Read this first
A PQC readiness assessment measures how prepared you are to migrate to post-quantum cryptography — across inventory coverage, crypto-agility, governance, exposure, and supplier dependencies. It is breadth-first: it produces a scored baseline and a prioritized gap list, not a line-by-line audit of one system. Its job is to turn "we know quantum is coming" into "here is where we stand and what to fix first." One caveat that runs through everything below: the score is only as honest as the inventory beneath it.
Most organizations know they will eventually have to move off RSA and elliptic-curve cryptography. Far fewer can say, concretely, how ready they are to do it. A PQC readiness assessment closes that gap. It is a structured evaluation of your posture across the whole estate — deliberately wide rather than deep — that converts an uneasy sense of exposure into a measurable baseline you can act on and re-measure over time.
What it evaluates
A readiness assessment scores you across a small number of dimensions that, together, determine whether a migration would succeed or stall. The exact weighting varies, but the core set is consistent:
- **Cryptographic inventory coverage** — do you actually know where cryptography lives? An assessment tests whether you can enumerate algorithms, key sizes, protocols, and their locations across code, infrastructure, and certificates. This rests on a cryptographic inventory; without one, every other dimension is a guess.
- **Crypto-agility maturity** — could you change algorithms without re-architecting? Crypto-agility measures how deeply algorithms are hardwired into your systems and how quickly you could swap them under pressure.
- **Governance** — is there a crypto policy, a named owner, and a mapping to standards? Control frameworks such as ISO 27001 A.8.24 expect documented rules on cryptography; an assessment checks whether yours exist and are enforced.
- **Exposure** — which data is at risk, and how urgently? This ranks systems by data shelf life against the harvest-now-decrypt-later threat, so long-lived secrets protected by quantum-vulnerable key exchange rise to the top.
- **Third-party and supplier cryptography** — much of your real attack surface is inherited. The assessment probes vendor products, libraries, and dependencies whose crypto you do not control but do depend on.
How it differs from a full audit
A readiness assessment and a technical audit answer different questions. Readiness is about breadth and posture: how prepared is the organization as a whole, and where are the biggest gaps? A full audit is about depth: it examines specific systems and implementations closely, verifying configurations, tracing key material, and confirming conformance. Readiness usually comes first — it establishes the baseline and, crucially, scopes where the deeper audit work should be aimed. Running an expensive deep audit before you know where your risk concentrates tends to over-examine the wrong systems.
The output
You should walk away from a readiness assessment with three concrete artifacts: a scored baseline across the dimensions above, a prioritized gap list ranked by risk and effort, and the seed of a migration roadmap that sequences the work by data shelf life and dependency order. The baseline is not a one-off grade — it is a measurement you repeat, so you can show progress and detect regression as systems change.
A high score on a thin inventory is false confidence
The single most common failure is scoring readiness against an incomplete picture. If your inventory covers 60% of your estate, a strong score describes only that 60% — the untracked remainder is exactly where forgotten, quantum-vulnerable crypto tends to hide. Treat readiness as a repeatable measurement anchored to inventory coverage, and be suspicious of any high score whose denominator you cannot defend.
How quantakrypto helps
We run readiness as the front door to a migration program, not a compliance checkbox. That means starting from a defensible cryptographic inventory, scoring the dimensions above honestly, and handing you a prioritized gap list that flows directly into a sequenced migration plan. Where the assessment exposes governance or crypto-agility weaknesses, we help close them — and we run training so your teams can maintain the baseline and re-measure it themselves rather than depending on an annual outside review.