Industry Context
Regulated institutions run on cryptographic trust. Banks, asset managers, payment processors, market infrastructure operators, and critical infrastructure providers depend on cryptography for every authenticated session, every signed transaction, and every record a regulator, auditor, or counterparty will later rely on. That trust is not an implementation detail — it is the condition on which the licence to operate rests. Almost all of it sits on the same foundations: RSA and elliptic-curve cryptography secure the systems in operation today, and the same schemes secure the compliance artefacts an institution must retain — signed submissions, audit trails, transaction records, identity credentials — for years after they are created. In August 2024, the post-quantum migration moved from theoretical to mandatory. Regulated organisations are now expected — by supervisory expectation today and by hard deadline within the decade — to know where their cryptography is vulnerable to quantum attack and to show a credible migration plan. Almost none of them can. Most institutions cannot say, with evidence, where their cryptographic dependencies sit, which of them protect long-lived sensitive data, or in what order they would migrate. This is where cryptographic exposure stops being a technical detail and becomes a governance question. An institution that cannot produce a cryptographic inventory and a migration plan is already out of step with what supervisors are beginning to ask — years before the hard deadlines bite.
Emerging Requirements
The forces driving change are external, dated, and largely outside any single institution's control. In August 2024, NIST ratified the first post-quantum cryptographic standards — FIPS 203, 204, and 205. The replacement algorithms for the ECDSA and RSA schemes in use across the industry are no longer research proposals; the successor algorithms are now published standards. NIST IR 8547 sets the transition timeline: RSA and elliptic-curve cryptography are scheduled for deprecation for new systems after 2030 and disallowance after 2035. CNSA 2.0 goes further for national-security systems, requiring new acquisitions to support ML-KEM-1024 and ML-DSA-87 from January 2027 — which matters well beyond defence, because those procurement expectations flow through supply chains and set the tone that government-linked counterparties carry into the market. The direction of travel is not confined to the United States. In the UK, the NCSC's post-quantum migration roadmap expects organisations to complete discovery and migration planning by 2028, finish their highest-priority migrations by 2031, and complete the transition by 2035. In the EU, DORA has applied to financial entities since January 2025 and makes cryptographic risk an explicit component of ICT risk management; NIS2 extends comparable obligations across critical infrastructure; and MiCA brings crypto-asset service providers inside the regulatory perimeter with custody and operational-resilience requirements that presuppose knowing where your cryptography lives. For a regulated institution, the practical near-term deadline is therefore not 2035 — it is the 2028 discovery-and-planning milestone. Alongside the standards, the governance expectations are shifting. Regulators and auditors are beginning to treat cryptographic agility — the ability to change cryptographic primitives without re-architecting — as a control to be evidenced, not assumed. Long-term data retention obligations mean signed records must survive the deprecation of the schemes that signed them. Supply-chain scrutiny extends cryptographic responsibility to inherited dependencies in third-party HSMs, signing services, and vendor platforms. And audit defensibility increasingly requires an institution to show a roadmap, not merely an intention. None of these requirements demands a finished migration tomorrow. What they collectively demand is that a regulated institution can answer, on request, three questions: where is its trust dependent on soon-to-be-deprecated cryptography, what is its exposure, and what is its plan. Today, most cannot.
Business Risk & Exposure
Doing nothing is not a neutral position. It is an accumulating, unquantified liability. That holds even for those who judge a cryptographically relevant quantum computer to be decades away: the exposures below accrue from data captured and records signed today, and the regulatory deadlines are already dated. Neither waits for the hardware. The most immediate exposure is harvest-now-decrypt-later. Adversaries — including state actors — are collecting encrypted data today for decryption once quantum capability matures. Any data whose sensitivity outlives that horizon — client records, transaction histories, identity credentials, commercial secrets — is already exposed: the risk crystallises at the moment of transmission, and only the loss event is deferred. The decryption deadline is, on any prudent planning horizon, a question of when, not if. History also says the migration itself takes years: complex estates take three to seven years to migrate, and the SHA-1 and 3DES deprecations each took five to ten years or more to work through the industry, so the work has to start well before the threat is imminent — not once it arrives. The second exposure is long-term record integrity. A regulatory submission, an audit export, or a signed confirmation produced today must remain verifiable years later. If the signature scheme behind it is broken or deprecated in the interim, the record's evidentiary value degrades — quietly, and usually unnoticed until it is needed in an audit or a dispute. The third is cryptographic dependency risk. ECC and RSA are buried throughout the stack: in authentication, internal PKI, signing services, data storage, and vendor platforms an institution does not control. Most organisations cannot produce a complete inventory of where they rely on these schemes — which means they cannot scope their own exposure, let alone govern it. This is the governance blind spot: you cannot manage, prioritise, or defend what you have not mapped. The cumulative effect is future scrutiny risk. As deadlines approach, regulators, auditors, and institutional counterparties will ask for migration plans. The institutions that can produce a credible, evidenced roadmap will clear those conversations. The institutions that cannot will face the migration as an emergency — under time pressure, with weaker negotiating position and higher cost. The point a board should take from this is simple: post-quantum readiness is a business-risk and governance issue first, and a technical project second.
The Capability Challenge
The reason this is hard is not a shortage of post-quantum algorithms. The standards exist. The challenge is that the capability to act on them is scarce on every side of the market. There is a visibility gap: no authoritative inventory of where cryptographic schemes are relied upon across owned systems and inherited dependencies. There is a competency gap: the standards are barely two years old, and incumbent security teams rarely hold post-quantum cryptography as a dedicated discipline — it is a new risk category outside most teams' scope, through no fault of theirs. There is a judgement gap: discovery tooling can scan an estate, but scanners produce data, not judgement — no risk classification, no sequencing, and no narrative a board or a regulator can act on. And there is a procurement gap: the large integrated firms offer cryptographic assessment only as part of broad, slow, expensive security mandates, leaving the mid-market and the specialist end of the institutional market structurally underserved. Underlying all of these is a simple asymmetry: the obligation to demonstrate readiness is universal, but the specialist capability to establish it is not. Closing that gap does not require waiting for tools to mature or for a multi-quarter programme to be commissioned. It requires a focused diagnostic, applied by people who hold the discipline, delivering an output written for the people who have to defend it. The reader should take away that the readiness gap is a capability question, not an infrastructure purchase — and that it can be closed in weeks, not years.
Preparing for the Transition
Readiness is a sequence, not a single decision. Each stage produces value on its own and can be acted upon regardless of what comes next.
- Current State
- Discovery
- Risk Assessment
- Planning
- Migration Preparation
- Trust Infrastructure
- Long-Term Readiness
What organisations should be doing today. The first and most actionable step is diagnosis: a complete cryptographic inventory of where ECC, RSA, and related schemes are relied upon, across both owned systems and inherited vendor dependencies. This is the input every later decision depends on, and it has standalone value — it is the artefact a regulator or auditor will ask for, it is the deliverable the NCSC's 2028 discovery milestone effectively mandates, and it is useful whether or not anything else is commissioned afterwards. From there, risk assessment classifies that inventory by exposure — what is harvest-now-decrypt-later sensitive, what carries long-term retention obligations, what is buried in dependencies outside direct control. Planning converts the assessment into a prioritised, NIST-aligned roadmap with owners and sequencing. Migration preparation introduces crypto-agile patterns so that primitives can be changed without re-architecting — the roadmap targets crypto-agility as the destination, not a single one-off migration. Trust infrastructure addresses the integrity of the records that must outlast today's cryptography. Long-term readiness is the steady state: an evidenced, governed, periodically refreshed posture rather than a one-off project. The organisational requirement running through all of it is ownership. Post-quantum readiness fails when it has no home — when it is treated as a future IT task rather than a present governance responsibility with a named owner and a board-visible roadmap. The institutions that approach it as a sequence they have started, rather than a deadline they are waiting for, are the ones that clear it without disruption.
Relevant QF Infrastructure
Quantum Future's consulting practice maps to this readiness journey at the points where regulated institutions most need help. Post-quantum cryptography is its only business, not a practice area bolted onto a general security offering. Every engagement stands on its own; none is a precondition for another. The Cryptographic Discovery & Risk Report is the diagnostic: a fixed-scope, fixed-fee engagement delivered in four to eight weeks, producing a seven-component, board- and regulator-ready report. It comprises a complete cryptographic exposure inventory, delivered as a cryptographic bill of materials aligned to the CycloneDX CBOM standard so it is portable into the institution's own tooling and re-runnable as the estate changes; a harvest-now-decrypt-later risk classification aligned to NIST IR 8547 timelines; an authentication vulnerability mapping; a registry of long-lived keys and certificates — the highest-priority migration targets; a priority-ranked, NIST-aligned migration roadmap framed around reaching crypto-agility; an executive summary written for the board and the regulator; and a structured findings and recommendations summary with suggested ownership and indicative timelines. The Report is deliberately bounded. Remediation execution, legal or regulatory advice, and penetration testing are explicitly out of scope — it is a cryptographic inventory and risk assessment, complete in itself, and everything needed to begin a migration programme internally or commission remediation from any provider. It is vendor-neutral by policy: the report never recommends Quantum Future products or affiliated technology as remediation, roadmaps reference open standards (NIST FIPS 203/204/205, CNSA 2.0) rather than vendors, fees are never contingent on findings or outcomes, and ecosystem affiliations are disclosed in every engagement letter. Its job is to tell an institution the truth about its exposure, not to route it toward a product. The engagement treats its own data with the gravity a cryptographic inventory implies — it is a map of where a client is weakest. Only metadata about cryptographic usage is collected, never key material; working papers are held in an encrypted, access-controlled workspace restricted to the named engagement team; deliverables are transmitted encrypted, with hybrid post-quantum encryption available on request; and working papers are returned or destroyed twelve months after delivery. Every finding is traceable to a documented source, and a PhD-level post-quantum cryptographer reviews and signs off every report personally. Strategic PQ Advisory supports the planning and governance layer for institutions that need board-level or sovereign-grade engagement rather than a technical inventory. Typical scope areas include organisation-wide migration strategy aligned to regulatory timelines, regulatory positioning, multi-year programme design, independent vendor and technology assessment, sovereign cryptographic readiness against CNSA 2.0 and equivalent mandates, and sector advisory to regulators and national cybersecurity bodies. Scope, deliverables, and duration are agreed at scoping. A set of supporting advisory lines is available around these two engagements, each commissioned independently: a Quantum Threat Briefing (executive education on the threat, the regulatory timeline, and a credible response); a CBOM Snapshot (the cryptographic inventory as a standalone deliverable, with an annual re-run available as ongoing crypto-agility monitoring); a Digital Asset Quantum Exposure Assessment (a blockchain-native review of wallet and key architecture, on-chain exposed keys, and signature schemes, built for exchanges, custodians, and protocol foundations rather than for a bank); Migration Programme Assurance (independent architecture review and gate sign-off over an active migration — Quantum Future assures, it does not implement); PQ Technical Due Diligence (independent review of a target's or vendor's cryptographic claims for acquirers and investors); and PQ Practitioner Training for in-house security and architecture teams.
Future-State Architecture
A prepared institution looks materially different from today's default. It holds a complete, maintained cryptographic inventory and a named owner for it. It runs a NIST-aligned roadmap sequenced by risk, operational complexity, and regulatory deadline, with crypto-agile patterns in place — so a change of primitive is a configuration decision rather than a re-architecture. Its long-lived records and attestations are governed for integrity across the transition. And it can answer a supervisor's migration question — or a counterparty's procurement question — with evidence rather than intention. The operational improvement is that readiness stops being a looming, undated risk and becomes a governed, business-as-usual posture, refreshed as the estate and the standards evolve. The commercial improvement is quieter but just as real: the institutions that can evidence readiness clear regulatory conversations, procurement reviews, and due-diligence processes that their unprepared competitors will face as emergencies.
Next Steps
Discuss Your Readiness Strategy
Start with a conversation about where your cryptographic exposure sits and what a defensible roadmap looks like for your venue.
Explore Relevant Solutions
See how Discovery, Strategy Advisory, and PQAS map to each stage of the readiness journey.
