top of page

PQC Strategy & Readiness Assessment

Pre Implementation Review

An independent, evidence-based assessment of your organisation's cryptographic readiness, migration strategy and third-party PQC exposure.

Assessment Overview

Post-Quantum Cryptography (PQC) is not simply a technology upgrade. It is an enterprise transformation challenge involving cryptography, applications, infrastructure, suppliers, data, governance and risk ownership.

Our independent PQC Strategy & Readiness Assessment helps organisations understand where they are today, where they need to be, and what needs to happen next.

What We Assess

PQC Strategy & Roadmap

Cryptographic Estate

Third-Party Cryptographic Risk

We independently assess your existing PQC strategy, roadmap, priorities and assumptions against current standards, industry practice and emerging regulatory expectations.

We assess the scope of cryptographic dependencies across applications, platforms, infrastructure, cloud environments and critical data flows.

We examine third-party providers whose cryptographic implementations, services or dependencies could create exposure for your organisation.

Outbound Connections & Protocols

Governance & Accountability

Migration Readiness

We assess external connections, protocols and dependencies to identify reliance on classical cryptography and the migration constraints that reliance imposes. 

We examine governance structures, standards, ownership, decision rights and how cryptographic risk is escalated, owned and resolved across the organisation.

We assess planned and in-flight remediation, migration priorities, constraints, dependencies and the organisation's demonstrated capacity to execute the transition.

Our Approach

We use an evidence-based assessment rather than relying on policy statements or vendor claims.

The assessment typically includes:

* Review of existing PQC and cryptographic documentation
* Development of a structured PQC assessment questionnaire
* Stakeholder interviews
* Assessment of cryptographic dependencies and exposure
* Review of third-party risk
* Assessment against relevant standards and guidance
* Identification of gaps, risks and dependencies
* Review of quantum-risk assumptions and migration priorities
* Independent validation of current-state readiness

Third-Party PQC Risk

Third-party providers can become a significant source of cryptographic exposure.

We help organisations classify and prioritise third parties according to factors such as:

Data sensitivity | Cryptographic longevity | Dependency depth | External connectivity | Migration complexity | Business criticality

This creates a practical basis for deciding which providers need engagement first, why they matter, and what evidence should be required from them.

What You Receive

    The assessment provides a clear view of:

    * Current PQC readiness
    * Key cryptographic risks and exposures
    * Critical gaps
    * Third-party dependencies
    * Decision points
    * Migration constraints
    * Governance weaknesses
    * Priority actions
    * Areas requiring further investigation

    The objective is not to produce another generic PQC report.

    It is to establish whether the organisation is actually positioned to execute its cryptographic transition.

Independent. Evidence-Based.
Risk-Focused.



PQC readiness cannot be demonstrated by having a strategy document or a migration target.

It requires evidence that the organisation understands its cryptographic estate, knows where dependencies exist, has assigned ownership, understands third-party exposure and can execute the transition.

TRANS INK STAMP.png

PQC migration has moved from good practice to regulatory expectation. Assessments are conducted against the standards and timelines your regulators, auditors and clients will hold you to.

  • NIST FIPS 203, 204 and 205. The approved post-quantum standards for key establishment and digital signatures.

  • FIPS 140-3. Cryptographic module validation. FIPS 140-2 certificates move to Historical status on 21 September 2026, after which new procurement should require FIPS 140-3.

  • UK NCSC migration timeline. Cryptographic discovery and a defined migration plan by 2028. Highest-priority migration complete by 2031. Full migration by 2035.

  • EU coordinated PQC roadmap. National transition roadmaps and cryptographic inventories by 31 December 2026. High-risk use cases addressed by 2030. Systemic transition by 2035.

  • NIS2. The Commission has proposed amending the Directive to require member states to include post-quantum transition policies within national cybersecurity strategies.

  • CNSA 2.0. NSA requirements for national security systems and the suppliers serving them.

  • EU DORA. ICT risk management and third-party oversight obligations for financial entities, which extend to cryptographic dependency.

Regulatory Alignment

These frameworks are the basis of QCAS, our published assurance standard, and are applied across our FIPS 140-3 Gap Analysis and NIST CSF 2.0 work. The assessment maps your position against them and identifies where your own timeline diverges from the one your regulator is working to.

Start Your PQC Readiness Assessment

Understand your exposure. Establish your priorities. Build a defensible path to PQC readiness.

Email: info@sitg-consulting.com

bottom of page