Q-Shield

PQC Readiness Assessment: Inventory, Risk Score, and a Sequenced Roadmap

A post-quantum readiness assessment answers which systems are harvest-exposed, which secrets live longest, and what has to move before each standards deadline. How the three steps fit together.

What a PQC readiness assessment actually answers

A post-quantum readiness assessment is not a scan that returns a pass or fail. It is a structured evaluation that turns a vague worry — "we should probably migrate someday" — into three specific answers:

  • Which systems are harvest-exposed? Which of your systems carry traffic or store data that an adversary could capture now and decrypt later.
  • Which secrets have the longest confidentiality lifetime? Which data must stay confidential for years, and therefore cannot wait for the deadline to act.
  • What has to move before each deadline? Which systems fall under which standards dates, and in what order they need to migrate.

Everything else in the assessment exists to produce those three answers reliably. The structure below is how you get there: inventory, then risk score, then a sequenced roadmap.

Step one — inventory: you cannot assess what you have not found

An assessment can only be as complete as the picture it starts from. Most organizations do not have a full account of the cryptography they already run: algorithms accumulate over years across applications, libraries, appliances, service-to-service links, and certificates issued and then forgotten.

The first step is therefore a cryptographic inventory — locating where and how cryptography is used across systems, and recording for each place the algorithms in use (whether classical, such as RSA-2048 and ECC P-256, or already post-quantum), their key sizes, the protocols that carry them, certificate lifetimes, and the systems and data that depend on each. Unknown cryptography is unmanaged cryptography; a key you cannot see is one you cannot rank or schedule.

Step two — risk score: rank by exposure and lifetime, not by algorithm alone

A raw inventory lists everything flat, but not everything carries the same risk. A weak algorithm protecting a short-lived internal session is a very different problem from the same algorithm protecting data that must stay confidential for a decade.

That is what the risk score resolves. Q-Shield scores quantum risk on five axes (a five-axis QRS) so the highest-risk, longest-lived secrets surface first rather than being buried in a long undifferentiated list. This is where two of the three assessment questions get answered directly: which systems are harvest-exposed, and which secrets have the longest confidentiality lifetime. The score is the bridge between "here is everything we found" and "here is what to touch first."

Why lifetime carries so much weight comes down to the threat model. Under harvest now, decrypt later, an adversary can capture encrypted traffic today and decrypt it once a sufficiently capable quantum computer exists — so data whose confidentiality must outlive the migration window is exposed now, not at some future date. Ranking by lifetime is how the assessment accounts for that.

Step three — roadmap: sequence the work against dated deadlines

The final step turns the ranked findings into an ordered plan. Q-Shield produces a NIST-aligned migration roadmap toward ML-KEM, including a hybrid ECDH + ML-KEM key exchange where that fits — so the migration adds post-quantum protection without abandoning the classical algorithm's established assurance during the transition.

Sequencing is what makes the roadmap a plan rather than a wish list, and the sequence is anchored to published, dated deadlines:

  • NIST IR 8547 deprecates RSA-2048 and ECC P-256 in 2030 and disallows them after 2035.
  • U.S. federal guidance targets high-priority, harvest-exposed systems by the end of 2031 and all remaining systems by the end of 2035.
  • CNSA 2.0 sets a 2027 timeline for U.S. national security systems.

These are dated, sourced deadlines, not predictions — which is exactly why a roadmap can be sequenced against them.

Keeping Q-Day where it belongs — open

It is worth being precise about what is *not* on a fixed schedule. The arrival of a cryptographically relevant quantum computer able to run Shor's algorithm is genuinely uncertain and debated among researchers; no authoritative date exists, and Q-Day should be treated as open rather than as a countdown.

A readiness assessment does not depend on predicting that date. Its urgency comes from two things that are already true today: long-lived data is exposed to harvest now, decrypt later regardless of when Q-Day arrives, and the migration deadlines above are already fixed in the standards. The assessment is how you plan against what is known instead of guessing at what is not.

From assessment to a prioritized plan

The three steps compose into a single output: an inventory that shows what you have, a five-axis quantum risk score that ranks it by exposure and lifetime, and a NIST-aligned roadmap that sequences the migration toward ML-KEM against dated deadlines. That is the difference between knowing a transition is coming and having an ordered plan to meet it.

See how Q-Shield turns a PQC readiness assessment into a prioritized, NIST-aligned migration plan.

Get started