Cybersecurity GRC 12 items
Post-Quantum Cryptography Readiness Assessment
Assesses readiness for the migration to post-quantum cryptography covering cryptographic inventory, risk prioritization, crypto agility, and migration planning.
NIST PQCNIST 800-53CISA
Free PDF · enter your email to download.
Cryptographic Inventory
- Is a cryptographic bill of materials (CBOM) maintained for algorithms, key sizes, and protocols in use? *
- Are systems using quantum-vulnerable algorithms (RSA, ECC, DH) identified? *
- Are dependencies on third-party and embedded cryptography catalogued?
Risk Prioritization
- Is long-lived sensitive data assessed for harvest-now-decrypt-later risk? *
- Are systems prioritized for migration based on data sensitivity and lifespan? *
- Are contractual and compliance timelines for PQC migration understood?
Crypto Agility
- Are applications designed so cryptographic algorithms can be swapped without major rework? *
- Is cryptography centralized via libraries/services rather than hardcoded per application?
- Are vendors and suppliers queried on their PQC migration roadmaps?
Migration Planning
- Is a phased PQC migration roadmap aligned to NIST-standardized algorithms (ML-KEM, ML-DSA)? *
- Are hybrid (classical + PQC) schemes considered for transitional deployments?
- Is PQC testing planned to validate performance and interoperability before production?
Download the full Post-Quantum Cryptography Readiness Assessment checklist
Get it as a clean, printable PDF — free.
