Buyer's guide
How to evaluate a PQC readiness platform
Board mandates for PQC inventory create noisy vendor shortlists. Use this checklist to separate discovery theater from evidence your auditors can verify.
RFP checklist (copy into your evaluation)
Discovery
- Agentless external scan (TLS, JWKS, SSH, email STARTTLS)
- Host/endpoint depth (if required for your estate)
- Source-code/binary scan (if dev-heavy portfolio)
- KMS/key-store coverage
- Honest statement of blind spots per method
Evidence (the moat)
- CycloneDX CBOM export
- Signed reports with post-quantum or modern signatures
- Public verify link — auditors check without vendor login
- Transparency log or tamper-evident inclusion proof
- Offline verify spec or CLI
Ongoing program
- Scheduled re-scans and drift diff
- Mosca HNDL / shelf-life scoring for boards
- Remediation workflow with re-scan proof
- Framework mapping (NSM-10, CNSA 2.0, CMMC, PCI-DSS 4)
Commercial fit
- Mid-market packaging and transparent pricing band
- Self-serve or pilot path without six-month sales cycle
- Coopetition story — layers onto CLM/discovery incumbents
Red flags
- One-time PDF with no drift story
- Dashboard-only proof auditors cannot verify independently
- Claiming full-estate coverage from a single discovery method
- No CBOM — proprietary inventory only
Compare vendors side by side
Use the full landscape matrix and individual Qtangl vs vendor pages. Download the comparison guide PDF.
Continue on the Q-Day hub: Vendor comparison hub
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- NIST IR 8547: Transition to Post-Quantum Cryptography StandardsNIST · 2024Federal transition guidance with deprecation timelines for quantum-vulnerable algorithms.
- National Security Memorandum on Post-Quantum Cryptography (NSM-10)White House · 2022-05Federal mandate requiring migration away from quantum-vulnerable algorithms by 2035.
- Quantum Threat Timeline Report (Mosca inequality)Global Risk Institute · 2023Dr. Michele Mosca's X + Y > Z framework for harvest-now-decrypt-later exposure planning.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.