Q-Shield
Quantum Risk Assessment: Ranking What You Encrypt by Exposure and Lifetime
A quantum risk assessment ranks encrypted assets so the highest-risk, longest-lived secrets migrate first. Why a flat 'migrate everything' plan fails, and where scoring sits between inventory and roadmap.
The question behind a quantum risk assessment
Most organizations that look into post-quantum cryptography arrive at the same uncomfortable realization: nearly everything they encrypt relies on public-key algorithms that a sufficiently capable quantum computer running Shor's algorithm could break. The natural reaction is a plan that says "migrate everything."
A quantum risk assessment exists because that plan is not really a plan. It asks a narrower and more useful question: of everything we encrypt, what is actually at quantum risk, and what moves first?
The answer is a ranking, not a verdict. Nothing in it says an asset is safe or unsafe in absolute terms. It says that this asset should be handled before that one, and gives a reason.
Why "migrate everything" fails
A flat plan treats every use of classical cryptography as the same problem. In practice they are very different problems:
- A short-lived internal session key protects data that stops mattering within hours.
- An archive of contracts, health records, or design documents may need to stay confidential for many years.
- A certificate on a public endpoint carries traffic anyone on the path can record; a link inside an isolated network is far harder to capture.
When all of these sit in one undifferentiated list, the work gets ordered by accident: whatever was discovered first, whatever is easiest to change, or whichever team has spare time. The assets that most need attention have no particular reason to land at the top.
Migration capacity is also finite. Changing algorithms touches libraries, protocols, hardware, vendors, and testing. A plan with no order spends that capacity wherever it happens to fall.
Risk is driven by lifetime and exposure, not by a predicted date
It is tempting to anchor quantum risk to a date: work out when a cryptographically relevant quantum computer will exist and count backwards. That does not hold up, because the date is not known. When such a machine will arrive is uncertain and debated among researchers, no authoritative date exists, and Q-Day is honestly described as open rather than as a countdown.
A ranking does not need that date. It rests on the harvest now, decrypt later threat model: an adversary can capture encrypted traffic today and decrypt it once a quantum capability exists. That makes two properties of each asset decisive, and both can be established now:
- How long the secret must stay confidential. Data whose confidentiality must outlive the migration window is at risk today, because a copy captured now is still valuable later. Data that expires quickly is not worth storing for years.
- How exposed it is. Data that crosses networks where it can be recorded is a harvest target in a way that data which never leaves a controlled environment is not.
This is why ranking is the rational response to an open question. You do not have to guess when the capability arrives. You order the work so that, whenever it does, the secrets with the longest lifetime and the greatest exposure were moved first. See harvest now, decrypt later for the threat model in depth.
How Q-Shield scores quantum risk
Q-Shield scores quantum risk on five axes — its five-axis QRS, short for quantum risk scoring. The purpose of the score is the one described above: it ranks each asset by exposure so the highest-risk, longest-lived secrets migrate first.
Two points about what the score is and is not:
- It is a prioritization tool. Its output is an order of work. It is not a certification, and a low rank does not mean an asset never needs to migrate; it means other assets go ahead of it.
- It is only as complete as its input. The score ranks what the inventory found. Cryptography that was never located is never ranked.
Where scoring sits: after inventory, before the roadmap
Risk scoring is the middle of three steps, and it does not stand alone.
Before it: cryptographic inventory. You cannot rank what you have not located. A cryptographic inventory discovers where and how cryptography is used across systems. That record is the raw material the score works on.
After it: the migration roadmap. A ranking says what goes first; it does not say how or when. Q-Shield turns the ranked results into a NIST-aligned migration roadmap toward ML-KEM, including a hybrid ECDH + ML-KEM key exchange where appropriate.
Skip the score and the roadmap has nothing to sequence by. Stop at the score and you have a sorted list with no schedule.
Quantum risk assessment vs. PQC readiness assessment
The two terms are often used interchangeably, but they cover different ground.
A PQC readiness assessment is the whole diagnostic: inventory, risk score, and roadmap together, ending in an ordered plan. A quantum risk assessment, as described on this page, is only the ranking step inside it.
If you are starting from nothing, the readiness assessment is the place to begin. If you already know where your cryptography lives and need to decide what to touch first, the risk ranking is the step you are missing.
What a good ranking gives you
A sound quantum risk assessment leaves you with three things: an order of work you can defend, because it is tied to how long each secret must last and how exposed it is; a clear starting point, so migration effort goes first to the data already subject to harvest now, decrypt later; and a direct input to the roadmap. None of that requires a prediction about Q-Day — only an honest account of what you protect and for how long.
See how Q-Shield ranks your cryptographic assets by quantum risk so the longest-lived secrets move first.
Get started