simpl.
Cybersecurity GRC 12 items

Post-Quantum Cryptography Readiness Assessment

Assesses readiness for the migration to post-quantum cryptography covering cryptographic inventory, risk prioritization, crypto agility, and migration planning.

NIST PQCNIST 800-53CISA

Free PDF · enter your email to download.

Cryptographic Inventory

  • Is a cryptographic bill of materials (CBOM) maintained for algorithms, key sizes, and protocols in use? *
  • Are systems using quantum-vulnerable algorithms (RSA, ECC, DH) identified? *
  • Are dependencies on third-party and embedded cryptography catalogued?

Risk Prioritization

  • Is long-lived sensitive data assessed for harvest-now-decrypt-later risk? *
  • Are systems prioritized for migration based on data sensitivity and lifespan? *
  • Are contractual and compliance timelines for PQC migration understood?

Crypto Agility

  • Are applications designed so cryptographic algorithms can be swapped without major rework? *
  • Is cryptography centralized via libraries/services rather than hardcoded per application?
  • Are vendors and suppliers queried on their PQC migration roadmaps?

Migration Planning

  • Is a phased PQC migration roadmap aligned to NIST-standardized algorithms (ML-KEM, ML-DSA)? *
  • Are hybrid (classical + PQC) schemes considered for transitional deployments?
  • Is PQC testing planned to validate performance and interoperability before production?

Download the full Post-Quantum Cryptography Readiness Assessment checklist

Get it as a clean, printable PDF — free.