six domains.

Algorithm exposure: which algorithms are deployed, where, and in what configurations, extending beyond TLS to code signing, firmware verification, and key encapsulation.

Dependency mapping: which systems, services, and contractual obligations depend on each cryptographic implementation, and what breaks if migration proceeds out of sequence.

Key management and certificate chain analysis: which certificate authorities, KMS platforms, and HSMs support PQC algorithms, which do not, and what the replacement timeline is.

Governance authority: who holds decision authority for each migration action, and whether those approval chains have been tested under operational pressure.

Vendor and supply chain readiness: whether third-party products support PQC algorithms, on what timeline, and under what contractual conditions.

Operational migration capability: whether the organisation has deployed PQC algorithms in a staging environment, measured performance impacts, and confirmed rollback procedures. Organisations that lack cryptographic agility at the architectural level face compounding constraints across these domains.

Each domain should produce a documented finding with a supporting evidence chain. Where the evidence is absent, the finding is that evidence is absent, which is a materially different statement from "we plan to gather it."


The Regulatory Clock Is Structural

CNSA 2.0 deprecation begins in 2030. Prohibition follows in 2035. OMB memorandum M-26-15 requires federal agencies to report migration progress on a defined schedule. DORA's technical standards apply to financial entities from January 2025. NIS2 implementation acts are live across EU member states.

The harvest-now-decrypt-later threat model compounds the pressure. Data encrypted with vulnerable algorithms today can be stored by adversaries and decrypted once quantum computing reaches sufficient capability. No assessment conducted after that data is harvested can undo the exposure. Treating PQC readiness as a future planning exercise is a calculation that migration can be deferred without consequence. The evidence suggests otherwise.


The Cost of a Performative Assessment

An assessment that produces comfort rather than evidence carries two costs. Operationally, the organisation proceeds on a false baseline, allocating resources to a plan built on assumptions. Regulatorily, when a supervisor or auditor requires evidence of cryptographic governance, a qualitative readiness score does not constitute it.


SITG-Consulting's PQC Readiness Assessment is structured to deliver the evidence base that migration decisions require, producing findings traceable to source evidence and mapped to regulatory obligations across all six examination areas.

The question is not whether your organisation has conducted a PQC readiness assessment. The question is whether that assessment produced evidence or aspiration.


 
 
 

Comments


bottom of page