Are You Ready to Witness the Future of Data Security?
Platform
Resources
©2026 QuNu Labs Private Limited, All Rights Reserved.

Most organisations have conducted a cybersecurity audit at some point in the last two years. Very few have conducted a quantum readiness assessment. These are not the same exercise. A cybersecurity audit evaluates controls, policies, and configurations against a known threat model. A quantum readiness assessment evaluates cryptographic architecture against a threat model that does not yet exist at full operational scale but is arriving on a documented timeline.
The NIST post-quantum cryptography standards were finalised in August 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). NSA CNSA 2.0 mandates algorithm replacement for national security systems by 2030 and prohibits all quantum-vulnerable algorithms by 2035. Citi published a Quantum Readiness Survey for supply chain assessment that is cited in the NIST migration documentation itself. These are not draft guidelines. They are published standards with enforcement timelines.
The quantum readiness assessment is the first step of the migration programme. Without one, an organisation cannot know where it is exposed, what to migrate first, how long migration will take, or what it will cost. The assessment is also, in many regulated sectors, becoming a compliance document in its own right. This guide explains what a quantum readiness assessment actually measures, how the outputs are structured, and how to use those outputs to build an executable migration programme.
A standard security audit looks for controls that are absent, configurations that are incorrect, and vulnerabilities that are exploitable today. Its threat model is the current adversary landscape: ransomware, phishing, insider threats, unpatched software.
A quantum readiness assessment has a different scope. It looks for cryptographic algorithms that are currently secure but will become insecure when a cryptographically relevant quantum computer (CRQC) is available. These algorithms are not misconfigured. They are not unpatched. They are working exactly as designed, and they are the problem.
The specific algorithms under examination are the public-key cryptography systems that underpin the entire digital security infrastructure: RSA (used for key encapsulation and digital signatures), Elliptic Curve Diffie-Hellman (ECDH, used for key exchange in TLS), Elliptic Curve Digital Signature Algorithm (ECDSA, used for certificate signing and code signing). AES-256 is quantum-resistant and does not require replacement.
The first output of a quantum readiness assessment is a complete cryptographic inventory. This is not the same as a certificate inventory, which most organisations already have. A cryptographic inventory maps every algorithm in use across infrastructure, applications, and vendor integrations.
What gets discovered: TLS cipher suites negotiated on every external and internal endpoint, JWT and SAML token signing algorithms, SSH key algorithms across all servers and network devices, code signing certificate algorithms, HSM algorithm support and configuration, VPN IKE configuration, certificate authority algorithm selection, and third-party and vendor API authentication mechanisms.
The discovery scope has four asset classes in order of assessment priority. Class 1 is network perimeter (TLS): the highest attack surface and the most straightforward to migrate. Class 2 is application layer (JWT, SAML, code signing). Class 3 is infrastructure (SSH, VPN, HSM). Class 4 is embedded and legacy (IoT, SCADA, operational technology firmware): the most complex and the longest migration tail.
A raw cryptographic inventory is not a migration plan. Risk scoring converts the inventory into a prioritised queue. Three factors determine score:
A quantum readiness assessment maps the cryptographic inventory against applicable regulatory requirements. For organisations operating in regulated sectors, this is not optional: it is the compliance deliverable.
Key regulatory reference points: NIST FIPS 203/204/205 (international standard for PQC algorithm selection). NSA CNSA 2.0 (2030 migration mandate for national security systems; 2035 prohibition deadline). NIST IR 8547 (RSA-2048 and ECC P-256 deprecated by 2030 under initial public draft, November 2024).
For defence-adjacent organisations, the parameter set matters. NSS-grade environments require ML-KEM-1024 and ML-DSA-87. Civilian migration defaults to ML-KEM-768 and ML-DSA-65. Planning with the wrong parameter set creates rework when the system is deployed into a defence interoperability requirement.
The output of a well-structured quantum readiness assessment is a migration sequence, not a flat list of vulnerabilities. The sequence is determined by combining the risk score with migration complexity:
An organisation's quantum migration is only as complete as its vendor ecosystem's migration. Every API integration, SaaS application, and third-party data processor that uses RSA or ECC in its communications with the assessed organisation is a residual exposure point even after the organisation's own infrastructure is migrated.
Citi's Quantum Readiness Survey, referenced in NIST's own migration documentation, is a model for organisations to adapt for supply chain assessment. [Source: NIST migration FAQ : Citi Quantum Readiness Survey] A complete quantum readiness assessment includes a tier-1 vendor assessment (all critical vendors) and a framework for ongoing supply chain monitoring as the migration programme progresses.
A well-structured quantum readiness assessment produces five deliverables:
Four errors account for most quantum readiness assessments that fail to support an executable migration programme:
A quantum readiness assessment is the document that turns a board-level concern about quantum computing into an executable migration programme with a budget, a sequence, and a compliance deliverable. The organisations that have completed assessments know what to do next. The organisations that have not are accumulating undocumented regulatory exposure with every day that their RSA and ECC infrastructure transmits data.
Contact QNu Labs to book your quantum readiness assessment.
Ready to take the next step?
Book a Quantum Readiness Risk Assessment: https://www.qnulabs.com/request-a-demo
Download: The QNu Migration Theorem (Survival of Equality): https://www.qnulabs.com/whitepaper
Contact QNu Labs: https://www.qnulabs.com/contact-us
Related: QShield Platform: https://www.qnulabs.com/quantum-security-platform
Related: QKD Complete Guide: https://www.qnulabs.com/blog/quantum-key-distribution-qkd-complete-guide
A standard cybersecurity audit evaluates current controls against current threats. A quantum readiness assessment evaluates cryptographic architecture against a future threat on a documented timeline: the cryptographically relevant quantum computer. The algorithms under examination are working correctly today; they become the vulnerability when quantum computing capability reaches the required level. A standard audit will not find this exposure.
No. AES-256 is symmetric encryption and is considered quantum-resistant at its current key size. Grover's algorithm, which provides a quantum speedup for searching, reduces AES-256's effective security from 256 bits to 128 bits, which remains computationally infeasible. PQC migration focuses on public-key cryptography: RSA, ECDSA, and ECDH.
Mosca's Inequality states that if the time to migrate your cryptographic infrastructure plus the time remaining for quantum computers to reach cryptographic relevance is greater than your data's required confidentiality period, you need to begin migrating now. For data with 25 to 50 year confidentiality requirements, this inequality already resolves in favour of immediate action.
A basic quantum readiness assessment covering the network perimeter and application layer of a mid-sized enterprise typically takes 4 to 8 weeks with automated tooling. Full infrastructure assessment including embedded systems and third-party supply chain assessment extends to 3 to 6 months.
No regulation currently mandates the assessment document itself by that name. However, NIST FIPS 203/204/205 compliance, NSA CNSA 2.0 compliance (for national security systems by 2030), and NIST IR 8547 compliance (deprecation of RSA-2048 and ECC P-256 by 2030) all require an organisation to know which systems use vulnerable algorithms. A quantum readiness assessment is the instrument that produces that knowledge. Without it, compliance planning cannot begin.
Cost varies by organisation size, infrastructure complexity, and vendor ecosystem breadth. The starting point is a scoping conversation to determine asset class coverage, vendor assessment scope, and regulatory framework requirements.