Build a cryptographic inventory
Find RSA, Diffie-Hellman, elliptic-curve cryptography, certificates, SSH keys, VPNs, TLS libraries, firmware signing, package signing, and encrypted archives.
Quantum security
Quantum risk is not a reason to panic. It is a reason to inventory cryptography, classify long-lived data, ask vendors better questions, and make cryptographic agility part of normal security architecture.
Checklist
Find RSA, Diffie-Hellman, elliptic-curve cryptography, certificates, SSH keys, VPNs, TLS libraries, firmware signing, package signing, and encrypted archives.
Prioritize data that must remain confidential for years: medical records, legal archives, product designs, identity roots, government data, and sensitive customer records.
Assume adversaries may store encrypted traffic or archives today and attempt decryption when stronger quantum capability arrives.
Require cloud, identity, VPN, HSM, certificate, device, SaaS, and security-tool vendors to explain post-quantum support timelines and customer actions.
Pilot post-quantum or hybrid cryptographic modes in non-production paths before attempting broad migration.
Start with systems that sign code, firmware, packages, certificates, device identity, and long-lived authentication material.
Map where TLS, SSH, S/MIME, VPN, PKI, mTLS, and service certificates depend on vulnerable algorithms or brittle tooling.
Add post-quantum readiness, crypto agility, exportable evidence, algorithm inventory, and migration support to vendor questionnaires.
Watch performance, key sizes, interoperability, hardware limits, logging gaps, rollback paths, and incident-response playbooks.
Post-quantum readiness should become a recurring architecture and risk review, not a one-time research memo.