Why PQC Vendors Are Not the Starting Point for Your Post-Quantum Transition

The Order Matters. Getting It Wrong Is Expensive.
A growing number of organisations are beginning their post-quantum cryptography (PQC) transition with a vendor evaluation. They attend a conference, see a product demonstration, receive a pitch deck, and begin a procurement process. This is the wrong sequence. It produces partial coverage, unmanaged dependencies, and a governance gap that widens with every deployment decision made without a baseline.
The transition to post-quantum cryptography is not a product installation. It is a structural transformation of how an organisation discovers, governs, and remediates its entire cryptographic estate. The vendor has a role. That role does not come first.
What Comes First: Cryptographic Discovery
Before any product is evaluated, an organisation must answer a set of questions it has rarely been asked:
Where does cryptography sit in our environment? Not where we think it sits. Where it actually sits, including in legacy systems, third-party integrations, certificate chains, firmware, and embedded devices.
What does it protect, and for how long? A payment transaction has a different confidentiality window to a medical record, a defence contract, or a pension fund's member data. The protection horizon determines when the quantum threat becomes a live exposure, and that calculation is asset-specific, not organisational.
What are the dependencies? Which suppliers, platforms, and protocols must move before we can? Which certificate authorities, hardware security module (HSM) vendors, and cloud providers are on a PQC roadmap, and which are not?
What is our governance position? Do we have a cryptographic asset register? A Cryptographic Bill of Materials (CBOM)? A policy that defines algorithm approval, deprecation timelines, and exception handling?
These are not optional prerequisites. Regulatory frameworks across jurisdictions are converging on the same requirement: that organisations know what cryptography they run before they are expected to change it. The EU's Digital Operational Resilience Act (DORA) requires financial entities to maintain ICT asset registers, including cryptographic controls. The NSA's CNSA 2.0 timeline sets algorithm deprecation dates that cascade into supply chain procurement. The UK's NCSC, France's ANSSI, and Germany's BSI have each published post-quantum migration guidance that assumes a cryptographic baseline already exists. None of these frameworks begin with a product recommendation. All of them begin with an inventory.
If you do not have a cryptographic inventory, you do not have a PQC programme. You have a procurement exercise with no foundation.
The SITG-Consulting PQC Discovery Sprint
At SITG-Consulting, we built the PQC Discovery Sprint to address precisely this gap. It is the opening engagement of the Cryptographic Transformation Implementation Model, a gated methodology that moves from board mandate through to continuous cryptographic assurance. Each gate is a formal decision point, passed on evidence, not assumption.
The Sprint is a defined, time-bounded engagement, indicatively 20 to 30 working days and longer where the estate is more complex. It is a forensic process that maps cryptographic assets across the enterprise, scores them by exposure and protection horizon, identifies dependencies on external systems and suppliers, and delivers a governance position the board can act on.
The outputs are specific:
A Cryptographic Bill of Materials (CBOM) that catalogues algorithms, key lengths, certificate authorities, and protocol versions across the estate.
A risk-scored asset register that maps each cryptographic dependency to its confidentiality window and quantum exposure.
A dependency map that identifies which transitions are blocked by supplier, platform, or protocol constraints the organisation does not control.
A governance assessment that tells the board where the organisation stands against applicable regulatory requirements and sovereign deprecation timetables.
The Sprint is not a discovery exercise that ends in a report. It is not a maturity assessment or a compliance checkbox. It is not a vendor-led tool deployment. It is not a migration project in miniature. Its outputs are built to enter board papers, regulatory submissions and procurement decisions directly. It opens a governed programme.
The Sprint does not end with a vendor recommendation. It ends with a position. What you have, what is exposed, what you do not control, and what the board must decide. Vendor selection becomes rational only after that position is established.
Quantum Washing: The Damage Already Being Done
The term "quantum washing" describes the practice of marketing products as quantum-safe, quantum-ready, or PQC-compliant when the underlying claims do not hold up under scrutiny. It is the post-quantum equivalent of greenwashing, and it is already distorting procurement decisions across financial services, critical infrastructure, and government.
The pattern is consistent:
Products marketed as "PQC-ready" that have not completed FIPS 140-3 validation under a post-quantum boundary. The National Institute of Standards and Technology (NIST) Cryptographic Module Validation Programme (CMVP) has a defined process for this. Claiming readiness without completing it is, at best, misleading.
Hybrid implementations presented as complete PQC solutions. Hybrid key exchange, combining a classical and a post-quantum algorithm, is a transitional mechanism. It is not a transformation. An organisation running hybrid TLS on its perimeter while its internal certificate authority, its HSMs, its firmware signing, and its supplier integrations remain classical has not transitioned. It has applied a partial overlay.
Discovery tools positioned as transformation programmes. A discovery tool is one input to a PQC programme. It identifies cryptographic artefacts in a defined scope. It does not map dependencies. It does not assess governance maturity. It does not produce a board-ready risk position. Treating the tool output as the programme output is a category error that leaves the organisation exposed precisely where it assumed it was covered.
The commercial incentive behind quantum washing is obvious: the PQC market is growing, procurement budgets are opening, and the organisations spending the money often lack the in-house expertise to challenge vendor claims. The result is that money moves before the problem is understood, and the gap between perceived and actual readiness widens.
PQC Wrappers and Corridor Resellers
A specific variant of quantum washing deserves its own scrutiny. A number of resellers and channel partners are now offering what amount to PQC wrappers: products that layer a post-quantum key exchange onto an existing VPN tunnel, TLS termination point, or encrypted corridor, and present the result as a post-quantum solution.
These products have a legitimate use case, but only after the organisation has completed its discovery and governance work. A PQC wrapper applied to a VPN corridor protects data in transit across that corridor. It does not address the cryptographic dependencies inside the systems at each end. It does not address key management, certificate lifecycle, firmware signing, or data-at-rest encryption. It does not produce a CBOM. It does not satisfy a regulatory requirement for a cryptographic asset register.
The risk is that organisations deploy these wrappers, report to the board that they have begun their PQC transition, and create a false baseline that is difficult to correct later. The wrapper becomes the programme, and the inventory, governance, and dependency work that should have preceded it never happens.
This is not a hypothetical failure mode. It is already occurring.
Where the PQC Vendor Fits
SITG-Consulting works with PQC vendors as a consultancy partner. We partner with them. We do not endorse them. That distinction is central to how we operate and to the independence of the advisory work we deliver. Our role is to ensure that an organisation has completed its discovery and governance work before any product enters the conversation, so that vendor engagement is informed, productive, and tied to a defined requirement set.
Major distributors across multiple jurisdictions are now engaging us for precisely this reason. They hold PQC products they cannot move in-country because the prospective client does not understand what the product is for. The organisation has no cryptographic inventory, no governance baseline, and no clarity on where the product fits in its estate. Without the discovery work, the distributor has a solution and no defined problem. That is not a sales cycle. It is a stalemate that serves neither party.
The discovery and governance work unblocks the vendor relationship. It gives the client a requirement set, the distributor a qualified buyer, and the board a defensible position. The vendor's role is essential. It is not first.
The Sequence That Works
The organisations that will navigate this transition successfully are the ones that start with the question, not the answer. The sequence is:
Board mandate first. Secure executive sponsorship and commitment to a governed programme.
Discovery second. Find out what you have, where it sits, and how long it must be protected.
Governance third. Establish the policy framework, the CBOM, the deprecation timetable, and the board accountability structure.
Dependency mapping fourth. Identify which transitions are blocked by external constraints and engage suppliers accordingly.
Vendor selection fifth. Evaluate products against a defined requirement set, not a marketing pitch.
Remediation sixth. Deploy, test, and validate in a sequence determined by risk priority, not commercial convenience.
This is not a theoretical framework. It is how SITG-Consulting delivers every engagement, and it is the only sequence that produces an auditable, defensible transition that holds up when the regulator, the auditor, or the incident response team arrives.
Conclusion
If your PQC programme started with a vendor shortlist, it did not start. It purchased comfort. The transition to post-quantum cryptography is a governance transformation, not a procurement exercise. The hard part is not choosing the algorithm. It is knowing what you have, understanding what it protects, and building the governance architecture to manage the change.
The vendor comes later. The work starts now.
To discuss the PQC Discovery Sprint or request the Sprint overview document, contact brian.couzens@sitg-consulting.com.
Brian Couzens CEO, SITG-Consulting




Comments