Cybersecurity · Threat Landscape

The roadmap: what your organisation should do now

Written by the Mono training team · · 13 min read Share
Executive summary The first three parts of this series established the threat, explained the mechanism, and described the standards that replace vulnerable algorithms. Part 4 is the operational article — what a security or risk leader should actually do, in what order, and how to make the case internally. The post-quantum transition isn't a single project with a defined end date. It's a sustained programme that, for most organisations, will run through the end of the decade. The organisations that complete it before the ASD's 2030 target are the ones beginning the inventory and governance work now.
Data sources
ASD Information Security Manual (2024)·NSA CNSA 2.0 (2022)·NIST SP 1800-38 (2024)·NCSC Post-Quantum Guidance (2023)·ENISA Post-Quantum Cryptography Report (2022)·APRA CPS 234
Figures reflect publicly reported research as of mid-2026. Findings evolve — verify current studies before citing externally.
Post-Quantum Cryptography — 4-part series
Phase 1You can't transition what you can't see

Build your cryptographic inventory

A complete cryptographic inventory identifies every system, application, protocol, and data store that uses cryptography. This is consistently the phase that surprises organisations most — in scope and in time required. Even with commercial discovery tooling, the inventory takes months for a mid-sized organisation, longer for large or complex ones.

Network & perimeter — TLS certs, VPN cipher suites, load balancers Identity & authentication — PKI, directory services, MFA, SSH keys Application layer — custom crypto calls, API signing, JWT/SAML/OAuth Data at rest — database, file/disk, backup encryption, HSMs OT & IoT — SCADA, building management, connected devices Third-party & supply chain — SaaS, cloud platforms, payment processors

NIST SP 1800-38 — the Migration to Post-Quantum Cryptography project — includes practical guidance on discovery tooling and inventory methodology. Commercial vendors including IBM, Entrust, and Keyfactor offer discovery tools that automate portions of the inventory for network-visible assets. OT and IoT assets remain the hardest to reach.

Phase 2Not everything at once

Prioritise by data longevity and breach impact

Once you have an inventory, you'll have more transition work than can be done simultaneously. The prioritisation framework has two dimensions: how long the data needs to remain confidential, and what the impact is if it's compromised.

Tier 1 · Immediate

Data confidentiality beyond 10 years, or catastrophic breach impact

The harvest-now-decrypt-later threat applies most acutely here. Certificate authority infrastructure, health records, legal and contractual data, strategic IP, government reporting systems, critical infrastructure OT.

Tier 2 · Plan within 18 months

Moderately sensitive data with medium-term confidentiality needs

Transition timeline can follow Tier 1 completion, but planning should begin now, in parallel. Internal communications, HR systems, financial reporting, customer data subject to retention requirements.

Tier 3 · Standard refresh

Transient or low-sensitivity data, short natural refresh cycles

Incorporate post-quantum requirements into planned upgrades rather than separate transition projects. Web applications, short-lived session tokens, systems already scheduled for replacement.

Phase 3Your vendors carry your risk

Assess your vendors

Most enterprise cryptography is vendor-implemented. Vendor assessment should be built into procurement immediately, and existing relationships reviewed. Vendors without credible post-quantum roadmaps for Tier 1 systems are a supply chain risk — document responses and act on gaps.

Ask this"What is your post-quantum roadmap?"

A credible answer names specific algorithms (ML-KEM, ML-DSA, SLH-DSA), specific release timelines, and alignment with NIST FIPS 203/204/205. "We're monitoring developments" isn't acceptable for Tier 1 systems.

Ask this"Which products use asymmetric cryptography?"

Every product managing certificates, signing code, establishing encrypted connections, or handling authentication is in scope. Vendors who can't enumerate this are themselves a risk.

Ask this"Do you support cryptographic agility?"

The ability to change algorithms without replacing the entire product. Vendors building this in now are better positioned — make it a procurement requirement for new systems from here on.

Ask this"What's your CNSA 2.0 compliance timeline?"

A contractual requirement for vendors selling to US federal or Five Eyes government customers. Their timeline is a concrete signal of seriousness — a useful benchmark even outside government procurement.

Phase 4Getting systems across

Begin migration on Tier 1 systems

With inventory complete and vendors assessed, Tier 1 migration can begin. The recommended approach is hybrid cryptography — post-quantum algorithms running alongside classical ones during the transition, giving immediate harvest-now-decrypt-later protection without requiring simultaneous decommissioning of classical infrastructure.

TLS / PKIIssue new certs using ML-DSA or hybrid ECDSA+ML-DSA. Update TLS to prefer ML-KEM. Supported in OpenSSL 3.3+Longest lead time
VPN / Remote accessUpdate IKE/IPsec cipher suites to include ML-KEM for key encapsulationVendor-dependent
SSHOpenSSH 9.0+ supports post-quantum key exchange. Rotate key pairs as support becomes availableAvailable now
Code signingMigrate signing certs and processes to ML-DSA — critical for software supply chain integrityHigh priority
HSMsSupport varies significantly by vendor and firmware. Often the longest lead-time item — assess roadmaps earlyPlan early
Phase 5Not a problem that stays solved

Govern and monitor, ongoing

Ongoing governance is required for structural reasons, not as compliance theatre — the threat landscape genuinely continues to evolve.

Algorithm evolution

NIST continues evaluating additional post-quantum algorithms. Future guidance may deprecate current standards. Build a process to monitor and respond.

Cryptanalytic developments

Post-quantum algorithms could be weakened by future research. Cryptography's history includes algorithms once considered sound. Monitoring academic research is essential.

Ongoing inventory

New systems deploy continuously. Procurement must incorporate post-quantum requirements so new systems don't reintroduce vulnerable cryptography.

BoardroomMaking the case internally

How to present post-quantum risk to a board or risk committee

The transition requires sustained investment and executive sponsorship. Three anchors make the case effectively.

Frame it as present risk, not future

Harvest-now-decrypt-later means the risk is active today. The board doesn't need to believe a CRQC exists in 2027 to understand data encrypted now may be readable in 2035.

Anchor to regulatory obligations

ASD's ISM sets a 2030 target. APRA's CPS 234 requires managing emerging technology risks. For listed companies, ASIC disclosure obligations are relevant.

Use the peer comparison

Major banks, government agencies, and critical infrastructure operators already have active programmes. The question isn't whether — it's whether to lead or lag.

Start hereIf you haven't begun

The minimum viable starting point — five actions, all available now

For organisations that haven't started, these actions have the highest impact per unit of effort and require no capital expenditure to begin.

01 · Start the inventory

Even an incomplete inventory is better than none. It surfaces the highest-priority systems quickly — start with network-visible assets using available tooling.

02 · Appoint an internal owner

Name a single individual accountable for post-quantum transition progress. Without a named owner, the programme won't move at the required pace.

03 · Update procurement templates

Add post-quantum roadmap requirements to vendor templates immediately. Every new system acquired should have a credible plan as a condition.

04 · Brief the board

Frame the risk, the obligations, and the programme of work using the three anchors above. Sustained investment requires sponsorship earned early.

05 · Review TLS & PKI configuration

The largest attack surface and the most accessible starting point. Assess certificate inventory, key types, and CA configuration against post-quantum readiness.

Key takeaways

What to take into your next risk conversation

01

Start the cryptographic inventory now

It takes longer than expected and surprises organisations on scope. An incomplete inventory started today beats a complete one started in 2027.

02

Prioritise by data longevity and breach impact

Tier 1 systems — long-term confidentiality or catastrophic breach — transition first. That risk exists today, regardless of when a CRQC arrives.

03

Vendor assessment is risk management, not paperwork

Vendors without credible roadmaps for Tier 1 systems are a supply chain risk. Make cryptographic agility a procurement requirement from now.

04

The board presentation frames a present risk

Harvest-now-decrypt-later, ASD obligations, and peer comparison are the three anchors. Sustained investment needs sponsorship earned through effective framing.

Enjoyed the series?

The roadmap is technical. The decisions that drive it are human.

Board briefings, vendor assessments, internal prioritisation debates, and the culture that determines whether your organisation acts before 2030 or scrambles after it — all people problems. Click or Flick Corporate builds the awareness foundation that makes those decisions informed, timely, and grounded in evidence.